URLhaus Database

You are currently viewing the URLhaus database entry for http://homehandyworks.com/eln-images/xFIDPfs4SS1yw7ghXXk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2038507
URL: http://homehandyworks.com/eln-images/xFIDPfs4SS1yw7ghXXk/
URL Status:Offline
Host: homehandyworks.com
Date added:2022-02-09 09:16:07 UTC
Last online:2022-02-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 09:17:19 UTC to dns{at}aplus[dot]net)
Takedown time:6 days, 7 hours, 49 minutes Bad (down since 2022-02-15 17:07:07 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-10WF1gTm.dlldll c3b5ce1ebc47721507fe1f898328a182a6bb9519917425b3782d005b51466be7Virustotal results 27.27% Heodo
2022-02-10SAf74x1do.dlldll afd46e1666789f9a70442e307c4287871fb3ab66a296a881181d31a5431e6a3cn/a Heodo
2022-02-10x918PGFUN1iagt2Z.dlldll 82941f5d0ec4ad9b32805ce972a3fa61312137aa4183e5e85eb1ec6c41f54775Virustotal results 13.64% Heodo
2022-02-10FEb1YuoZbNzgS.dlldll 5d7d7c486b82dbd17993597e98f8631e7803fc9b8483593b64ba43ee7b0b14c7n/a Heodo
2022-02-10SGEKH.dlldll 5fb047893e1723a888215dd5a4f445f498fecd12f56bc60a93b42fcdb9f7def6n/a Heodo
2022-02-10xDr3IEQ77Hj.dlldll c13dfc24d891404c3c2114c4bf8676c18f6f494d728b91d74971c3eef751e029n/a Heodo
2022-02-10UYRJq4HXT.dlldll d66781dafdfe678263721a85fac4ba57c2b38c175ba51974611003719c79280cn/a Heodo
2022-02-10HkINRMnXblrbKZTa.dlldll f75be26e37b9d9ffb4b60c347e3b9d13e565a8e3e29a45b011848462d63b9d06n/a Heodo
2022-02-106IPJdsPt0TtZdleolsm.dlldll 56729aba53182d14cf6f3f08444e0fe7ff1cb86fd56f347b7d45f2da88189c1an/a Heodo
2022-02-09ctB.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 7.46%Heodo