URLhaus Database

You are currently viewing the URLhaus database entry for http://avcservices-tt.com/EANAPI/hswSV1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2097102
URL: http://avcservices-tt.com/EANAPI/hswSV1/
URL Status:Offline
Host: avcservices-tt.com
Date added:2022-03-14 21:05:16 UTC
Last online:2022-03-15 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-14 21:06:14 UTC to abuse{at}ovh[dot]net)
Takedown time:12 hours, 6 minutes Good (down since 2022-03-15 09:12:52 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-1535FQOZwJJ7.dlldll a5bf95fb746418cf0f33747af5a51a6c152de387b075b4c805ff889ce5778282n/a Heodo
2022-03-15OwOPHLdHy89gPB.dlldll 6162b80cc2468851cc292b81d90fe5b60a44e0d0ea851b7d9f912252bd83a4d9n/a Heodo
2022-03-15LMxOCzujNCNi.dlldll 51a0925bf0e22439bc2a656b6f454eaaba49f2f8186136aac1ab208a07615079n/a Heodo
2022-03-15otNMqcdR87b2yZ4.dlldll 9d1ec9baa8f269aaae3ecd40cfafd50a781956e2bc11370a87abb5a9f82f7f7dn/a Heodo
2022-03-150pcvXX7xOiUZc1pbe.dlldll e9a0dfd998189b939aae3e2ae028aa15f1987ab7b1c76bbd9534783011c66825n/a Heodo
2022-03-15oWVWccK3zOpqNY.dlldll db3ad816d3effa04dcb9ddd16769d66d6db5def14c8b4561dcf6b8c63b75d6d0Virustotal results 10.61% Heodo
2022-03-152CHg3HEKq4vyzEpmSH.dlldll b6228a6307fc98a87b7da8e35ee59ec0b95476f7a78a87baeed796346ba5a4dfVirustotal results 9.23% Heodo
2022-03-15cWTS66sYHT.dlldll 032d278d6b10de03dab4e5b61d7137c25b852f3af5273548fd1ae8ebaeed3f64Virustotal results 6.15% Heodo
2022-03-15wqVGUlZX5Hsn74.dlldll 991a203406ac307fbfe08101e9dce06dfbea34b5233eace51f521c08aa031ba0Virustotal results 6.15% Heodo
2022-03-15vYhc.dlldll 6fa2464e083d28d717b448901ce099134a3c5cb7bc3b2f8bcaf2b9a1e7734039Virustotal results 4.62%Heodo
2022-03-14slrEoTceP7PQh85EEUr.dlldll 8f9cc738a84ab78d1375d2869f435b9e83326c0c1e45deaaaf04c9a8eaf93c40n/a Heodo
2022-03-142P9gukikvc6famzH2X6.dlldll 768716cd75d7fa0c13a11033a3bf874fbd76c100d2610aa3d250d9b13730fc43Virustotal results 4.62% Heodo
2022-03-14qfbt4kLJ.dlldll fc93fb2b83ab73311189ed06d09100deefe42d44218823e6ccd719ae150cac38n/a Heodo
2022-03-14i4H.dlldll 43d70d66dad54c002e9b06c58c8f5cc4d92e3565b2b69675fcc16e6442a8f108n/a Heodo