URLhaus Database

You are currently viewing the URLhaus database entry for https://assf.com.ng/2021/coY6141cNQXQYGrob4o/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2102306
URL: https://assf.com.ng/2021/coY6141cNQXQYGrob4o/
URL Status:Offline
Host: assf.com.ng
Date added:2022-03-17 16:41:13 UTC
Last online:2022-03-18 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-17 16:42:11 UTC to abuse{at}ovh[dot]net)
Takedown time:10 hours, 32 minutes Good (down since 2022-03-18 03:14:33 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-18fRLF.dlldll 2775ce21f71a13f07a03ed3b73acc8c5cee2996c5584c59d6b7b0de5f78207f5Virustotal results 20.59% Heodo
2022-03-18sFiGe3E1floZF.dlldll 22e2b57e1d7d67977bb8b1cc5c3c803595875f78e928e1383a4bc6647a9dd503Virustotal results 20.59% Heodo
2022-03-18Wo8IPFpp761lgK5.dlldll 1a29ccb106693097345d05c35a27c55ed391666260543c60b433588f784a0b3dVirustotal results 20.59% Heodo
2022-03-187h6PqZ1XOV.dlldll b5f7a98da9a650ab5037263586e7ef875d601090c197444febea70755fa44c02Virustotal results 20.59%Heodo
2022-03-171wIFP4bD.dlldll d90e8419f4a59e32c0d3784047306597c062de2354998e0a1ba78bb223232be0n/a Heodo
2022-03-17zCRhGeTPx.dlldll 3a929b6917edc1a9fedd0b60dbd2ac38199ec1de48d5439c5aa96afd8f546242n/a Heodo
2022-03-17qeFMcLYA4W.dlldll 2aac15eb355f1a7bdae1c5b151102e4ef361ef42ee6bd40ec3945d5afc3d9517n/a Heodo
2022-03-17eGl.dlldll 7bac29dc60a0cacd96f27103e9e61be8e5a98b7233a5d58bff310ec78e8bfe17n/a Heodo
2022-03-17hbbHSBEm05wbjr.dlldll 7a82b8ce330fd95d087ff6b482557ce0e5db7b0d4da0975981794dfc954dab4cn/a Heodo
2022-03-1783Q0IkBxloSBg5znzMR.dlldll 79244f07e7491a9d7bb1c5f38b16646353694fae133ade697ee191be391f813en/a Heodo
2022-03-17jOUYs01b2peQ7HAd.dlldll 1f53636482df22ee70aed0c6bc97d2600ede47be5125510b0bff0618a0f583adn/a Heodo
2022-03-17x93i8O15w.dlldll 0c2076696522f22fd31f4ff4e179982b1f4f47adb78dc1bdde5eb28f86376cbdn/a Heodo
2022-03-17qyKcNHN.dlldll ffccea70fcb47ef029673e1dfeaf4828666e2592dd18c1c2a9ebd74e867bea4bVirustotal results 20.59% Heodo
2022-03-17QwaA.dlldll 98884b136cc12f460293f154bdca538911c96ba0ed226bf871f4dac91ceb0bdfn/a Heodo
2022-03-17vrpbTDaGmC4km4s3K7.dlldll fedd1bbfbd477158f743ebd2086be0c7105ff3aaf7e69250fea8b641fe9dde92n/a Heodo