URLhaus Database

You are currently viewing the URLhaus database entry for http://gavalisangh.astravit.com/umar-rack/fyMw4DZw1JAB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2058620
URL: http://gavalisangh.astravit.com/umar-rack/fyMw4DZw1JAB/
URL Status:Offline
Host: gavalisangh.astravit.com
Date added:2022-02-24 21:01:08 UTC
Last online:2022-04-06 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003915139 created on 2022-02-24 21:02:06 UTC)
Takedown time:1 month, 10 days, 19 hours, 19 minutes Bad (down since 2022-04-06 16:22:00 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-291coj.dlldll 3755e204e82668051343eb798a797c973ff61568d3bceaa45d5416916ab8f3dcn/a 
2022-03-221coj.dlldll a0877a4248df5da8cdec21b1f2eddc23ecfeffd052569115b762a58dc14a2b98n/aHeodo
2022-02-25sedSb.dlldll 601176e4aa0260d428d0941279f64a374d1fee5dd3b07473bd14554856971457Virustotal results 11.94% Heodo
2022-02-25ok263dkWLJbTHn.dlldll 3141d4b0a1d3ed109154c90c7b190867b40e4674ddfb8f501ccad34f6128b3b2Virustotal results 23.19% Heodo
2022-02-25Mfb03w.dlldll ea1a171b757cca43331c7ad24af3e70d4b630f8658f702e6728e65e9b48f6153Virustotal results 15.94% Heodo
2022-02-25dqIgxZa4iLpqoDR.dlldll 618bd522be02ff199be6afd1a76eef9af7b529f2b27f166a7d1d25f0dbf663a5Virustotal results 18.84% Heodo
2022-02-25zp9YqO9SxR19K2ehf.dlldll 61eab0d82b8bf8db8e732c2f9ac2a1577b0466c3afcc672e3bba946cde08c287Virustotal results 15.94% Heodo
2022-02-2555mcKkVpNqRr8rD.dlldll 5b8dd791d12f42529792e048d769389eac3352d516486a5a0c8704da382ecac4n/a Heodo
2022-02-25SVj.dlldll 8763605be2504da3b6626d9539c544f9c504c51fd88c69cec444cf682f847821Virustotal results 14.49% Heodo
2022-02-25jtUHGW.dlldll 88745f1e47722cd63649e851627bfcdf86b499f2dd265615cb5a15f6941eb295n/a Heodo
2022-02-25cgPgJKv6B.dlldll 3ab4d672e15a586eac1c9729c2ba09e4199496cdf178a70dd50947a571cd740fVirustotal results 11.59% Heodo
2022-02-25cLCcwce8IU.dlldll 9c5df1c312fa295b3aeb2f629020339c4c82b9857ebddce46e8b1045b25b753cVirustotal results 11.59% Heodo
2022-02-25yzCI3KVc4BRb.dlldll 96d05721f783342484e8b62fb62b2f9fba4dfac0c7863f15f047d2e1ec3aeea1Virustotal results 11.59% Heodo
2022-02-25dNKhWOuol7K.dlldll 6ce988a6e26849642747afc7ff3c0289c0985b68841aeee9fdccdbc568daf33bn/a Heodo
2022-02-25ZjwDWdKbwWx.dlldll 1a7572c7a97534b913f67f686ed2e48a222dad9e67807eabb46d30708bafc78dn/a Heodo
2022-02-25X9MgM1khSWG.dlldll 27a5efd5823439128920ddc2731eeec90b30c3da7eacc9998489e038e5d48d64Virustotal results 10.14% Heodo
2022-02-25Vi8TlhdCpt.dlldll 9b40344650d464808a6c327c8204c4356d44d49310e6c143301e24a55924b8feVirustotal results 17.14% Heodo
2022-02-25eiAYu5TjtgWP.dlldll d4ec3324453cba875567251fb62a43feb277726c11b29be16379613598481f65n/a Heodo
2022-02-25xSeNR6.dlldll 9ba2100144a3a0458a63a901eb4aeea6a089ed30254b108476d5bc1823dd77a9Virustotal results 14.49% Heodo
2022-02-25P7wZWhCLxFqy.dlldll dc47421efea2dc2b6fc93a9533e8d1ebf6ee7bfe5fe30135c01f86846e4d8c5fVirustotal results 15.71% Heodo
2022-02-250Hk.dlldll b2f536525d4312afc74fa5295050f2123fff4c22c50d90ba0f4fb8cf9cfd4561Virustotal results 15.71% Heodo
2022-02-25koqf5cszFpGmax.dlldll f0609da3d26b40824c994874cd933553b4e40585c837e5209a3f34831fc4dd99n/a Heodo
2022-02-25vP2YnmwGQ447BMR.dlldll ac0ba7cf88be8d02f7eb162db19532f5514b186fc5f476dc1b9c26212a9fd0acVirustotal results 10.14% Heodo
2022-02-251julXAF6.dlldll e42731335122f3dbeea5124d46c12ea0eaf8a4ae289af96bfd11ad20fe855408Virustotal results 11.59% Heodo
2022-02-25DObj.dlldll 2c08988e554dc91e11263752510b5c88eb89e97beaddfd7140780ef77daf5ca6Virustotal results 11.59%Heodo
2022-02-24TEnh2B9zS2IEzWDrt.dlldll bf44d5ff355c18eadc76f83b7880d7d300c2eed8c9ad63c5cdc24e8692c48ee4Virustotal results 8.82% Heodo
2022-02-24tRFcAoJbt30cK.dlldll 1f3ceb1495a34de8a8c52e9e333028b50da280d70f6953f95ac3b4dd3a665e0dn/aHeodo
2022-02-24gPaYB.dlldll 066877fc056d819f9d5a877d9ea0b5ee11a04ddde1d0700679d33fd7df6ee130n/a Heodo