URLhaus Database

You are currently viewing the URLhaus database entry for http://lista33rivera.uy/wp-content/jiBtjSaJMcM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2100999
URL: http://lista33rivera.uy/wp-content/jiBtjSaJMcM/
URL Status:Offline
Host: lista33rivera.uy
Date added:2022-03-16 22:42:08 UTC
Last online:2023-01-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-16 22:43:11 UTC to abuse{at}hostgator[dot]com)
Takedown time:10 months, 10 days, 11 hours, 3 minutes Bad (down since 2023-01-21 09:47:10 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-26eHoTtp0iePMbH2JPtLDg2j.dlldll 12b388da65f9c204a41abd442f0f270713791e7bbb9321c70ed988f048d72f33Virustotal results 49.25%Heodo
2022-03-17vSjxKj1UzOfpVHtV.dlldll af65f063efb35fa64575d35003d00a2f27f4ff2ea186c8c539035e75ba199e13n/a Heodo
2022-03-17FHgskABMpGCGtFfcz0QXqIpqICN1ZX4f.dlldll a6a5b4bf512ca83256a3abd4aefceed9190e07afe9fbc9e5d77c10b2ba862bfan/a Heodo
2022-03-17jkLxA6M3.dlldll c4ced61fee4295295f7663f3778370bae395db02b9ebf699f465b01deff122ccn/a Heodo
2022-03-17nX1BcMhQFmJi0RblD.dlldll 2e153d501b4d9d065d57d76db718589492e57744980b8ad9b5dd844cefcae22cVirustotal results 26.47% Heodo
2022-03-17FKQz9rSS1xdlNGNNP.dlldll 12e9e7d3bc5ee1ddf0c557c32cd5fbbfac2be968a84bb31b724b0b3b5b253c17Virustotal results 29.41% Heodo
2022-03-16pxhyMleiso4ZQ2rXhN0AQwkA7KIr.dlldll 520004a99c2c4b2cdeb328ec928eb76bdf1534120ce970f0b9a5e7c34c7366d1Virustotal results 29.85% Heodo
2022-03-16DhKAnDdWDjaZ1IqCpMg.dlldll 7a524c90a2269a0193f2a8ce8d06c5fc90e16c86b81aceaabf55ed8d013d1676n/a Heodo
2022-03-16rEdNvBOuChU3oF9gibqT9.dlldll f781abb39ac4f11c90bbd47fec33c69f32791a5ad846be7fa9f2fa10af432cfan/a Heodo