URLhaus Database

You are currently viewing the URLhaus database entry for http://aaticd.co.za/wp-content/6JENALSdgs0RAPqV20z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2095994
URL: http://aaticd.co.za/wp-content/6JENALSdgs0RAPqV20z/
URL Status:Offline
Host: aaticd.co.za
Date added:2022-03-14 09:24:08 UTC
Last online:2022-04-19 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-14 09:25:12 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:1 month, 6 days, 8 hours, 27 minutes Bad (down since 2022-04-19 17:52:34 UTC)
Tags:emotet link epoch5 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-16CfgY.dlldll cd9e8dd25052152d54bbf5d3dc5371acb7a0aab8303567f2a49e6c6bd21b1888n/a Heodo
2022-03-169QnR9xudlp.dlldll 9efe8bc32413c4cc9fc99d116894393de264ef7465f9551f5a3795a571dff1f3n/a Heodo
2022-03-16DhFCePL.dlldll dbbf24e442361839e7113e3e8b91215e35b68f06b5f98dba3b9ec1874f7877cdn/a Heodo
2022-03-162RShjS.dlldll 9b3ee49df18efe8f6f22d5b34c469ecbbba4f045ad41949dc18a3bb3e142146bn/a Heodo
2022-03-16RvQewuhC9Ki3NqhwH.dlldll b512e8a13471607f5152fe750849be9e96234170cf15ff6676aacce14708dacen/a Heodo
2022-03-161apAZHK0QtS3FQDG.dlldll b8b8e503a26c3cd6b6625c1155d80e4417c5e9ee9ecb6a6f1e8efafeab755f42n/a Heodo
2022-03-16jHnqHLG7K91X8d.dlldll 3d483c142210ee92fe2239d5fb08815c133bdf8f57ddb67ecb03a117a8dd1733n/a Heodo
2022-03-16Lrk41apL6LTX.dlldll b0eaab1c048f1b6f86a0e8fe3a2a6fee9e87770c536cbe0e0b956f9c1d0b06bbn/a Heodo
2022-03-16TTGmG3HB3O0C8orYIbM.dlldll c30529cb6634f6bf6a06f5a49296be641d9d59039d1b9c439fb72afa51c097a6n/a Heodo
2022-03-16ToyKrRBqyijwy7eHXWm.dlldll 5bb53d958ba846161471997abcc948b2ead7a8b6ad686629f55eca215190ba3en/a Heodo
2022-03-163bI.dlldll 870d76f00591b78b68c888160708dee69122fc6a3a875df841561ae01c0e1d5fn/a Heodo
2022-03-16DOJ7N52wn6Gzr.dlldll fd421fc46f9d3d59c25b677f894151d8547e54103af63d38cb07cc6e1b8e4725n/a Heodo
2022-03-15i4Tud2.dlldll ec76ae65d6e9d1867e3d5a94203e49508efab628aceca32b989e2640eb472330n/a Heodo
2022-03-15ka6kKcAUKqiDwMg.dlldll 804cd08d884fa1567917529d11fd9bd1b76e9095667b89ef784886b74d5d1ae2n/a Heodo
2022-03-15QlKMyKXr.dlldll 8f68141db9e03a2ccdeb0c44cf7047df81bfabc752378a65be8885431e2a213an/a Heodo
2022-03-15XnL7w.dlldll 6bcbe0ed9da8fd5d72a70c1a8ec70283b3e0c5438395ab6125615e32c71fa72dn/a Heodo
2022-03-153N45R7UJMV5Rl.dlldll 2496e993f4cba20c58b23872dbd780f79701df13b9223a1127611f8c914d4fden/a Heodo
2022-03-15kN79K6eaQsvWfrqf.dlldll b67e325ae49a5f52d49128b68cb60d2e07c87035865f912d5e4a0f1eddc06129n/a Heodo
2022-03-15uJNYuV.dlldll 9abd7d99207dea29e02364dc8a48e0c43a1207c14d31791e2cc368310bebc37en/a Heodo
2022-03-15ez3i7.dlldll 0955ef93b99858a8c1581673ae35ea78728311355f57f0493ce8d91af494a7e9n/a Heodo
2022-03-15bzKqmJ6.dlldll 817b3531003be8dcf693256f8b13b2f6a7465dd0c3c95bb0c1396c756375582an/a Heodo
2022-03-14ufd3MQxiV5Eg.dlldll cd2c8be79c458923fbbd37763cff069d5cb89bf95a8063364a39950bc24c2d48Virustotal results 13.85% Heodo
2022-03-14kqIUi80r.dlldll 7c7e81d4142750bee944849e7231f4a23379fadc281e057843b682d7017a0797Virustotal results 13.64% Heodo
2022-03-14Tv0uCR6SJsZ.dlldll 6a1edfff98c525817549e269c2408c2d2d07145c2c1d9ea6c7c165f569726fc9n/a Heodo