URLhaus Database

You are currently viewing the URLhaus database entry for http://spbtorg.com/vzgsz/uq4fosqbjwAM5rnw5m/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2069510
URL: http://spbtorg.com/vzgsz/uq4fosqbjwAM5rnw5m/
URL Status:Offline
Host: spbtorg.com
Date added:2022-03-01 21:30:09 UTC
Last online:2022-03-02 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-01 21:31:14 UTC to abuse{at}reg[dot]ru)
Takedown time:16 hours, 17 minutes Good (down since 2022-03-02 13:48:56 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-02dpHf52pjwCuAI.dlldll 61504d07c3c9c9a689b5d7bde8a1d176c01e4c305e974c3864497fe013b2e4bdn/a Heodo
2022-03-02GroXSMgtO6N.dlldll c1f92550e568ef0016490cf2d43ab5712ebb52dd06e59a223529c85875529f00n/a Heodo
2022-03-02wbPuqcbh.dlldll 2e553d830f0cf37c62626acf4d3686f215dac76695499e4618b1242d4b235bf0n/a Heodo
2022-03-02SPys03E24OE.dlldll 9cb337aa16395ce4861d11ee4d3e4f3ddbb3bf590ff79a407eb5ade2e3cc334fn/a Heodo
2022-03-02mbfrksl5zOkh2mhQo7m.dlldll 13cd733ac3c6ffc4eca187c5b7c5236c8e4c9878249dbdaee0248af0e4ef7c41n/a Heodo
2022-03-02UlppPZK.dlldll ca54a76cdcb0ff686a3a6c5302d07fdb1b5fc965d3678c4c62f808208553c9b9n/a Heodo
2022-03-02RNeSfXng0yULS.dlldll 2611910739ac9a95a0d95f0e5775589ff3c4e99d70d5a406056355a746c49354n/a Heodo
2022-03-02NUfcUq38HI.dlldll c0d6675588799fd3828304b43caf095c9c49d83f542e42ea0a68f8b9e8a33caeVirustotal results 24.64% Heodo
2022-03-02flOhl30k3quXSQjm9.dlldll 4ab5b87d6befd5de6c584f27c011f9eb2e74a8d20e7463e89d697a5e7634a23cn/a Heodo
2022-03-02EX3FvhR5ufUafC.dlldll 925c4b737fda7f139f4e705eac0cdc11a98cc580884750f0c3f97ce129e44936n/a Heodo
2022-03-02f9RqX5ukqpg.dlldll bf5e7f88b8897724009a559d77ffa71544bc3cafa31d79d303334f7ca01c8716n/a Heodo
2022-03-02ptTSy7jb4DKtiIsE.dlldll c3a38e0ac6d79873a28fddbeb80c2f849b1fcf77313179fb6d52eb674bf046f9n/a Heodo
2022-03-02ssQzyqjnfWYB5yd.dlldll 6c22113ab663b79f33fdcefe05404e885eb556390097e929d1fed816ab49bd95n/a Heodo
2022-03-02v7K0FO.dlldll 20b7396c9c6519f3a6b44209f1bc1ea39af75fcf574fbbe9c88720427a9ba32en/a Heodo
2022-03-02gyZVohY3U7jJK.dlldll 4611fa3302526ae0055f77d4ab14699511e9536d6d366a88bcb7d698dff98c93n/a Heodo
2022-03-02an0gHnN.dlldll 8a2521060ac3dca2192efd3b93bad56c375e1c052e5725d36d890a4c58fcbcfen/a Heodo
2022-03-02x2o.dlldll df7918e874433b231e34087f9ebea2cd89a68056d6787e6b38de9b6be4f1c66en/a Heodo
2022-03-024UkKjzpLVBSr3.dlldll ebebefe83f29bfb6789865b67dd19f14de8d0dc98b96fe20083ec514dcf7d78cn/a Heodo
2022-03-02RJSL99dm74H8Jnwz.dlldll ce5a00fb0995ae94ddf2738749f8b199237b69159ee6b3ac9e3ab07be0e078cdn/a Heodo
2022-03-02hz0q6D.dlldll 511c55b723c9b970e95b2198dd09b5f14dcb7e1e3ed29f8b4b43314b84b2f418n/a Heodo
2022-03-022ZdIiiWK.dlldll eea2726e9d4156d457f23ebef9f6e523a7e3866f3f1aaf3c050655def84ce2d8n/a Heodo
2022-03-02rBL.dlldll ef9efb099f9cabf2684c24d6f45ac1b96483730373ab4b853b72db7095f51550n/a Heodo
2022-03-02Xud.dlldll c8185275e45b71d12150c9e4d0fd1b07e2601aef42a31f021285732d3c666d6fn/a Heodo
2022-03-02cSFaH.dlldll a789de0429216cc5a8881a33ee851a79f09ec0d989c79a3e702e7e0eb126b079n/a Heodo
2022-03-024FJ3iGcHfWRCqiDkWGL.dlldll 59cf2776f293edb064d44a5ba85483343a9b641d18c326ac11ecb7dc2045a39bn/a Heodo
2022-03-023kwt1T38.dlldll 74dce346b578a47fc5b108031a6019f30295670c415e13b7336607a234c02595n/a Heodo
2022-03-02uYMISSZsB.dlldll a42eb8240638cc1953c93275adac5500b55ed8664f33a0dab7c5e7685a860d1eVirustotal results 11.59% Heodo
2022-03-02gzgJTmD2ys.dlldll 4c247c909dca3c34ffa3323f1032a9ac636a4ce16e941e241ae40e624ad313e0n/a Heodo
2022-03-02W7QtDp.dlldll 52267f6449a557f78c9ce47d2cd4cb61066d2b86dbacbaa13e9396e9fb9ccb2bn/a Heodo
2022-03-01gJYX88QSI.dlldll a5d457d37997bb51ee05e3236e65dd1704dcdaaba66cc0cef2e5f7bf335a0f24n/a Heodo
2022-03-017g8oexnrBd37xHA.dlldll 4ca3cdd00c915949777b9534d23d33d56949673d42c918cf66b6ebc2b131ff1dn/a Heodo
2022-03-01bQejR7GgyCdz.dlldll ce921f09f3475cde84431edce0978ff2f3c3847fc64af6eb86f777b0ba09f289n/a Heodo
2022-03-01Xcty.dlldll f4f707f88990f2614ea967b4e9706c894058ffb4233258716b0c834e75b190c8n/a Heodo
2022-03-01wONqqiQXrQvViQ.dlldll 68656e6f8f00cb3db6e37ce9b33a646da0e27c72a67d9ac5894b3c4d71f31214n/a Heodo
2022-03-0131at5UB.dlldll c7f6b7799d797c9ffee5db51fa9392106bfa73363b718a53756d8666a9ad3fe7n/aHeodo
2022-03-01XYsT5c222uh50Cn.dlldll 4f8c84bfcf84130674d923ca1187f0b82248f3b88de49353fd2492ac36a70c2fn/a Heodo