URLhaus Database

You are currently viewing the URLhaus database entry for https://s4tiva.com/wp-content/pO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2103615
URL: https://s4tiva.com/wp-content/pO/
URL Status:Offline
Host: s4tiva.com
Date added:2022-03-18 10:40:10 UTC
Last online:2022-03-18 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-18 10:41:11 UTC to abuse{at}digitalocean[dot]com)
Takedown time:3 hours, 7 minutes Good (down since 2022-03-18 13:48:14 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-18EupQx9a.dlldll c11990c4bfc1fe9586263eaeeabd5b194e43b30459609dd6ddd7aa229ebf0018Virustotal results 27.94% Heodo
2022-03-184PTMJzoxTsj.dlldll 7ab1aea91407630b2810fbbffdbd7e4a4fe73eb6903d8ccbe563e9b39132b405Virustotal results 27.94% Heodo
2022-03-18xc1ZMcW4w.dlldll 0ebeb9fd250d1929da9327d7f6bd9ce74e3e2a6fd26fb82d5e1912cc810299d5Virustotal results 23.53% Heodo
2022-03-18WJlcJMdTFoMS6GSijA6SizJWOA6nJGW8K5.dlldll 72f73093f4259427f0ae57370a8cad172db4c8f44b85c97fca1d2a5d8e8d4ea9Virustotal results 22.39%Heodo
2022-03-18N1SYpPznGRQHTDZIW9y1v4kN.dlldll f7092d572ffc4bdf8e61ce9e10b22268aaf0732b40a9dbf27324e89b56a1afc3n/a Heodo
2022-03-18JTQYHYFUSSsPyjR5tnVhXg7.dlldll c1ec107518cc570811a6cc25591f47ffa769538853231d8ee63a692df4cea945n/a Heodo