URLhaus Database

You are currently viewing the URLhaus database entry for https://landingpageis.com/alfacgiapi/IhZmV1LIJwi6O/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2104677
URL: https://landingpageis.com/alfacgiapi/IhZmV1LIJwi6O/
URL Status:Offline
Host: landingpageis.com
Date added:2022-03-18 23:31:07 UTC
Last online:2023-01-21 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-01-21 02:24:06 UTC to abuse{at}trellian[dot]com)
Takedown time:10 months, 8 days, 11 hours, 7 minutes Bad (down since 2023-01-21 10:39:22 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-19ToAaeNkkUJBGmiG0nxFxP0kN2VK.dlldll e1ee127ef5002387fc25ecc88058f6fa045ec2fe7934f7c09619cae22f33450aVirustotal results 26.47% Heodo
2022-03-19ARuJKwLrP5NhkN.dlldll 62f7f04c73715a15c1eb505b675a163f7d91746c5f701a271700cee3e37520ddVirustotal results 26.47% Heodo
2022-03-19ss54wP3ADs.dlldll d12118640f282d900728b3a808940b7d7ddceda83eb93f052c9f24de4b83f86cVirustotal results 23.88% Heodo
2022-03-19xebhATt3a3xrl.dlldll 07c0afb3081fc56a732da109c21948ac45fad937bdccd5c334c282428527dcbeVirustotal results 20.59%Heodo
2022-03-19NsZJvZYoy1B2JR7c.dlldll 6b48d921c61bd940da400f702b5abba185378752fde8fb8b53992bcdda42196an/a Heodo
2022-03-19Ci6eomj7paZGpn6Y.dlldll ca4ec143faab91902b131061e125e0d4c7dd25781966eab9c61fa4fafb56377bVirustotal results 25.00%Heodo
2022-03-19Iagq3DK1kfzPdzz48bnD1.dlldll d0cbf89cf7aaf3dddc46df9b34fe0ffac5f49bdea74d2eb72a172e569dce4c46Virustotal results 22.06% Heodo
2022-03-193GOWacvzhUMxi58m5dIVwUTqT0se.dlldll 17e2ce7168b9a8bf19c657de8eec9380d2ff2a0191d446268958e6933dc8de5dn/aHeodo
2022-03-18uyNzlQRxllrvOFS5b3bc.dlldll 3c5b93ebfc1420a958855e85ae2c957eaa31ff70398c41b191b8d5dfae980d07n/a Heodo