URLhaus Database

You are currently viewing the URLhaus database entry for https://golfpia.karmatechmediaworks.com/wp-content/oEicpDnEkk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2038844
URL: https://golfpia.karmatechmediaworks.com/wp-content/oEicpDnEkk/
URL Status:Offline
Host: golfpia.karmatechmediaworks.com
Date added:2022-02-09 16:37:07 UTC
Last online:2022-02-10 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-09 16:38:24 UTC to abuse{at}uk2group[dot]com)
Takedown time:22 hours, 1 minutes Good (down since 2022-02-10 14:39:41 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-10BWZDKG.dlldll fdb940aba634863fa8dc570eb70ae85f1522d973c0c58c3eae1b9fffec50f775n/a Heodo
2022-02-10H7x3.dlldll 60a5843ab9529293cd599be1ddacc97c7218736fe8ac052862aaafa63afa40e7Virustotal results 7.35% Heodo
2022-02-104NenmRd.dlldll 6b634cd8a6a4344a3a067c62c1cf5508dd7461f16185d7cf68027b7a4912b0c9n/a Heodo
2022-02-10E1yD.dlldll 3d85f139207a943fb3229c1a580654e77feab1bf022f7bcf76dacf1b33ad3f6cn/a Heodo
2022-02-10rlemhVrBOjLo.dlldll 32a4912c97f07b8732e5ba8f889970c4ba2ce56a060da0b5998a859286bbda65Virustotal results 7.35% Heodo
2022-02-10oWXB.dlldll 1207532cef21521a6725f27cea33807cfa18fafa412d68db895e522283604bcbVirustotal results 6.15% Heodo
2022-02-10Jqtw0a4Mpdg.dlldll edbccfb7b9f7c940e5673f5b1f7c78459e6b905e98cf7ce77fd6e0f5e385d540Virustotal results 9.38% Heodo
2022-02-10YFvv.dlldll 91ae86d9ec9aebafa9c7706e679b3d0616588b897b9f7b907116aed4c60fb520Virustotal results 16.67% Heodo
2022-02-10lZNVmKacEM.dlldll c0f31b9ed55b92f1235ac3741646ed9a846854c6ff8902ba3f93f6665eac04d1Virustotal results 13.43% Heodo
2022-02-10aOipONLa4o3e.dlldll a251b6a703fc5ca827dadad3a4c848662e0c64c984fefd0244f8fade79a46192Virustotal results 15.15% Heodo
2022-02-10Q8hclY.dlldll 9d830dd1b5cae25208ab1bb6f097527926f3c5049fcbc5123b50df4fb9949086n/a Heodo
2022-02-10i6F5kxeAQiAposq.dlldll 23811da0870edc79409255bfe24f425d85eed204b15f3dc40ca38c66416754cdVirustotal results 11.94% Heodo
2022-02-10YFyJW1UoAiSJkjNBQ.dlldll 570e45f0c019d896c95114aa46432617190fcd4b2e2df3526aa52688cf8b0831Virustotal results 11.76% Heodo
2022-02-10nfy2er7scOoOQKz.dlldll 6348258aa6bf1976386a4fef909f22e7bac16203821af549db794b107ad08a39Virustotal results 9.23% Heodo
2022-02-09g9EKZ4rRqmPyzCT.dlldll 14a4e0040a142e2271e18144a908b3c248cc4045836c65b77d4bd47dccb25bd9Virustotal results 11.94% Heodo
2022-02-09tEsp1.dlldll e612d78fbbbf65f8fb1bf6f60d9143b408bf698bb367cad45a266f9a9c9e40d1Virustotal results 10.45% Heodo
2022-02-09wY1QFUm3.dlldll 3809cf85e8d3594627c505f3e02e102607175aab0a505ac2307e4ab04c907afbn/a Heodo
2022-02-09Que1Yd3LUgSfTzgiB.dlldll ca0d0f54857049d27516def3936a5cef60abef0c7990c9b511b983f27c381953n/a Heodo
2022-02-09579Lte.dlldll 9d283cc9a284654ca759a6a5da043fb9d4407d6625ec931f5ea35a8faa28f0e7n/a Heodo
2022-02-09UYbcXOQL.dlldll 8462dc1a6f1416f9fc1f3395820f316113a5744cd46e0302c14af4175256b261n/a Heodo
2022-02-09jntxLAe008.dlldll 3486b2c85f7a0f66d2939738ba6b0e041c8856ba6ad314f2e8822699d4427b84Virustotal results 24.24%Heodo