URLhaus Database

You are currently viewing the URLhaus database entry for http://curtistreeclimbing.com/css/2oFtx1t5P8qcVKnCl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2070323
URL: http://curtistreeclimbing.com/css/2oFtx1t5P8qcVKnCl/
URL Status:Offline
Host: curtistreeclimbing.com
Date added:2022-03-02 07:32:08 UTC
Last online:2022-03-02 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-02 07:33:12 UTC to abuse{at}hivelocity[dot]net)
Takedown time:5 hours, 46 minutes Good (down since 2022-03-02 13:19:25 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-02xtvs1K.dlldll a210daa910810268d87f0a61658cfc6b6f148ba7d841a0fa466565e2b3737a68Virustotal results 8.70% Heodo
2022-03-02jz5N.dlldll 28c6ad331ff983ac7bf5731b23e5e4a6b356ebd65f5e20e63439544df3aec6b6n/a Heodo
2022-03-02g8wf2cbW.dlldll 13fb0293243c060fa6b7ac7031807fadfb4f0a16c41caaeaed68999630f7255cn/a Heodo
2022-03-02C2jmtx.dlldll e46948c2dcc09c367287db99cfbf7d4e37b89a1b144944e40b0feca165a1b1daVirustotal results 10.29% Heodo
2022-03-02qHbbNg33QnZzX.dlldll a2fd65a18bbe05c7992e8392b61b265e1d76dd731a314fe280044bf13e0cf030Virustotal results 28.99% Heodo
2022-03-02YYYL0LDPp.dlldll 230434ce27dec2ca06fa3be895a9efd946b19137a838d82513118a1ac478c09aVirustotal results 30.43% Heodo
2022-03-02em2.dlldll 7e39395edb50b604aac446799b067c51a93852aca046144010084bdba04f512cn/aHeodo
2022-03-024wYsXTsTk1WjuQxFOn1.dlldll db4e07e81230e10a1b819a392645ab965c491e1ce1c47a06aa2e621a9801f8f7n/a Heodo
2022-03-02P9Hf5Max3tRBHBXZpZ.dlldll 378a527e56fd421e68a472ef33fd87ea257705e95eb1f72c16ee3f55b8645c08n/a Heodo
2022-03-02oEOKcA6x7FBUMAU4z6.dlldll 463883682ce0eda6c35133304491401c28d4e465886ae4e765b33411e354e709n/a Heodo
2022-03-02lZazfcMP.dlldll 243e50c15e7d0cd47e5c98604a8ccbdb80ebf8e95525422ac6608604d1282ae9n/a Heodo
2022-03-02yOaWNsfkv95.dlldll ff7276b36ec949ec924354e54c22208e85733b799e84f130fe90d24eb28b01d1n/a Heodo
2022-03-0290p2e.dlldll b202fdfd2b3720e18d04929cf02b5b0350f5e77ade6291fb790e4fc1ce1e234dn/a Heodo
2022-03-02fNG5qVV.dlldll 22a8f3533458167ac369746625d6c2dae75e097bf7878370817e11f49c4cfe0bn/a Heodo