URLhaus Database

You are currently viewing the URLhaus database entry for https://collision-staging.com/wp-content/94PQ1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2072335
URL: https://collision-staging.com/wp-content/94PQ1/
URL Status:Offline
Host: collision-staging.com
Date added:2022-03-03 07:50:10 UTC
Last online:2022-03-03 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-03 07:51:20 UTC to abuse{at}cloudflare[dot]com)
Takedown time:14 hours, 19 minutes Good (down since 2022-03-03 22:10:31 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-03WCpImyfi3hoofIW0.dlldll ae65ba37e0dc4c611e52fb47c0553c338296f91dc0665f070eec816da8e1bedcVirustotal results 17.39% Heodo
2022-03-03aDenuL8Ilz.dlldll ab48a1aacb180a6324e3d5c5bd8daaf122d067d0db31a3ad43e3cfb176ef22caVirustotal results 18.57% Heodo
2022-03-03Gl2s07SPtjfKMQg.dlldll 90ee703d35e05d5db72e823fe0866bc57c7df11a2c5bfdbd96312a0a99a56c9cVirustotal results 17.91% Heodo
2022-03-03SoRZTA2A2sI2pz8xz.dlldll 86b13447371a6b99377353d9729d7573ff14413e86a9c055895d63efbbc5b8a1n/a Heodo
2022-03-030zQpwzviCiSA.dlldll ed7b34c49b48ce509fc2e317de2e21dcf7ce7cd6eeccffa98ccc927d5e1eb7c5Virustotal results 17.14% Heodo
2022-03-03yoal3NBV36NGwD.dlldll 1871eebe41c564646c2b09c224fa2beb2932c07863239938d8116c13b4d1e6c2Virustotal results 13.04% Heodo
2022-03-030CZN7HOAPSP.dlldll 81274802cd2e7adb4759bc108f4b6c5fb404db9eac1b2f407f105cfafcf9ef30Virustotal results 11.59% Heodo
2022-03-0305LK6ja.dlldll a628ca0025236beb576a544bf45458591729a5c6a0a305ee31a8d62b0365997aVirustotal results 8.70% Heodo
2022-03-03mhlB8OKwXwixk11JMG.dlldll 37c777201735db787d18047166b373125a5ea923fec4a8b785b5a9152790e35fVirustotal results 8.57% Heodo
2022-03-03Tw3vAaEwIXFQ.dlldll 6da40de84d688d805f010a41ea3f8f9290f3ae9a9b0e4f5a53f91a71d870c98cVirustotal results 8.70% Heodo
2022-03-03XqbF4.dlldll 0f3e0d7d885b18e9140efcaba925ee8a6425cacd6387e8f3a1d56734e99dd84aVirustotal results 8.70% Heodo
2022-03-03KrfmXdQc6DLPg.dlldll d8bf43d03bfa724bf55d5fe373a3fb606d475e45b806a0d67a831437f1ad5ce5Virustotal results 5.80% Heodo
2022-03-039Ij6DUKR28Dt1aZy.dlldll a9a2feae352b2e749281f340e800a342a88d156e76cac019c3ba29cd82bc41fdVirustotal results 18.57% Heodo
2022-03-03PynDV.dlldll 97a0dfbd4751b06e6321cfbc8bf7a8c787a731567fa31a0af4fbb1cd4f1f7c5eVirustotal results 18.84%Heodo
2022-03-03DxKX7R4CZ.dlldll a0ea0fd1ed4bd73b43a7514875b578a259da6b6c4aa4fa197532c73c6c54866fn/a Heodo