URLhaus Database

You are currently viewing the URLhaus database entry for http://balibuli.hu/cgi-bin/WDDM0VHSK4VcOFmU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2098709
URL: http://balibuli.hu/cgi-bin/WDDM0VHSK4VcOFmU/
URL Status:Offline
Host: balibuli.hu
Date added:2022-03-15 17:28:12 UTC
Last online:2022-03-16 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-15 17:29:13 UTC to abuse{at}telekom[dot]hu)
Takedown time:15 hours, 47 minutes Good (down since 2022-03-16 09:17:03 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-16LBlzrBSeycSh56eC.dlldll 1a68ce1f23ad3c61356461f9111a53ba8da1ed2f0e1208f45654ed68e40ff389n/a Heodo
2022-03-16Ge1xPMEvYusmcq4geszT8q.dlldll 618233bf30dabeaa46102ebbf469cbd6c7007f214271508792709ea139f94d01n/a Heodo
2022-03-16xvpo6F3WdRC2W.dlldll fb49ac910ee097cf3131c1a6ec8bdb73b7f41e926ad4875b9add05fb7d63def2n/a Heodo
2022-03-167yG8k4RE7AcgUOwHoBIbn6iXg.dlldll e3ca559c001b09ef430c52d2fdc5146966b51366543f402cff49d922dcf97047n/a Heodo
2022-03-16jbJ3jfFh4ttqtzIOU.dlldll e92e209dc7f72aae2be6f4094875e41b7e747fca6ec963cc6aca875ce70bed83n/a Heodo
2022-03-161W0VlPcNYf4pMUDrbsN6KA.dlldll 80d98587c5bfa70725490efdad650be398704dbb17e1febe45479ba2aac038f2n/a Heodo
2022-03-16nWs3Pu6tHXCot2deYPj8IoCLfj.dlldll 8664d224b5bfeb36fa39ed9720657315ff31e8c33988a5415c7da1b96529ea27n/a Heodo
2022-03-16VuluIFOuqqrHblD.dlldll b4566419aecf38658f41d1e33f6a9bf23ae074421bce6ca26f2272b8de8b291dn/a Heodo
2022-03-16kt6R4y.dlldll f8e98d9b936190641576fd191bd26ed362235df3b9886a9ac89ee741e43064aen/a Heodo
2022-03-1536L7aoc65MKi1hVJgslHwjo.dlldll 7fed33fd712b25ff2b7cef7aceb549ad60cccf9e0ab46bfcdc16a47604a3b5bbn/a Heodo
2022-03-15wK2MrGuRxRt0IT4wdk4ygOeX6a0ZU55NTEe.dlldll 26912cf61748f0e362eb412d2748415d8d51ada88ba46635c35f8e882559207aVirustotal results 22.73% Heodo
2022-03-15O4Vbhow6Rfx14Nw1.dlldll 970007f4dbf2692851bc7877de1a0504569fe64308c254ec8710803e96d1a29an/a Heodo
2022-03-15VXoexcfD37hSCnxHOszQAqf05R0zjZuJ.dlldll e0ef8368630f67b069ce045436bdb543b3ab4e46a9be4cd876ad50b9b9f95819Virustotal results 23.08% Heodo
2022-03-152dMyBiRth26.dlldll 08722ec2d26379a71eabf6b41efbdda1dea5beb57abd197307c16506292f7872Virustotal results 22.73% Heodo
2022-03-15v1ApWRAANpUAaqdCXRcphXgRQSiW.dlldll 1c17661bd200ab21288c705705c09429ecf17c06f53075c9cdf2f2e9f40f80a0n/a Heodo
2022-03-15k87EgUAXQZsKtKzT41AB3Hm8WoHYCBLgahT.dlldll 174d20bd86ea4b92232249a67ea1163ca48fc376649f6fc1db84d5f362ab22d6Virustotal results 15.52% Heodo
2022-03-15zYhbObhXsNS77gEQxRV1hXzyG4d.dlldll e54644e3b23de01bfbc21ca0af0ec528be364c2ebe3fa1b4e9aa552c730f4324Virustotal results 16.92% Heodo
2022-03-15u0QAHvowjGfcdUwHBd3AFQj.dlldll 5c2012834919f1b0e57b913a88834c4fa1aa97e7adc31e72e496fc5267b1734cVirustotal results 17.46% Heodo
2022-03-15aTnFURwLOhWFFcGxYiRZEd5JJgT.dlldll 13cbc730150b943bcf11865f5b7b1fb4e633e926f18f4b2110e422907a601464n/a Heodo
2022-03-15syW8AOff.dlldll e816de8bbbf4cc522c92953c72d9b4c29904c85684ed35dcef9b3a5cbe262782n/a Heodo