URLhaus Database

You are currently viewing the URLhaus database entry for https://alebit.de/css/gqKtdKmTsC4iDh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2096805
URL: https://alebit.de/css/gqKtdKmTsC4iDh/
URL Status:Offline
Host: alebit.de
Date added:2022-03-14 18:20:06 UTC
Last online:2022-03-15 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-14 18:21:12 UTC to abuse{at}netcup[dot]de)
Takedown time:14 hours, 55 minutes Good (down since 2022-03-15 09:16:26 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-15KpvCC2SrkEFeROdLZxgaLoK4.dlldll 9a95a9365f251e0057cd5844ec4889f51ae631a741ebf9631a23341147834bc4Virustotal results 10.61% Heodo
2022-03-15i95f92a.dlldll 664733a9ed44c873ef6838be30c42b0fc76ae31543e3c20aa9b5eb590ee04771Virustotal results 12.12% Heodo
2022-03-152gUG1lFviE53XtXJlG.dlldll 2c0cae7c964c9e9f898a12de7dce45459f2d35113b658fc2042fd8af449e0cc7Virustotal results 10.61% Heodo
2022-03-15ILWquFK9rpQ8g.dlldll f7523b46e97c7cb05c093018ccd8ff0fe97866aed644a5ed4a64ce78d71fe88cn/a Heodo
2022-03-15dj9wAP4DI76kefF13e4.dlldll b7167252ac8b4b3072a0f7466c985ae10357e7f7ed43cf0a137c1f4ccee2b287Virustotal results 10.61% Heodo
2022-03-15JrXoZQBgxxNsByplfaEU6Az.dlldll 02c6e7e71e690dffc63c34d1c1b27b81a913536d0a68aa96bd666a9d7a32656bVirustotal results 9.09% Heodo
2022-03-15gqVXc50rre2pLyCTuJUfPi9LKGEAww55qdZ.dlldll 3ef4088db0684d9427d964250f6139fe1f86a4aac32846bdf31274b9cae90666n/a Heodo
2022-03-15JdQfTzZ6j6IKAI6UHcwKJ1rDdld7ztsCch.dlldll 4297163f25cb800e99023d778b668f80d9b88cba610c857350a605e786e8b27bn/a Heodo
2022-03-1524CtDv7AW.dlldll d01c7a7a46d888acd7d445958e437e6f1cc0655e8da38b51fa02ca210152957en/a Heodo
2022-03-14jxgNTY.dlldll 4020d2bafe3719fe0bf8bfa36f7c5c2f486b90e636957947c23869b4af5d7b44n/a Heodo
2022-03-145iHkCnpWmzvhauKvXSgnZNbA3xErdt.dlldll 0bd2371394f642cda2a4477a1e63498003cfdc56006009b67907831e40166285n/a Heodo
2022-03-14MjUWTMa6Uw1i7k5wXifU.dlldll 6eebf4d9537f09a40819a47543fc23e67191dff6ea8b9a3fd1c6b96a54fb5150Virustotal results 22.73% Heodo
2022-03-146IZw5QfOqZT.dlldll b3a46232fd78282afe6f5376fbb46ab67f27aaa286b85298c91a96c3f697ab8en/aHeodo
2022-03-14UiuVRnFirO2WbG.dlldll e62510f5606fd761ea59e1643ece7d8bcca2278df9fcdc58aa44d9987eafb2abn/a Heodo
2022-03-14qQYoXWXl.dlldll 2401b05e4498747b3627c433d47793b65bd592b41d6ccbc4b3cca108de943b68n/a Heodo
2022-03-14Urdq6pEoMEj4vyg.dlldll 588d7116a0393a45b389e81cb73b0fdd269fce86aec947c8609446c9bfc8b265n/aHeodo
2022-03-14IeWOQROod6.dlldll 70d2dbff8dc6372be3bdfd0d21855a6b92984f607a90d2b2493f24e36ebd966en/a Heodo