URLhaus Database

You are currently viewing the URLhaus database entry for https://updatesgarmin.com/c/X5oK7bz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2068406
URL: https://updatesgarmin.com/c/X5oK7bz/
URL Status:Offline
Host: updatesgarmin.com
Date added:2022-03-01 09:41:04 UTC
Last online:2022-03-01 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2022-03-01 09:42:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:7 hours, 29 minutes Good (down since 2022-03-01 17:11:58 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-01LVfJsFB1DBdCmUvt.dlldll 98ff36313f4ae111966ea3584c1a9021c3ea6be13935f1485949dd69555250fen/a Heodo
2022-03-01I7tnQt.dlldll e4c4dcca251e2310e44aa93f81057b3b15dc27cfb036a4c234a178f8afe73709n/a Heodo
2022-03-01kcaBbymm1.dlldll 5e997093b5eb50582d79a51afcd41fd145edcac935d7ab2aa8be5277c8cd03bdn/a Heodo
2022-03-01hGQgtwzGPk5zJAv.dlldll 5b843bab058e9fe5b5f269b5ce6019a426719866a29445fa8fe4465de196a4d1n/a Heodo
2022-03-01bddADvw.dlldll 9b18bb21e7bacaee4ad3a1582949e512304490d46ea56327e3e26c3884bcdc01n/a Heodo
2022-03-01X9SOElzZ.dlldll d064ce17f078d1492f40d7d968f4c796fb8c38c9fb06cb17aaff8df172b9c7b0n/a Heodo
2022-03-01Ls9XbNsIU002IyiqN.dlldll f6a032f5df449ec86a47ab24266499a0e4ae00da591d7cf233faa54b56e11cben/a Heodo
2022-03-01kcCaORenj3YPL.dlldll 684fe82407e7893e7bd79856380691b47394745a234069e24f3d15cc49ca5b87n/a Heodo
2022-03-01inqzPaBpXXZF286Ce.dlldll feb8f2202543f98969cc4840cad0e120981577a8e698a0c9e50a8a68f4e7015aVirustotal results 27.14% Heodo
2022-03-014J0.dlldll 2b176502d79f3f09f38c07fd61c46546d2cb76b76c1e0a2b5d928d35a293b35en/a Heodo
2022-03-01BUH679jD.dlldll f1cd058b4ecc7b9cccbe8637d5a229c970f0613acfd6683e0913a5f007bfceb7Virustotal results 28.57%Heodo
2022-03-01I10vYUtOHmrV.dlldll 329efea3adc02bc65c90822bc806668313134696b62925950336626d15368432Virustotal results 24.29% Heodo
2022-03-01g2O.dlldll 66d05a8768f43a23342451af0e1c276530bb9f283346665c9b9308c7e1645f4fn/a Heodo
2022-03-01fgKV2okN5hWmUiz2p.dlldll cb4402ff5ab62a22c3cf2b26c5099ed454f96f7c6a14dd6f329708648e20eac5n/a Heodo
2022-03-01rll6NQLTVIi.dlldll 32ef028b2e99fb24ef94aff64146be956152bcce5c1ab8af91f5023f89e71f56n/aHeodo