URLhaus Database

You are currently viewing the URLhaus database entry for http://diacrestgroup.com/ggv3rjy/9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2068936
URL: http://diacrestgroup.com/ggv3rjy/9/
URL Status:Offline
Host: diacrestgroup.com
Date added:2022-03-01 15:06:05 UTC
Last online:2023-01-21 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-01 15:07:07 UTC to abuse{at}hetzner[dot]com)
Takedown time:10 months, 25 days, 20 hours, 19 minutes Bad (down since 2023-01-21 11:26:17 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-01B7tYH11h5gzY1sx.dlldll d9381d778e21373428040d10d06da1f739cd527686797aaeaae93a4a9698bb40Virustotal results 20.00% Heodo
2022-03-01OWzd6KiyjVAlIxlJipIZCduj8vXdnnO.dlldll 083cc143e1685bae669bd4423f49ce99b73c488b8622b3a50f47bfad122b4f90Virustotal results 17.39% Heodo
2022-03-01KlqfRPqJ31H7PSoqq.dlldll a9e680a2309f5487d5331f5a1c5c5520261df77292147588979c0b5bd11f8ee6Virustotal results 19.12%Heodo
2022-03-01wpQYF1oVC.dlldll b71e00c6a5c77a5e91a4f0eafe0cec1817406ba2b187dac166becfcd50600296n/a Heodo
2022-03-01vvRZnHi9Xfgsp1iiibIGq8phSA.dlldll 8f514a684759be70f66fbced90ce93045b1277a878a8dc706d0fd397c1eade65n/a Heodo