URLhaus Database

You are currently viewing the URLhaus database entry for https://damjangro.org/data/XPMJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2099795
URL: https://damjangro.org/data/XPMJ/
URL Status:Offline
Host: damjangro.org
Date added:2022-03-16 07:55:09 UTC
Last online:2022-03-16 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-16 07:56:15 UTC to abuse{at}versio[dot]nl)
Takedown time:6 hours, 59 minutes Good (down since 2022-03-16 14:55:21 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-16pQB1jNY46J0l8.dlldll 78170521a3996397cb5fe6fd95e0849c7388ddcad534ca47f15a50a5db975ea4Virustotal results 29.41% Heodo
2022-03-16QjEYY9q7.dlldll 265d5bc95d915b56fadf6e2a7344bc864444dc2e64f8bdc903e3d6eecedfe932n/a Heodo
2022-03-16kGCdUJKD7m.dlldll e59348d4dced35b7efa561c6931c4b6c4cf38d3c49973b1a435b426784edc26bVirustotal results 28.36% Heodo
2022-03-162P3iu.dlldll 0900771af0f580a50311f3c2663d09268a9fe46653ff367757951c0084d610c9Virustotal results 28.36% Heodo
2022-03-16uPmibEEGmtBV.dlldll 44d6e84955dda3422f6ce598640283e7a3d4e5650f0a014fb327c78b97035327Virustotal results 27.94% Heodo
2022-03-161FFsv4kFo8pTrRlu.dlldll 5c5a1bc8dd79716ef3d153eb66a5385602719cf07a09615183d9fe21ca0cc1bdVirustotal results 27.27% Heodo
2022-03-16o0rPK2rYKCOCmowIo4.dlldll fd98c8cf3ff16984917de22beef1d73fcaeca194dfaef686ef66f0c77f868256Virustotal results 28.36% Heodo
2022-03-16XzfqqT3Tc4H.dlldll 5025e5c5ae5eb416537cfb1952539434890b282782d2139393b8aafd47052b62Virustotal results 27.69% 
2022-03-16ZybK3.dlldll 3e28055052bc64452e3d15a6ac6a3f23b75d09b665fc41aec9b121d08ed8ab14n/a Heodo