URLhaus Database

You are currently viewing the URLhaus database entry for http://lost-earth.com/Black_and_White/ZW4rHEdD1vZX/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2038496
URL: http://lost-earth.com/Black_and_White/ZW4rHEdD1vZX/
URL Status:Offline
Host: lost-earth.com
Date added:2022-02-09 09:15:08 UTC
Last online:2022-02-11 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 09:16:29 UTC to dns{at}aplus[dot]net)
Takedown time:2 days, 2 hours, 43 minutes Poor (down since 2022-02-11 12:00:21 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-11IOAH.dlldll 134211ddb082354c34ae1d49d76988ab261371543b6c3221edc5dc7ac7432bcfVirustotal results 15.94% Heodo
2022-02-11Hqhf3qBWDbZn.dlldll 91bbd8cd5c0b455ad7b9bedfc513852c50a297d0740ef448dd11d6285ca9b2b2Virustotal results 14.49% Heodo
2022-02-111JFkKxOygKezRueHcQ.dlldll 6b19428954b9bb2d63127423b8c2bc104fe151808716eeda82e1d6bb793fb3ben/a Heodo
2022-02-113qJW.dlldll 7027c4c727f2c6adf5b3ebc2d7d8433c22aed739f43294ac77c2475365d65cfen/a Heodo
2022-02-11PpsTnPtPQPPFu3Ndb.dlldll 9e38fe2b5b866e94c8f16cb7c43246d160cecf025d4d1f7b8b2cbcb52828980bn/a Heodo
2022-02-11tlIYQ.dlldll 4c8af87862bd0d3f5d71fc3456f7623ddc4b8e1e41399f49326f571a76499dcbn/a Heodo
2022-02-11Dilz.dlldll 31bdf71ac6334709895975c8ffb8814bbf37f2dfba4b12444af12e37fa2cb9d7Virustotal results 8.96% Heodo
2022-02-11l61.dlldll 3400b4042d4a4481837260ece5c1695442ba0567cad46626a6f1e1772f8ce222Virustotal results 8.96% Heodo
2022-02-113xj.dlldll c6a9f1547787abfefb28bda94ddcdcef7ef573a4f79edf08f9ef76c40400f1b6Virustotal results 7.58% Heodo
2022-02-11Q6hDzPj.dlldll d190b6fbc34b32593d791105922c17a88d69ac343c1f6dbceda9833e506e7636Virustotal results 7.94% Heodo
2022-02-10hO2WaudBZqUC1C0Qv.dlldll 65d6fb75392df0557f17468b2be5b67dfefad33ece6217c3d6f6961ed7b709d6Virustotal results 7.35% Heodo
2022-02-103UTZYr9D.dlldll 881e62ef09067cb3ca0aeb72dd2f17ee261411fe312013879a70069d5ba62507n/a Heodo
2022-02-100Fi.dlldll 368b615bb23b8c9517b880eb6c33eea24d1a2fe5054a6baf5fa5362176953b2bn/a Heodo
2022-02-10kQ1dLmrdCKCIUFADy0r.dlldll 69efc21bbf9c8dade61ba90aa70152b75fbf5ae9e41b310567403c9bbf5fe8a5n/a Heodo
2022-02-1080xpM5ENxYSZc.dlldll b2139bcbbda5bda3b5ebea0038b515e4b7199446be07c60bbafcd47c423be709n/a Heodo
2022-02-10z7dxizTxLRQ.dlldll c69eb6a59f63e543a46186791bbbbf06d6f423737415d6d436c6efe4f001a3dbn/a Heodo
2022-02-10g8xXjMAUroLoTX2.dlldll 6d1797517910568ee39db8a6e1ca58b824b2962e48949443cefbc89d6ecd818cn/a Heodo
2022-02-10drVTxW27XHXqybYuF.dlldll 914686cf9a9c90162cc76bed695da10075988d0faf3578c9978fb51caeeab29dn/a Heodo
2022-02-10XPfkQS4MXKD.dlldll 435f521caca9d6c8dad6c7dd67c9bc5de8832ac0b371036fc6dcc1b5bc4e9fben/a Heodo
2022-02-10dltUH2zLDMfthtShQp8.dlldll d037470efd8b022e44164300e7ef1ff8c9b78b20e3d28133af61209027933e3cn/a Heodo
2022-02-10nsXgugJB8ejtLcjs.dlldll 054ce8c3742070d28122173b7b2d4cfa59f7b0292244b30bfa64602273b4785an/a Heodo
2022-02-10DQUC3qM.dlldll d8a23516ab3ba8c7d50ac091e1135f39847ec3091feb10c28acc35193ba0a790n/a Heodo
2022-02-1084XwrhuN.dlldll e19562ff3cef8b3d6293f325bcc3a8ed6c5fc3f3db59fdbc88da25fccb6e6daan/a Heodo
2022-02-10XJJrC.dlldll 062b85c94c58b6ef45fc0c024c7f90e2ec34278832aef07a91cc41b6026f2180n/a Heodo
2022-02-1099WffugtEj3sn.dlldll d8394375ab8035643d37efc41547ae238e3960cd8dd973d921a8d21d97ee43dcn/a Heodo
2022-02-10CyakxEchC5CuUTASl.dlldll f4947389ea48f51d92ebd04bdf8dd8db496c4b3ca96e79dd19a4947918bf96b7Virustotal results 8.82% Heodo
2022-02-10x2Yd4ZrVn9pglYvM1R2.dlldll 592f61f62dca484952baa73f6bd06ec019c92650cdf14f85587e7e634e2bf6eaVirustotal results 7.46% Heodo
2022-02-09AMz6z8R.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 8.82%Heodo
2022-02-09fVPE1Uf76EdwIKA.dlldll aeeddb7343937b8dfacdc2e56e03fe1dd70fbbb9bf50b11dcce246fa672f2dacn/aHeodo