URLhaus Database

You are currently viewing the URLhaus database entry for http://mellow60s.com/Stanley_files/EFIqwZ183rfmd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2038497
URL: http://mellow60s.com/Stanley_files/EFIqwZ183rfmd/
URL Status:Offline
Host: mellow60s.com
Date added:2022-02-09 09:15:08 UTC
Last online:2022-02-15 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 09:16:29 UTC to dns{at}aplus[dot]net)
Takedown time:6 days, 10 hours, 26 minutes Bad (down since 2022-02-15 19:42:38 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-100FqMqW3XCaVXk.dlldll d7eef6152c0eb74faa8d8f28351bf86f01f428b3d5c82f8654acccab95ef1a3eVirustotal results 14.93% Heodo
2022-02-10ah6vqzcynxL7.dlldll 04edc7778fb47e806b9f9dd530aff94adfe9a8c774f81b7e33306819bd8208e9n/a Heodo
2022-02-10cZjBnodcIXUg.dlldll 24621ccdb34089bc8acd5f50b9f98f6e5c7edcbf3a5febe6dd984b2f5db00e66n/a Heodo
2022-02-1000RRMu28VPK2T.dlldll 9504316103e65dcb192781c71c3d528b1121b1a0e8802ae145841c1296504c0bn/a Heodo
2022-02-10zs8grV1wOk63xzOIRKE.dlldll 1ca2b6885334e73617b9686446ddb5c629c2282d02767dd3bbfe44f7638644f0n/a Heodo
2022-02-105r7E0g6T9gAWSSggAmv.dlldll e46b5857bbd3d45745298f2cdacced3e86817ca0b26ac4d2f0a9cc6fbc1f7a9dn/a Heodo
2022-02-09DzMnNwLS.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 7.46%Heodo