URLhaus Database

You are currently viewing the URLhaus database entry for http://ctha.uy/cgi-bin/zGhvZLq6kSV1L1Vi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2089643
URL: http://ctha.uy/cgi-bin/zGhvZLq6kSV1L1Vi/
URL Status:Offline
Host: ctha.uy
Date added:2022-03-11 07:19:09 UTC
Last online:2022-04-21 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-11 07:20:22 UTC to abuse{at}hostgator[dot]com)
Takedown time:1 month, 11 days, 6 hours, 42 minutes Bad (down since 2022-04-21 14:02:54 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-26jH77q.dlldll ffe85564222c2797d9a977369ec42ef100eeac04c151bc5947ba225e65578482n/a Heodo
2022-03-12HKhl.dlldll ca5c2886c486d692b94e606cae9e111f8194371bd5187d8e5241785409f1cb6an/a Heodo
2022-03-12mrQQILyvMtEQKC.dlldll 8f83ad2e4ef88f7f356d9e5bfe59be4afeb3a3690d48d164de367c62a858c972n/a Heodo
2022-03-12WaMb2h.dlldll 9b7b622ab4a362fd612fa65a8536e052983175b5c8af5351f83528ba21a7799bn/a Heodo
2022-03-12FFyfZCdu4EU5SxUkK.dlldll 145d7753cd237795e0093475a2ef112d8f7f3a5bd9cb4ea839db21a5121619dcn/a Heodo
2022-03-12A1AATSO6Aw8QV.dlldll fd0e5bb69bbc685e5c267f28c2ed1a72449d3b5fb71d3fd012a4ec8f6b4bfdfbn/a Heodo
2022-03-122A6bQZx.dlldll 365d9a4e610672480454f3734b5e74f233fdbf755ba602561cb13358be632610n/a Heodo
2022-03-1213dKxyIh.dlldll f677ce2903ff060ae40eba6e2df620ba3a5043a5f996690b2bdc188c64e86027n/a Heodo
2022-03-11Pxpy6.dlldll e024125bb1a77cc89bd83ae4ffb77ecfd4d234b6549eab68844e4502cab815a8Virustotal results 16.67% Heodo
2022-03-11iCLc2iyWo3igA0.dlldll 7043a6fd369384a7df86a41456fed85c18ccd0f5fda48ce67f662b5822a524b6Virustotal results 15.15% Heodo
2022-03-11453q2xFDKEiFAcc.dlldll 8e491f07ffcb428b3fb564498047ea53c55a4b2e8c66dd1634aafa926ef6323eVirustotal results 15.15% Heodo
2022-03-11FRepHnt.dlldll f90b183a528728f26e61e4214e12ee0dc8470f15f223087d2d81b46fa6ec702aVirustotal results 16.67% Heodo
2022-03-11dlbqigroTW6Uv.dlldll edd4e376e90316360d2ffa2aceaf474d727b6865ec550423c26346aa63073265Virustotal results 16.67% Heodo
2022-03-11hmU4vaSeop7XV3b.dlldll 7bed573d916327eee67f5acf07fdb4a3c1bd129a3e64d283f928e13db5a3190cVirustotal results 15.38% Heodo
2022-03-113EOql6xpKru.dlldll fee60a3e4f19e9c9786fe6aba1c770c7fa5a296221b2545c8a492ec9285fb274Virustotal results 15.15% Heodo
2022-03-11zO7H3FNyj9Dr.dlldll 0cdfb0992d01cdcf78217f1420539be7a1d438c3b0a3606de8b86f4b84357136Virustotal results 25.76% Heodo
2022-03-11FkQQOMI.dlldll b2496c2dedf2cd73fee94c73ab6e7ab00e65a5e58955013bc544b7fa80efadb2Virustotal results 20.90% Heodo
2022-03-11kPUznYkt43s9Rpvcsyv.dlldll 00cb4ebe8dd7697d369b1f849446f7ab330d58ef687f1ed1bd4193c59bf2502cVirustotal results 19.40% Heodo
2022-03-11Y4IhiVJ1uPA1hB.dlldll 1ca90b321e217f776dca0886ff181f13e8b1ae8fef3843fafb210ebbb6a74dd6Virustotal results 20.90% Heodo
2022-03-11GVCxDdcSFr2koDAqB.dlldll 75fa638c2c3044e5393b258ebb5702ca02974f4751041a6fd451ef00d1c93f86Virustotal results 20.90% Heodo
2022-03-110LcuiF3NCRcVjQx.dlldll a95e27b92086bfa3d7101de6d0bd4d8c7a1329d4175da8099749f1199eebd644n/a Heodo
2022-03-11c2Kh7VzTyxuVbUMiTEn.dlldll 1833742301b5a6cf36ee30dc27560644211bf515fb4a85a288190704c90e32d8n/a Heodo
2022-03-11tiZycrwkSoAoxxm.dlldll 23d1a623921f36a30639ebe0c14ab19a4974d67db69df20b0c714c93bcd66754Virustotal results 15.15% Heodo
2022-03-11upDkk3rW0U9bR888vL.dlldll 6cf1ffcdf00f1459f821e6ef11fd79de824990c503f526301d43de0209ceaf79Virustotal results 15.38% Heodo
2022-03-11XJTLiRh88OmxfEgR7Z.dlldll 24ee1c711354df5f61eaebb53c5be2c5dac2e24a499ee92f0db893ef0f1d14a3Virustotal results 13.64% Heodo
2022-03-118S22BV.dlldll a0d94cbcf6b54c29f7026952e63f4e7f739f11c1e18cceeede081f0883426251Virustotal results 15.38% Heodo
2022-03-11V0M.dlldll d17431e439e59b4a4c1fdc3beebcd1309c63b40f3f5f7830364ef61e8368086bVirustotal results 12.12% Heodo
2022-03-11CaeVR12tmDzj4wXDnHE.dlldll 943815fcd525ffc4743024a3be6e06ae0ddeabca98c1c5cb90b733bff372ca5cVirustotal results 12.12% Heodo
2022-03-11eACcTMnfd8ymkgNuFpV.dlldll e7fc168ff08e1d7bfdd0046e3d9d3e811915c104762019af7e00609f0a61e43cVirustotal results 12.31% Heodo
2022-03-111mnW79z.dlldll 3f23f1df61a1a333321c936244b97f2b40f9ce4bfd1c740c4a0664e9dd40e872Virustotal results 12.31% Heodo
2022-03-118nTadN.dlldll 6f431b6484ac73e397b2a39fe9bea1965bc6865d23dfafe1c4c8d7c3347a1833n/a Heodo
2022-03-118I2TH.dlldll 35ae0ec19381c8e3ccb0023610783680f456263240c7e29f6afbd47ba9c21211Virustotal results 10.61%Heodo
2022-03-11GTllSYTw4q5.dlldll 351e5679c5ba77a33d2fe5b0ff41b689597ef7905b8b51593821dbc59ad69ad2Virustotal results 12.12% Heodo
2022-03-11PFHKwETUnEGxVYYxr8s.dlldll 9f7cbefa02be664d6fddd781bfef6849c6cb4b95efe3df6c774ef8128b90f7f0n/a Heodo
2022-03-11jWMLF.dlldll 64c7b3df5a14317e90384e21b0ccb450e9872e6a55c09c0990cd6e46dcf00b68n/a Heodo
2022-03-11W6BflxR0CiRN.dlldll 4f0d8c70789b39896269a03edd771c40b9bfca067eb0256e30b5a25aa9d1f88eVirustotal results 26.87% Heodo
2022-03-11V70jgS4hMkR4.dlldll f2fa0e36c694180d747b03106c326f697d248a0c649613a4743111d65fe878e4n/a Heodo