URLhaus Database

You are currently viewing the URLhaus database entry for https://damjangro.org/data/IlBcH2mM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2103549
URL: https://damjangro.org/data/IlBcH2mM/
URL Status:Offline
Host: damjangro.org
Date added:2022-03-18 09:53:05 UTC
Last online:2022-03-18 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-18 09:54:07 UTC to abuse{at}versio[dot]nl)
Takedown time:3 hours, 4 minutes Good (down since 2022-03-18 12:58:46 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-18cthOkzd0uzk2Sh2o.dlldll e085242e68af1bdf96568b0637f7af68f3a4bdf8766e154d81feb3a0a1a22b66Virustotal results 22.06% Heodo
2022-03-183gWPJY68RLSksIyhBZ.dlldll 8d3503428e5bdba0118f3d1bc73be643b04fcf718b294ccd319e50331f33ab5bVirustotal results 22.06% Heodo
2022-03-18C5ZwDeapuPAwm.dlldll 0661f739f74d351428d783c305022a2549a8b5240bae6fb2c52e08d2661d8b14Virustotal results 22.06%Heodo
2022-03-18bA8wgyB0sH.dlldll a13a6e8dd5c124e5cb352094abae6a7d76c94b1afb18bfe65f2c482b29b8c6daVirustotal results 22.73%Heodo
2022-03-18ToO4iWEz95ub.dlldll 14f18c8288fc4cd5e2be42704b9083632ace336345d981a626a8a97cd7f1241en/a Heodo
2022-03-18QhGOPZj1sDZoyahk.dlldll 93ecbc79688b494aa0a24d076ef787f30e945d343d0e8e6f4c373289153f285en/a Heodo