URLhaus Database

You are currently viewing the URLhaus database entry for https://chughtai.xyz/cgi-bin/r0hNrJM20mGthgS8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2057483
URL: https://chughtai.xyz/cgi-bin/r0hNrJM20mGthgS8/
URL Status:Offline
Host: chughtai.xyz
Date added:2022-02-24 08:51:08 UTC
Last online:2022-02-24 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-24 08:52:12 UTC to abuse{at}host4yourself[dot]com)
Takedown time:9 hours, 20 minutes Good (down since 2022-02-24 18:12:17 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-24LQVcWb0pN.dlldll 6a22aa9f6357685e75035e32304df343c08dd7a8c936acf930199e9be521836dn/a Heodo
2022-02-2449DJFkPsCdSSqrER.dlldll 8f5a2e5a8e87eb9a8e76978c29a6a4600285f34a1e156e7003123a910780b77bn/a Heodo
2022-02-24GAzEf1llN6xlTWWo.dlldll 9205a901b8e850540a1ca3800f4d4d8eaf7a693d03bf08d3e0c54e69c2ef590fn/a Heodo
2022-02-24T7bkNLrvJHJKJQa.dlldll 123aaa6a2499d306efc54096061e3dd04e66e67f480c0f643617282cc44a1300n/a Heodo
2022-02-24DFnKEr6ETMqjxUoWqV.dlldll caa18e279a2aba11bee94aaee00a7880a5be615a0a5dbe0b8760049542499debn/a Heodo
2022-02-24POuitPy87BbrV.dlldll 8229241ce15cc0a49994a009c0f59dedf627974b2cd0cec92218a3a744fd4817n/a Heodo
2022-02-24mlBQK2oAFcRi.dlldll 4fe515be3ff0ce8f2b5dac84af1b6f00de80fddda76c6eb4472db9e3f445bd27n/aHeodo
2022-02-24CZWdFj.dlldll 170863e145ecbef9863b818d488e0baee81d39b63d10a444987c9be858324026n/a 
2022-02-24hJPuTJLS.dlldll 3f4ebee3b7d8d708d22d20bcc31254328e79965494d922f1a7575326d67fb282n/a Heodo
2022-02-24IgS3lkL5uQxd.dlldll a353bbf43a84f9dbc5ed59f7efe2f4eabd8a40e6cbbb61f99e52a80d69a5349fn/a Heodo