URLhaus Database

You are currently viewing the URLhaus database entry for https://vinculinc.karmatechmediaworks.com/wp-content/VlcOPPwgidWlXDJNs6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2038841
URL: https://vinculinc.karmatechmediaworks.com/wp-content/VlcOPPwgidWlXDJNs6/
URL Status:Offline
Host: vinculinc.karmatechmediaworks.com
Date added:2022-02-09 16:37:07 UTC
Last online:2022-02-10 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 16:38:24 UTC to abuse{at}uk2group[dot]com)
Takedown time:21 hours, 14 minutes Good (down since 2022-02-10 13:53:14 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-107c5l39WCwz9BfP.dlldll 81ed51b39ba9a133e32919a7c075903d67414a8b4772167cb1ffe94149ad5840n/a Heodo
2022-02-10xopXxJo1ceYrrs2EydF.dlldll d62f3d2f28b241132effe22440e0aeb9f5dfef3814715816f0155d69b3bb4b55n/a Heodo
2022-02-10Mg3f63AP.dlldll bec150f0d7dd299af4032fc92a16ad650f1504437640481b0b8e8c61f568f924n/a Heodo
2022-02-10b6rsK8zrBV.dlldll f60e246d1ddd1fdacb12bc69ef471fdbf3a634f2365fdefb38013bfc897393ffn/a Heodo
2022-02-101111oyMzUEt9Zb3Pfz.dlldll 481aa5cd9fb7a7b5510854cc3b91b06ea7a217aa896c5a408aeb217c48bac40bn/a Heodo
2022-02-10CRV57U4QlTY9ohQhJm.dlldll f41c615a9ed01cdaaa56c5b0bec906519a3da367714b2646593d24b4cef71d4en/a Heodo
2022-02-10xUVlWp9vEZCjauEQqQ.dlldll f14ef3a2f09e558ab1673bdc6dfe5575ed8d4473fcb1ed71792b7aca508cfb74Virustotal results 6.15% Heodo
2022-02-10yeqcR74pFOP9mZ.dlldll 58a124d080366e2d59d7174eb55069e3ac6d91d2410088a67a8bbbd82194f0acVirustotal results 16.42% Heodo
2022-02-10AF1mef3FCeVc3AuO5HQ.dlldll 606d2f84b1ddb4a6a6b7d98fca7d3dcfc5d6c1f5143a2507540b8c51bd83b643Virustotal results 13.43% Heodo
2022-02-10T0OUPwyJCst1.dlldll cb7875b01dd484dac866036249b61137b14ed86c20e2d7c153387e5a4c1c0a47Virustotal results 13.43% Heodo
2022-02-10ZURermt.dlldll 7c86d75d30b91431730f522ffddb8f0e57d930056223040322c3a77233f7a634Virustotal results 14.93% Heodo
2022-02-10s46VAzoQ.dlldll f8628fe9a1cbe1a1fe6ce771fcfa81ae97dd8afa54c4104c5a055354af5e3380n/a Heodo
2022-02-10Yb6XypuK7sAQy.dlldll afe89ba7defb1cc6eeb21a6c067cc8cd5bedd5689bbb2031fd72e41b3abeee1bVirustotal results 12.12% Heodo
2022-02-10UtspL8mdM0RdIbb.dlldll 45e93615be573d34d21309713a0635e310182cda99f421c3e5b320a2110ec441Virustotal results 10.45% Heodo
2022-02-09krh78UNJw5fly1mdknC.dlldll 824158b15b56b66894f3c5a1c601f1f1ce2238fd4f473116ece8bbd52aa1582aVirustotal results 11.94% Heodo
2022-02-0961r2kxmQKwUm7Rw4a8J.dlldll a19fe1c006316c5566c3a837a644dcf54eb0a38733bb99a826b488df8741a0ddn/a Heodo
2022-02-09praOt9cuVH.dlldll 1c06ebf0338aaf711e1d0b30aa2327213bc77257565fec83abc26ee353a765eeVirustotal results 10.61% Heodo
2022-02-09gIAYAYzzy2MNV7S.dlldll f6470f49460c0b7edb6130492893ab6f92b73dcb4cdc8d5edb8a848c19b8a232Virustotal results 8.96% Heodo
2022-02-09s1weCJ0ju46.dlldll 88d9b4801d2666dc04eb03936d5fe2ae62af325690e3f93b91a2963ae7308668n/a Heodo
2022-02-09DpV1xvaTgeOOrr.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 24.24%Heodo