URLhaus Database

You are currently viewing the URLhaus database entry for http://pinkivpn.xyz/cgi-bin/wINgH8nEworlOOO609/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2074019
URL: http://pinkivpn.xyz/cgi-bin/wINgH8nEworlOOO609/
URL Status:Offline
Host: pinkivpn.xyz
Date added:2022-03-03 14:32:11 UTC
Last online:2022-03-04 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-03 14:33:15 UTC to abuse{at}quadranet[dot]com)
Takedown time:10 hours, 46 minutes Good (down since 2022-03-04 01:19:40 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-047HyIaZhuPz.dlldll a95f39187d962690f85ff39b1e77a03e447df1a097004ed43c521c3239f40476n/a Heodo
2022-03-04aVwNPgMvBRyo9tOjHg.dlldll 385dea7cdee0fecfa87a3c2a134c1b5c1cba20c326d999537503543f6154aa5dVirustotal results 11.76% Heodo
2022-03-03BRmWfJ8JyFW4rxT.dlldll e1784908015dec1786d1a710de1a891fe7431c40ba7f0f6688954a07851f3c18Virustotal results 13.04% Heodo
2022-03-039wNB61cjz1.dlldll e51a064c8a18624d0a646b968e6f3d9e43204aab77f9fc979dc7aeef91cc6113n/a Heodo
2022-03-03NSZXXYArQGKT.dlldll 2d1cdc174410c9ac3635239aa3cad4e7a3b775c88511614d29b885f85341eec9n/a Heodo
2022-03-03anHUq0aIAMul.dlldll d23ef2576217ed28812abdef1e799e52f4129abe09ead9582ed31224bc685735Virustotal results 10.14% Heodo
2022-03-033MQ3zf3R.dlldll e2ae4522e9caa05be2173925351413f4a13fbca9474ee492ba1ad400aab258f8Virustotal results 8.70% Heodo
2022-03-03yRyzKVfPG1YaqSsMuS.dlldll acee566c60b0374d326ef4cff2a8df9078d4476fb855545996a5ee646deeb3d6n/a Heodo
2022-03-032pzDsnngGA.dlldll 89641d2df8561bc411e900943f5691b773c3c16fc731b62213d82f3c9f60867en/a Heodo
2022-03-03QjWpK.dlldll 92f2859f06dff8702ece5b24d213eed1a3f012b5d15b1d3836290dea5cc360fdVirustotal results 18.57% Heodo
2022-03-03YGRs.dlldll 970dbb6df8f43e94afe2468847857747bee34268de9a2f21bc9db7ff9e05288aVirustotal results 17.14% Heodo
2022-03-03QSKV0Gf.dlldll 62063cf94fbd342ee7ccf3b4f3785024800b4632d9ebe07db1415ff8eee1f69aVirustotal results 20.29% Heodo
2022-03-039Xey8aKaiNbo2WmSIA.dlldll c2e067b5e6172b2608600c395d4559a8ff53139866447945e7e9ffe7485afcfbVirustotal results 20.00% Heodo
2022-03-03F9tgT7C.dlldll 8d6525ba7990c991d76e2b05b6f370f37ba8cad45c0144c389f8e77d31c924faVirustotal results 12.86% Heodo
2022-03-034h7bWkfS.dlldll 65be26abd43063c0b17eb9152457f0119a896f17741b8b9e125da757dd5a5200Virustotal results 14.29% Heodo
2022-03-03Gu9Wl9.dlldll bb65e2af1420bffa928202fbd2a9266f56bd3ef5fddf9166223dd59bacbbbd4aVirustotal results 20.00% Heodo
2022-03-03VKfAgsAb.dlldll b6528c85753762c0367ad003ae6706579cc3a45bc7ba83c684b8baaeacf08ff7Virustotal results 12.86% Heodo
2022-03-03TSlFTdmR9J.dlldll ad47e82fd670e82b240420a7d9dc8c3e44e7ba11180936c6e106740e816a96c2Virustotal results 13.04%Heodo
2022-03-038KtbBQ4Za0goQuIGZ.dlldll 95637c0f5702404198f6dae8ed5a328eb75a3411271fe6d3ef583c8845a6ac92n/a Heodo