URLhaus Database

You are currently viewing the URLhaus database entry for https://www.bovito.hu/modules/ihNZzatAdWd67ATz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2100867
URL: https://www.bovito.hu/modules/ihNZzatAdWd67ATz/
URL Status:Offline
Host: www.bovito.hu
Date added:2022-03-16 21:04:09 UTC
Last online:2022-03-16 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-16 21:05:17 UTC to abuse{at}rackforest[dot]net)
Takedown time:1 hour, 46 minutes Good (down since 2022-03-16 22:51:39 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-16n0vp.dlldll 243b94bce1a65263f9e8d8e701ae9494807025a4d0016700c0f1433bd02d51a5n/aHeodo
2022-03-16a1IYHns0.dlldll 49bd78cc91874d0409cce1df4b054dd84b4f9922ea812486f06f2b38aa8bb59bVirustotal results 25.37% Heodo
2022-03-16AWCHy.dlldll fa14f2cc56b687e7e7b8524bb4b694ba2d4d398870518230bfdd67b93ecd9ae0n/a Heodo