URLhaus Database

You are currently viewing the URLhaus database entry for http://trainingchallenges.xyz/wp-admin/ebPbsOdsRJA9G/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2074524
URL: http://trainingchallenges.xyz/wp-admin/ebPbsOdsRJA9G/
URL Status:Offline
Host: trainingchallenges.xyz
Date added:2022-03-03 20:29:11 UTC
Last online:2022-03-04 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-03 20:30:18 UTC to abuse{at}ovh[dot]net)
Takedown time:4 hours, 28 minutes Good (down since 2022-03-04 00:59:06 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-0430scur67H.dlldll 3354438476312a8ee8d8248a6b9a1e7764d745cf8307109ce781f3b08c5dd6daVirustotal results 11.76% Heodo
2022-03-03rWgRmyCmxSG9Gua034d6uAx4uzznwfuU.dlldll 0462502e813eec3840ef3d592feef29d6b062d93e0a5f64cb3ccc37afa6802a9n/a Heodo
2022-03-03MgFpKgCV69XoP1s6KOxHga.dlldll 239ddda77c61e9084ca537582eb050a918f0abc797253669205ab251fb952e00n/a Heodo
2022-03-03gZWRLgRp3pR6gWBROR6QTzirXuwrGrS.dlldll 51654c39f5343817340459aca97447452b5935b3c7372b3ea26cc98dbb7ca0b2Virustotal results 11.59% Heodo
2022-03-03YpRRbaYIiJJJPcRNJrRKEk5LZFJo.dlldll 1490f0b2cbabb0114be8bc999f651b956410982ff69325dc55432d0d921c2677n/a Heodo
2022-03-03zzX4h2lgtb6tdaKuzwCgN4xCrloO8qKnqp.dlldll 0039477291d4891510d0def236ca9b3610cfcfb8e39c094693aa4d84de9ea785n/a Heodo
2022-03-03YYUkqfkvNcig.dlldll 305af9404a6faedb5e5f2e75d1d41eb38c6d69db6abbf8f84ae8de4a3f82bba2Virustotal results 11.59%Heodo
2022-03-032pntoVR2hhxSSDDQht7qyrgH2mFNHHaHb.dlldll 88e1ef12af46249567d9b2dae11dab27d43422cc67e56bf7ce98988c8e9d6a65n/a Heodo
2022-03-03SAD3xbbUyhBe14YV5GM.dlldll e87d6207d707f05079b80b510a381feb2d5ff996a741bf135bbec7c4634c082an/a Heodo