URLhaus Database

You are currently viewing the URLhaus database entry for https://sandiegoinsuranceagents.com/cgi-bin/XK1VSXZddLdN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2055471
URL: https://sandiegoinsuranceagents.com/cgi-bin/XK1VSXZddLdN/
URL Status:Offline
Host: sandiegoinsuranceagents.com
Date added:2022-02-23 12:31:10 UTC
Last online:2022-02-24 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003913429 created on 2022-02-23 12:32:06 UTC)
Takedown time:1 day, 3 hours, 0 minutes Poor (down since 2022-02-24 15:32:25 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-24pDiJbwcZGQt.dlldll ef2cb4584728c172ff31cce1ad009d6ed3b7ad551e16da639c90f29697f64c49Virustotal results 18.84% Heodo
2022-02-24Ek2.dlldll 8fddc25789de41b4ee68a7d3649f8bb2bc96fcfb934dd0d457267a0df3c12f44Virustotal results 17.39% Heodo
2022-02-24uH0J3.dlldll 8905db6629a361f45b3ed5eafcf8860dd0417e506f4a86d3bcb3fa9c8874b28fVirustotal results 14.49% Heodo
2022-02-241RyHCb5gH03yyZGU.dlldll 02a47e553bd240164ba56da4ffa80d663d8bc5bfda872c37f1e4958af191e7b3Virustotal results 13.04% Heodo
2022-02-24IYgWxm5KzCOiu9IO.dlldll 7481596e3c3229385b224541dd476f2b3eaec8e2a7d69fe31dff738b1d64514aVirustotal results 13.04% Heodo
2022-02-24QkTGNRSFEd4dCCyN3BK.dlldll 13db4f3d330d38bdc9d7b8734d5464e800a55530225f4312429175ea1573774fn/a Heodo
2022-02-242Pyk6t45yEgAKOVD.dlldll 09188538d96ba7a6eb8b556bf9025dd21502b415313484a7fcdac39736351e4an/a Heodo
2022-02-24fV5XQVlsgjhO386w.dlldll 9a20b084138229f0f873b8a670b641fb36d5403ba3abf94dbc9ca78d60167e25n/a Heodo
2022-02-24NnrEcPf8IBLeMN.dlldll 3d33a2c8c70f31b1f5acd3a5f94e8056e34fc37be29bc0ac37c46a3145076d7eVirustotal results 20.00% Heodo
2022-02-24bFSS.dlldll 791fc84a8465213f4bbfcfa6af6264187500ff4d37cf2ec5a6ab227772c9b453Virustotal results 19.40% Heodo
2022-02-24cVrmBldL2IVrfwLc.dlldll 6b39508e70c0849bd89effb9eb25dcbb8ccfcd1a2ca7304f4b9f91bdb77bdf4eVirustotal results 18.57% Heodo
2022-02-24MdfUIwiZZtpA.dlldll d9391c02251af68c9787a94ab415ef880a62a9e9de1697053a74e8fe2121e1b7Virustotal results 17.39% Heodo
2022-02-24Z3vIVkVV7cBTv.dlldll 776d3030f2da7d971fe6ad696108d58149365844f0ea00209c7eb4c4c82114ccn/a Heodo
2022-02-24FxItFDRGFb6.dlldll 21419b7520b884ac2e095c3b8c91ebc7c5c4a69f9ab6d98614e17909c4445c89Virustotal results 14.49% Heodo
2022-02-248es4DkX04.dlldll afa09018c22c9178005d385219df53a7127191d6fc23930b858943b75609c2baVirustotal results 14.49% Heodo
2022-02-243EKlF.dlldll 3340940229de893ef6e80369112f59c9de36a7275dfcaa540fefe1db89195aecn/a Heodo
2022-02-23MPcoADwRQM7Gxxuo.dlldll 5bb6ffa54964e151d1454126675ce5d1489fac52007435df0451bb07918f2b88Virustotal results 13.24% Heodo
2022-02-23AZyebYUbxwBc4O0S.dlldll e1842e10e2df612e784a86aea6cd7f6836ddbfd43284ecfbde3503d4c2cd96efn/aHeodo
2022-02-23atYvHITn2qNtj.dlldll 1c3b98c99e9e3c868a4d139f1c8f1ec3e912535aa77f8266f07bddea00cd6ac6Virustotal results 15.94%Heodo
2022-02-23WPQ5KZjd0UFW.dlldll 88aa1c2df6e89bede6dacec300138fa206af74cb41001a4c5b6834990413be96n/a Heodo
2022-02-23WMfzMQ6NkaOSTRWcZ.dlldll f9586710d24707d4b937a38587f9b07cf63d2a4553bd40bd188a8cbfb7c8402bVirustotal results 20.00% Heodo
2022-02-23zSHc08MMeCOysfMj.dlldll bd9f84b13ec225a8d2465e9bf74cbf44b5e02d4a89898d999a5e57f5336616a8Virustotal results 24.29% Heodo
2022-02-234RarBzXgPH6JAgjS4wq.dlldll 7259d9aa48fdde7010c7d77b70ecf3122b3bd52e1a9f1c57a179b75149072166n/a Heodo
2022-02-23oVY.dlldll 7a6900047ac49486ef24fe93b504398c2419c05aec8eec5bab7988c91665c4caVirustotal results 20.00% Heodo
2022-02-23WELCD0hGL87fI22.dlldll 94569efb27370838cadef162b043db160d7c1a2e8ba842b969e4041474af1f22Virustotal results 24.64% Heodo
2022-02-23EnJ2X4zrr6AZ.dlldll 143c96b2ac7914d9e9d29d429860ed906d13b4a6b2c2479cb96544511d6b095an/a Heodo
2022-02-23Q5LaGq1Q.dlldll 9301270d1e772535ec71ccfce61de670bcc20933070da1b7de18e851992f5b03n/a Heodo