URLhaus Database

You are currently viewing the URLhaus database entry for https://uhc.karmatechmediaworks.com/wp-content/0EqfdeznntlOpaIP2Qv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2038843
URL: https://uhc.karmatechmediaworks.com/wp-content/0EqfdeznntlOpaIP2Qv/
URL Status:Offline
Host: uhc.karmatechmediaworks.com
Date added:2022-02-09 16:37:07 UTC
Last online:2022-02-10 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 16:38:24 UTC to abuse{at}uk2group[dot]com)
Takedown time:21 hours, 57 minutes Good (down since 2022-02-10 14:35:24 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-103aJ4h2uF95r09UGlI.dlldll aeb66f78b1f3bdad54788527bf7b684e090db949ce8ed481aa8739138b6a6dddVirustotal results 8.82% Heodo
2022-02-10HM4cckJZO.dlldll 4d8216067f49f61b6f7df9e3b7288bba3052e6ab85c75f4a36f40c3977896882n/a 
2022-02-10s1YNn.dlldll a09b9dd181ac4edfa4b5258dc4bd1e6e0c15151496d1fc07c7808f9e8517cb0dn/a Heodo
2022-02-10PnC5.dlldll 2d19171d2c6377330e19495ec47a71929491c372f167198326d626fe398f9e4cn/a Heodo
2022-02-10WTEZzj42lNlUWh0.dlldll 403964becd8427baf5074a5a49e5e474e19003831b570bdda4fa71470f098f38n/a Heodo
2022-02-10Vi8R73tdz3zl.dlldll a1af02feececa3d2c682c021ea83ab07a99e020a615a0e447f678085ff3cd044Virustotal results 7.35% Heodo
2022-02-10rnEcjsQaAt9fHE.dlldll a6f68440ebe7a7cba642b2e84e230c4bfdbb5d7e0910a1603fa1a4a717f1d500Virustotal results 14.93% Heodo
2022-02-10IvatD1YD3bnJoKl4.dlldll ea9cc6666a0a5db138ec1c72decbaf98b870f97970603090d54a610de61c177dVirustotal results 16.67% Heodo
2022-02-10qHrU1wjxE3.dlldll 9ce1d641d6cfbe8e68de9227e962f29b8c3ac026414a3399436f57ce3a5ffeaeVirustotal results 13.43% Heodo
2022-02-1055UUA.dlldll 9daeed41eeab7a12b7728ea028e9b11e2ec27a2f397923a27316004f284655c7Virustotal results 13.43% Heodo
2022-02-10YTbBlStYrAqGC.dlldll c02a8903498e3551f5e9ecbc16f6388808aec442c954d351347d9a0f431eb847n/a Heodo
2022-02-10UjRYf38vepAohfSkk.dlldll 270c1cec79701e0fb00d68daa3a9c5a50df0175efd7877ded5906de5ae499ec1Virustotal results 13.43% Heodo
2022-02-10nBFqkBcrQQH2.dlldll 312bf2ddc5fe0b0c2978b2aa44c6ad741adb0f49bb51f254c36fb1ff731dd1b4Virustotal results 11.94% Heodo
2022-02-10S5CkJhbyjsbAVCb7.dlldll e7b45164d421fab43634465875df4e50fb1fecb0bbf46d568952caabdc31048aVirustotal results 10.45% Heodo
2022-02-10ILPK19TzzlNH79OJi.dlldll 00c85bd7a6cbe4ee0d92cefde5c106f3956573a7f579dddb60e47f04cf3b32d0Virustotal results 10.61% Heodo
2022-02-09psnBt61uKDEF.dlldll 2c9747e063e078a32e2d04f9201a4f3b4ba3af237dc965eeb95fe18491963b92Virustotal results 8.96% Heodo
2022-02-09sbeOCXSBMirwdGjI.dlldll 8833974c0f14b3e4b246a040d483b8c74c54120e3179c7f78b487a6120f64679Virustotal results 8.96% Heodo
2022-02-09u0zNpE.dlldll d03d3c54655bc46c4fd135a6345178ed22084f64cc210cb84dbd2d3e88cc6382n/a Heodo
2022-02-09Njg1.dlldll fac6a5d04d9521d652dae0420f66171fc1b66b3b66c2830e475d6eb47cb20203Virustotal results 7.46% Heodo
2022-02-09t5mt33or8jHLr5nVkc.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 24.24%Heodo