URLhaus Database

You are currently viewing the URLhaus database entry for http://hi-techaudio.com/dir2021/g3d/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2038510
URL: http://hi-techaudio.com/dir2021/g3d/
URL Status:Offline
Host: hi-techaudio.com
Date added:2022-02-09 09:16:08 UTC
Last online:2022-02-15 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 09:17:20 UTC to dns{at}aplus[dot]net)
Takedown time:6 days, 7 hours, 24 minutes Bad (down since 2022-02-15 16:41:31 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-10EsKCcf.dlldll 080393acb325be4aae7e2dd0908c20ad1215f0d1a1dd0778389c5739b5b2024eVirustotal results 14.93% Heodo
2022-02-10i4pYk0n7jqh.dlldll f40e82b17f2049b35beb482883a65d8ecd910e56385ba828532794e2ba9f550bVirustotal results 13.24% Heodo
2022-02-10GQfr6Qw2OcJ.dlldll 9e9bcb346f58a9c84f38b8919c892d4601535e7d526c868affded245c841dd48n/a Heodo
2022-02-10064ZXSlc9sS5xWoij.dlldll cad70af550ebc5eebf937d4c5efc24e1a42a71e0c610d0602178b3f8e6ae10baVirustotal results 7.35% Heodo
2022-02-104668VA9UUGiEPJn86D.dlldll be1f137389d0250d384803c59adf5a3d4eda818d15c6d0ec15b67d89018f0c4fn/a Heodo
2022-02-105M3gyQ9kb4zjD.dlldll c3c91dfbee79516e3e88027dc398bd58a9a6b5eac56cd69d40778d476a15e5f6Virustotal results 7.46% Heodo
2022-02-09a9Y3UwXLhROLtq4010.dlldll 87aba171d0f050657ab19a1586df6108070d5aa94f1acef911a239a35390a1d7Virustotal results 8.96% Heodo
2022-02-09xp0ex1TDaF8kFlnntux.dlldll 8fa26c4315ed3fbd7d468d507e9a1e36ab2b89b14fd845d88986b2996e70d6ecn/a Heodo
2022-02-0921ABHl.dlldll 1246421eec32f6f3f391b86afdda76aeb62f85cce38522a69a9eebadd0ed6da3n/a Heodo
2022-02-09hXZ1oTpWf5eFpi.dlldll a441e87ba9fb0e397124dea900dc3a7afbc78bde55f66a31f51970db118296c6n/a Heodo
2022-02-09r9BOP6tUw6cZ3YaW.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 7.46%Heodo