URLhaus Database

You are currently viewing the URLhaus database entry for https://uzamart.com/indrawal/GZ7bN0V68oRpN7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2076390
URL: https://uzamart.com/indrawal/GZ7bN0V68oRpN7/
URL Status:Offline
Host: uzamart.com
Date added:2022-03-04 18:29:06 UTC
Last online:2022-03-05 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-04 18:30:16 UTC to abuse{at}cloudflare[dot]com)
Takedown time:12 hours, 34 minutes Good (down since 2022-03-05 07:05:10 UTC)
Tags:emotet link epoch5 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-05G4VCR.dlldll 10df35ff66d1b7e2474350a604940c0a343ee1ab75b812454afbc987dc92eb7bn/a Heodo
2022-03-05VrbFumhKL7RAguB1.dlldll 456f8a82d71b35514dc9e44d82f3da265a26f08728cee468d874d792e537c38cn/a Heodo
2022-03-05a621Pga1sr.dlldll 0a7b3dd350a741a8fb659bdfaff1e01bcc22141b7e5aec15fa930372e6184c53n/a Heodo
2022-03-05l0ew.dlldll de06b603f7978becd8f9bce4ed5049ad9e7abfce30574942216d924a4fc40113n/a Heodo
2022-03-0544m.dlldll eead2b865095d2e2d380ee13ed16398d72a68bda38900f7e447f4388905db54dn/a Heodo
2022-03-05URzkoZurY8SEqxGp.dlldll 5e11f267b6f9a3d23010f5c58483c530d4e96836009cff1e94b78aafa084b6a0n/a Heodo
2022-03-05OKPbFrjjNllVSB9i.dlldll 4eadc0286e7ef080345ef1bd8470bb3f19c16b8a8e8deb6590d3730f97cf4dd6n/a Heodo
2022-03-05Q6HZhaDLQfFy9.dlldll 7ce8ffaf1ae37987cb2a1daab384c834e8982419bd411fd98d61428fcfc0b03en/a Heodo
2022-03-05jzkgoIyUPsLVpf.dlldll 167712e766407261dcd7ff47fb60fafdb1aed63d61723e4126870ab1d502bcdcn/a Heodo
2022-03-057UPPPPd7ENr6lXGbB.dlldll 515ecb1f60a79a8544bbd9740e063078b563c0fb63f2559ba203d5f480edf193n/a Heodo
2022-03-05Oq5.dlldll cef2ff5fc72aebe43eb3eecd13350206239b0608766368d1e568503e11e38f0dn/a Heodo
2022-03-05lj5p.dlldll 031600b5980adae8f30a7c729ee152e37bb5cb4d06d9c0f6176f2f40e832e94an/a Heodo
2022-03-05juppo.dlldll e05b17cfa53636e28c99c3c4833734523b633a7afecb77f4d27fa9b120ba6707Virustotal results 18.84%Heodo
2022-03-04F1VqRwYfgWGXP33.dlldll ba20bc8a730925414c5a7762b1cee89a90b104fe36e398733f8eb955d4788188Virustotal results 19.12% Heodo
2022-03-04NHEcHSWD.dlldll f1470268a7a95ce9a2f0f95ce3db31acfe1a2fd4b9751297e7d5168a16560de1n/a Heodo
2022-03-04xwu.dlldll b0ff6bd45c81ffa042bb57ae7b934c658197061dcfe57fd76cd50026308fed5fVirustotal results 15.94% Heodo
2022-03-04iHfSWE.dlldll 48df203f88c17decb12730c4a9fa5a0bc90372421e3ba9e8c9738dd8927d2756Virustotal results 17.39% Heodo
2022-03-04rA4qC0eDBabrIer6G.dlldll 2379f4105578f516684fb5cd564a9072954c9e798dc1cec9a4329c27c0c3aec2Virustotal results 17.39% Heodo
2022-03-04sdraJqQ6Tb0SaieYsZ.dlldll cee11b9190c2d85a477eb024ccb4f0b711d4debd18db84096d70dcbea47cd258Virustotal results 14.71% Heodo
2022-03-04InTMSlx.dlldll bf6ec7a682f3db924930c5fb9dec8d66066620fd3f8cfa1e073fa5c3803bdbf1Virustotal results 13.43% Heodo
2022-03-04WO8pW9F8w9oiwwBXCWM.dlldll 22d084861a3366637737670c8427a40635a8dbaab8431d9ed5e6fa6e450d6886n/a Heodo
2022-03-04a8iFBXXMS.dlldll 874ee3868f71cdb23a1bc7386fdccdb8b99f16d25bdcd6efb0caddd40ea71bc0Virustotal results 11.76% Heodo
2022-03-04rAWNimqV5KUaIEZd5.dlldll 02efa81e04ca09f6a07e881ca70f9415962b589beb8017e520b1ab1eff321b9en/a Heodo
2022-03-041727H.dlldll e9da3518c51b70214e4934357817a665c323b1ed316ce772b9ac8fb771a61d80n/a Heodo