URLhaus Database

You are currently viewing the URLhaus database entry for http://basepainters.com/wp-content/Zega/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2097090
URL: http://basepainters.com/wp-content/Zega/
URL Status:Offline
Host: basepainters.com
Date added:2022-03-14 21:03:12 UTC
Last online:2022-04-29 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-14 21:04:12 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:1 month, 15 days, 3 hours, 42 minutes Bad (down since 2022-04-29 00:46:22 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-16y9no8n1LG7aJnptBl.dlldll 64c4a6670a1e25c9ddca49f257dec3702f1c4b0c8d7898c6dece1aed6637a5b5n/a Heodo
2022-03-16orz5L9x.dlldll 804e59ccb42bf0bcdcd45b0d6c2bde4b40ee637489d87e7da0c1cc8697b7066an/a Heodo
2022-03-16ZDDeXSBBTtJhtED.dlldll d7ba98da14f3c80c6798992e05b7a7294c83734a86d354d840c6f418cb3c641dn/a Heodo
2022-03-16omDWt.dlldll 0f2da4c537a8b172e08f0863b903a690d81483df738881cb18cdd0262b539479n/a Heodo
2022-03-16XSVS2U.dlldll 383289e41e4db1d8c0089cfc414fcfdbc5db950441165f223aa2e79d72dbac11n/a Heodo
2022-03-16vkPBKkz.dlldll 396e93d868e1c5548cc3caedcb8969229635a93a7d051e0384b02013029f7a26n/a Heodo
2022-03-161tf.dlldll fdb5b4369d63e42742fd98a2b6c1f0f4f552232a62b64bb54b154b530476b7d0n/a Heodo
2022-03-16FhV.dlldll de921f030dd9637a55bcb049a6a4763c945e39ff704d89e9d31c199f5c688068n/a Heodo
2022-03-16Pggjh.dlldll 5d26d74aa2be62b694c60a69aaf182d1119591377812eb4a9f76cc43d27119b2n/a Heodo
2022-03-169MRDRZR.dlldll a1e6129b578e8151c702563da4f9018d84fb88ff10cb981350ab630dcb1e6de5n/a Heodo
2022-03-16zNJWXwFtRs.dlldll b1c8fee94afdfeebfd165b14929d60089452579ac8387a1df2324874e50ec408n/a Heodo
2022-03-16rIShsd7DjO.dlldll 0dc6e244d1d8a5389cb1cd67d73570457dec6fb30fe6d80438af17247b074776n/a Heodo
2022-03-16TPJ2kysXC6b.dlldll 97f4748fadaae059fa7f79bbd44ec97a9a674ce4ee66aa2bac7c81f832d2fc0cn/a Heodo
2022-03-16Vu7MuqJQIqiHkP.dlldll 3c178c8d146c13adca550e096249dabd0d14941cb112966d7889467bf14cf1e3n/a Heodo
2022-03-16sjPb4Qtk.dlldll 8d1d49ff31784d04db5ddeca7bf36f3285397f8a7a6680dd520d111df926f61fn/a Heodo
2022-03-16bY1zf.dlldll 1b8a20da5ff950f3f4d42ff28e72b8572122e27e9ef0acc971da0dd0bb1a5123Virustotal results 28.79% Heodo
2022-03-16wOFiCRKuSDO.dlldll fc21e130ffd5a73c523df18c2cbabe1bda27e4c6d9072cf39b61adc7958fdca6n/a Heodo
2022-03-164p1PLlbhf4gB.dlldll c1acf0e28b1ca071566c0ba2be91c27eeb7c33bc033bd3eb61fdf0926fa36003n/a Heodo
2022-03-16aoY.dlldll d72c9a148ef9a4f7350dbeaaf752601e4042444ca164ea56096bc4cbf0ce9cc9n/a Heodo
2022-03-16sbpQHV43ePU.dlldll 41de2aa215ecf44b2915cb619ccd0e2a152421e895e34c4315d14764f7e88daan/a Heodo
2022-03-16NjD8s.dlldll 067097a56f82f963667e225dd47cdffc0d3ebd3685427d3a4d8726d3712bbc40n/a Heodo
2022-03-16Zd6Sva.dlldll c28ac8072d709122ee4280e31f08681083cf7484d5b4f354810c0e6c40b17c70n/a Heodo
2022-03-16uRHiSbAlf7NJfH6Y.dlldll 9470e14cb6edfd9e180c408605d59b1f51c5e81ab9229b626056e541c130568fn/a Heodo
2022-03-165KpthOlLzJ.dlldll d1bf3d40eb69706d8c211a64053bb2b099c23a60082d7477921833b312b12202n/a Heodo
2022-03-16Qw8Hg42blcFZ.dlldll e07306cfdc0ae025cf3bcf5bd132aa142714cd524a0ea492c1397f19fd8e7cddn/a Heodo
2022-03-15OR3z6JCp5.dlldll 34cc508e667da59383cf887959747a7a684dc4486d809e9ec370902c0a3d0225n/a Heodo
2022-03-15tF4ZqzbE4yOsL89QD5U.dlldll 03817d4ecdf309d85a287f5afda81b66744bce6cad9825f45a2e5a4f5f862f90n/a Heodo
2022-03-150YDhGn7I9E6.dlldll 2cb3a5d34b29a31dfdbff19a62d11f77cea40fff6b34386d421f7a88aeac2627n/a Heodo
2022-03-15LsyOuur5HHqx4zd2B.dlldll 023a91d85a261833e9a7c911c29457ec2773f6c0e9d7591ae275db2832416f6fn/a Heodo
2022-03-15zslL1.dlldll 68a2522c2488b93dfb94f3c40941d6e783a46f558f7e34ff78f0df81092cc882n/a Heodo
2022-03-15DlA6Gh2nS.dlldll f17ec4dd1d45e92c7a30c4b7e8fcc48f9cd863553f81758f4de1c651e1aca292n/a Heodo
2022-03-15M4r0S3k1xORJyyjqwB.dlldll e0153cf3434b1ebc9e372f2f203b465baa457709a7e017ca97cf0ae8490a5f87n/a Heodo
2022-03-154dw2rwp8o.dlldll 4ec6be84cae434883f90212cd4cb43aabd4450dfe04bc4666884d90e0b4498b2n/a Heodo
2022-03-157tIFpO8lI4ZJ0cH.dlldll 86bfb743e641fe8b69f5ef8dfd219c714986d7a1ffb048c5f6f19e0fb98d7f73n/a Heodo
2022-03-15Fpfdsd.dlldll e9d79547867047f2f7d13bf4b85eb4eb7d383f9a9a60dbb28a7a2cdb65f909f0n/a Heodo
2022-03-15B8nCaZt5E74x9ticT.dlldll 8ea8d4719f8e86e3fb3a6d01bc261033c42789e99b7303b51a9f6bce5157624fn/a Heodo
2022-03-15RY3KXH.dlldll 655403211bf13ea8d43b7b41bffdc7cdfea32e693620195b39b1a6ec67e515adn/a Heodo
2022-03-15hGYtnAJAiJE9lUG.dlldll 4845eb08e60130f4006090eea7a5fd9b96d5494f310ab45850b0dc12d082ed82n/a Heodo
2022-03-15Ev9SJ8kNcgnsn.dlldll 54357801be31bf5e38852258412ea76116123fa3cbe249d682d42f4409f96029n/a Heodo
2022-03-15ABcuPppDddbhslS.dlldll 99bb8ecf11582fcb5d03585c5373e51f4714041d26815c32ed9297c3b5335ea1n/a Heodo
2022-03-15uw14VyRNvaz1A.dlldll 8b21da15d9294b1e43510dbee4e3d541c7a21b158c104c8082a51028fef4c38cn/a Heodo
2022-03-15RqUn6KoYLLBJ112xiT.dlldll 2d6fa199ad20fd8f1682ca54e37dcabbd65118cda284c239cba9dbd4cf3fb7c0n/a Heodo
2022-03-159z5XCZyhQ1NSTh.dlldll 7e26223bac8b43f6593bddb75db9cd4b06578b814f8c152ee814a79acc161712n/a Heodo
2022-03-15m4yoQ4hE37.dlldll 28a9d4c28ecfccb86c5af515bb33efc09b902efe7f147bb136c99ddd81f31e77Virustotal results 10.61% Heodo
2022-03-15IeJhMRmyvygO.dlldll c32ef7f0c96aa336b252275d95a60a51a163f662efd935dd6be379ce878cc7f1n/a Heodo
2022-03-15JZhV43hk.dlldll 7d11f8b4139b91f7e33375dd6650469a5e9d96e0265a3864b99ae6e159189f0fVirustotal results 9.52% Heodo
2022-03-15DeP.dlldll 3fcc37b93b217988f336f92c8dde6f9692e4e5bc2f6adfc9d778d3d240e107caVirustotal results 7.69% Heodo
2022-03-15FA3BKY.dlldll c39efe69d570c2ce3d178adea07ea1e208fb1c1497cf2da72331da7ca54e5339Virustotal results 9.23% Heodo
2022-03-153UChP8iUr3hZMdFSa.dlldll add3806c6c3e95b2e606c1c16e406fcf125f8b22f27279b92edc27a61eff7d6aVirustotal results 12.12% Heodo
2022-03-15diEt0vir.dlldll de7c020fb70b0d54edc5f3fca24c6ee48000b105b7ab0613a0422699d586b313Virustotal results 13.64% Heodo
2022-03-15iiqQUf5.dlldll b782b8b44bbebb647975d68c99c4efab36c47ac539085a8e9326f519c7e59aacVirustotal results 13.85% Heodo
2022-03-15LrrpnieAW.dlldll aa0aed709caf1d1443b3aa7bd01b5fd24f651d1071fb229f54ffb41a27c963b3Virustotal results 13.64% Heodo
2022-03-15voBHr4AoI4.dlldll 690bb090fad4a173ac421990be0513a1188c880245d39b1923586514a2468566Virustotal results 7.58% Heodo
2022-03-155a0WKXZWWqTm.dlldll 26abc3edbd8390d93f7f9ff016debc1c1c0f3bb4cd222aaa352f71ff66fe6815Virustotal results 12.31% Heodo
2022-03-15uudHSuF1pFvL5mM.dlldll 86b5d5d086dcf8493259a6957b5f66fd63d66d5e48828d41c58ae480415907cbVirustotal results 6.06% Heodo
2022-03-15dOthY.dlldll 924ef05282d8217bf10ace0e71b21e94eefacc7172476006c8b0a676445c1ebbVirustotal results 6.15% Heodo
2022-03-15Z1k5Z5062A0IZ.dlldll 647e50431c455a684ec57a97f8d3c70590a3fdee03710696711963bbfc1e28bbVirustotal results 4.62% Heodo
2022-03-14JYmYTpm9xGac.dlldll 67e42968a078400b3adcfa0b7c092ff08fdecc636ad1c6378c88631444a08203Virustotal results 4.62% Heodo
2022-03-14e0S93sZIIS1G.dlldll e75fd9ad7295beae4c0055df842869354e1a5f3ceecdc2b899e0185945a439bbn/a Heodo
2022-03-14Zu9yD.dlldll 2f81f9597bdf2b4da587519bb73cea9c41e8391ed7b1af621dce480b47680316Virustotal results 4.62% Heodo
2022-03-14ruZyh.dlldll f1328028c2971632fe308df2aa48eddb6c2ebfbdc34c7033985679350aa5c2c5n/a Heodo