URLhaus Database

You are currently viewing the URLhaus database entry for http://festival.artdialog.ch/contact/RGhcwH4DRBM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2102691
URL: http://festival.artdialog.ch/contact/RGhcwH4DRBM/
URL Status:Offline
Host: festival.artdialog.ch
Date added:2022-03-17 22:46:07 UTC
Last online:2022-03-23 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-17 22:47:09 UTC to abuse{at}green[dot]ch)
Takedown time:5 days, 16 hours, 7 minutes Bad (down since 2022-03-23 14:54:51 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-23bhtgf8o6nR53dB0dE.dlldll e71234f874aa1bae5d3743a52ebe150e377fd4d42e172505a63306efd18f940fVirustotal results 63.24% Heodo
2022-03-18GivHCDz.dlldll ffb2e9b0637214fceffdd15b1e04ecaaf290026320af15e226657520b7ce8780Virustotal results 26.87% Heodo
2022-03-185OJEkh1pnjyp8w.dlldll c7de6ab6819e296f4846513e94940d99add1fd4a94fc29f74bfd7e32593f3115Virustotal results 28.36% Heodo
2022-03-18zDAaCSqcO291Xc.dlldll 333479820592c2c7b7064742681cbdf21857947cb083a6997f8a5c2ee93154f8Virustotal results 22.39% Heodo
2022-03-18lK2gSdjNzZ2jDX5G8.dlldll 5841e3b69fdc43a03108f40f3997e86efd7f08f3b956ffa985ec7fdae9c56e3en/a Heodo
2022-03-18up8IHvGCOokA0D.dlldll 5b506361937a1ee2af65922600abb1c8fce7d70fe972e851361bc4b78609d09aVirustotal results 24.62% Heodo
2022-03-1838QwAQ2TLDpbhnvZEe.dlldll a2f79efd1485e9fc2ef8f98d318f5359540c4bbfca607e48970b030778fe2897Virustotal results 25.00% Heodo
2022-03-18CbiQ1lU4a.dlldll fc2e5637265d0c61802346ae6a90311bd8928374d10f2162a007075e1b690200Virustotal results 26.47% Heodo
2022-03-18vpbU6oZco.dlldll 02c155742e39fa45c5325a06ee6927352a1cfbad59c43a2b6ea704dac5c3eb7fn/a Heodo
2022-03-18u1i.dlldll ac917c02fd5670c13ae75961953c1033797d02444584ca0a1adb206cfa55e7cfVirustotal results 23.53% Heodo
2022-03-181ifVQXNk6HGZTdCnLZ.dlldll 9cde55c6de3cab5bbd02e903c705593d6a98b49066349d18e423b7bde0396805Virustotal results 20.59% Heodo
2022-03-180BNFvVBa4f8.dlldll 55d1efbe1c8c3184d5dbf1e9efd65efc2f779e726c7ab288b51d7729494a77f0Virustotal results 19.12% Heodo
2022-03-18JK04H2jB6vRqBmbC.dlldll 86736a06da948af35da0d86e0fb9d95bfce21827d7f7b858e726eb42f03d9e7an/a Heodo
2022-03-18sgyyEBZXGTBZ.dlldll 1411904742f4fe328d16772ac2ceeb4ba64e90405ad833140dd0e75c054a5313Virustotal results 17.65%Heodo
2022-03-17llURewhhyN.dlldll 875e9121b6c0258a1603e8ddb9b95dbb77a79bf16a3ea8b1296de041c4da1bd6n/a Heodo
2022-03-17OEin2ps26EMe8.dlldll 7393335c65d5f39eee3d110413f51da3c6006e9af80be140681b577e59a0f39cn/a Heodo