URLhaus Database

You are currently viewing the URLhaus database entry for http://51.222.72.232/wp-includes/enHLtcZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2076975
URL: http://51.222.72.232/wp-includes/enHLtcZ/
URL Status:Offline
Host: 51.222.72.232
Date added:2022-03-05 00:57:04 UTC
Last online:2022-12-12 23:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-05 00:58:06 UTC to abuse{at}ovh[dot]net)
Takedown time:9 months, 12 days, 22 hours, 53 minutes Bad (down since 2022-12-12 23:51:35 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-12-08n/ajs 252cf566d6d35fe58730d0806d57a8812c8780a2486efde0ac3654eae60159feVirustotal results 1.64% 
2022-12-07n/ajs 90a6762eb91605c331ccceabbeec2e0f2b30c3b4f444f364d6fa0bd5cc9b01a6Virustotal results 1.64% 
2022-12-07n/ajs 8ec58652a1f84759c45068f2c95c9a8acc452d69f0f95de746403b6cfbf8877bVirustotal results 1.64% 
2022-12-06n/ajs 7de7c4d02f7e36a20f763172178dc206f79331c55d4aab505837e6548a10bbden/a 
2022-12-02n/ajs 4ff2bab4e31727f87697ddd8d30980a772cf4c01fd8573d0cc6beed0e2d8858dVirustotal results 1.64% 
2022-12-02n/ajs e6862b1f54c77529d67cf3cfa39c15239f9ad26ff402446796bfe4596a63001eVirustotal results 1.64% 
2022-12-02n/ajs 34f900d06849125941f3f1d56a8da26873f8e750ed1628537580a29a455623f1Virustotal results 1.64% 
2022-12-01n/ajs cebfb62b37f9f1f0bb2d22fde84dbf3ecefedcd9e167e080e2544ac049ffaca1n/a 
2022-12-01n/ajs 8c645c8985b7a76bab0204fbadf102863cbc30fc32e2c238666202944a476fb0Virustotal results 8.20% 
2022-12-01n/ajs e784b1a75528ca2c36e0d91d7b74e50bcbfdd374a5248f3d1ac667366b9c393en/a 
2022-11-17n/ajs 0ee679884ef870cff17e2bc56c7e9ffe298e2328655ea28a7a127b46a18345d5Virustotal results 1.64% 
2022-03-05UKA7hLtnTkjDG7qFfFUFr5.dlldll 78b06c97d96e8e85ee35ee3f01b0da837b357cdb39ab128514e39d80cb0f6135n/aHeodo