URLhaus Database

You are currently viewing the URLhaus database entry for http://cookingstudio.co.il/join/NbvVMsJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2090739
URL: http://cookingstudio.co.il/join/NbvVMsJ/
URL Status:Offline
Host: cookingstudio.co.il
Date added:2022-03-11 18:54:13 UTC
Last online:2022-03-15 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-11 18:55:19 UTC to nvabuse{at}cellcom[dot]co[dot]il)
Takedown time:3 days, 15 hours, 28 minutes Bad (down since 2022-03-15 10:23:28 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-12K0mXCG5PtI19mfOg.dlldll 58126cb874717256b788143f6824a6223eb8af689e6c58131ddbef40e002514dVirustotal results 23.88% Heodo
2022-03-1206emdNi.dlldll 11bf77874ecd0acd92195556dff1a16c0228238da38627b3e63e19698a840617Virustotal results 22.39% Heodo
2022-03-12QrDKP2QhmJrMVhFHQig.dlldll 913cfa1d6f7d2b3a78de000401daca6a5a8b5ac6944aabe5f4c056307ba9ca60Virustotal results 23.88% Heodo
2022-03-120Mr9.dlldll 9eaf433fccf7fadedb712daf1b5240bf353f34b8d8bb98d560ed839e3b7b634an/a Heodo
2022-03-12cHJ.dlldll b536fd8ab06757c5e1d20eb7a027e7c02c588c98cce48a6498ea68996ef0f0d0Virustotal results 20.90% Heodo
2022-03-123acINsXdaE.dlldll 296d647c9caf2df0f66a46a24ef7ad0668b6fb7eb9a7cc7d2c5f6c33f2e34566Virustotal results 19.40% Heodo
2022-03-12AE6wcwXzUP3.dlldll 17ae07bd14a233adae90b5869db92db8e06c26913d630728e3a3b560f2f21f54Virustotal results 17.91% Heodo
2022-03-12cnayBvW.dlldll d59286fc2f86114f708ac981032504cd2a39f050b1eefaea84785406fd8a7207Virustotal results 17.91% Heodo
2022-03-11PmJfykx4epv.dlldll fce6b0826ebfc3f3911ca33c1147e98cc23e543e565602dc30722abbf2f0dc7fVirustotal results 16.67% Heodo
2022-03-11BdJBkYT.dlldll adc7408af8e29d36b95d3e4b1c9ca7522a02ee135b8454ecff5799e4544f7098Virustotal results 15.15% Heodo
2022-03-118GA8HcLx7dMfVJZU.dlldll b7ac38d4d3f3849a41986fa3d3c9566cb7aab58df6466da926e68a6daa37b589Virustotal results 16.67% Heodo
2022-03-11sZ8.dlldll 9c7f89aa16be1cd1ceb101abf9e0be77005106fedfa5c6d5ab49f9e770b9e59dVirustotal results 15.15% Heodo
2022-03-11qzy6tu6k.dlldll e47e1ba879a10124bc2d34487ad3901db34595f960ac2f3d6bc7e3b46955973bVirustotal results 18.46% Heodo
2022-03-11edxuqXo5pHJ7.dlldll e7174804bf5e125c99cc76195ce0952166b19a63332f7792c23954b9858dcca7Virustotal results 16.67% Heodo
2022-03-11bfP8UBHyMowWIqLuxeB.dlldll db36c091a16b196e0832134cb666257d99d66f4e972ceb28550a426c1e65633cn/a Heodo
2022-03-11ylTzlMW2.dlldll 37987d7d33edd60f3e677626d9ac391892c8cf40b65847bf55760f363bba5239Virustotal results 25.37% Heodo
2022-03-11a3KBK9EGpLsX.dlldll 6670766b2a462d5564fb79575434272c17bfb744594e8efecf478a018710a220n/a Heodo