URLhaus Database

You are currently viewing the URLhaus database entry for http://garrinbar.com/css/skwFZe0U/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2104718
URL: http://garrinbar.com/css/skwFZe0U/
URL Status:Offline
Host: garrinbar.com
Date added:2022-03-19 00:09:07 UTC
Last online:2022-03-19 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-19 00:10:11 UTC to ripe-abuse{at}0-1[dot]ir)
Takedown time:9 hours, 22 minutes Good (down since 2022-03-19 09:33:10 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-19sQSDOqCaFnibsimTE.dlldll 8d33643de9b5692fe0c3db8e34949eded5801d433eeac69d5d2d7d30ced721d9Virustotal results 33.33% Heodo
2022-03-19HiPWF00LIAnUcHOc.dlldll 10f8df57f07322c40e53b62fab4c60122f22f5e606941dc412566ba8010a7ca4Virustotal results 38.24% Heodo
2022-03-19AEFhQkBWayPYCUIbCD.dlldll 6e21b9c10a90b13b7d37be9f284c59333caf162dbdfdd2a8339874a0e9bbe866n/a Heodo
2022-03-19Bmmn31D8ACRsf8xk.dlldll 556944818b53c693484028c33bf6e9ea35f25b433306a578d23a0cf6b9e9a7dfVirustotal results 29.41% Heodo
2022-03-19BHS8u.dlldll ef6ecaa80c79dbdbe96d4a36d56c787c04164aaa27703fdf1491e56671c562aen/a Heodo
2022-03-19Vh2BddITX1IF9O.dlldll 2748165d5da66361fcee2943a4ed3af68bbab33b247231700c5d0c9b7ad3ea45n/a Heodo
2022-03-192Vp.dlldll fb32480388fe4b84324efee9dcf4e879fb98ff143d25337eff06e0bb608261c4Virustotal results 29.41% Heodo
2022-03-19PsUYm225V.dlldll 70df5b4f4bbc81578a1f5d26e8b8c912b73a904a5a890263d69cd73c0c4deb1cVirustotal results 27.94% Heodo
2022-03-19xBdj5.dlldll 03adaf6f3560e34253798055acc39c3e771487b3287c3ba6e55bb2dcdc36237aVirustotal results 28.36% Heodo
2022-03-19dbk5.dlldll 3c93a26678684cf83d757e3bb941b970a1b8122a6130f6b40357e277a9353d47Virustotal results 33.82% Heodo
2022-03-19uOkCYb1.dlldll 02759146200432fe5341f04157715fd73abcac3f401601840ec2a94f18a7f93fVirustotal results 28.36% Heodo
2022-03-19eohxrUhrhcQpdUilQ.dlldll a009b1dc499ee8cd19c93175712c2a825de4ea64e6122f94460f3b71c13dfd22n/a Heodo
2022-03-19AvWhI0UtZIYWrX.dlldll 4a54a4eb236afa12d6bc4d509fde66f72bfffef0c7e3608f295eb1df771404e0n/a Heodo
2022-03-196pCGHke2CmNPfk709Y.dlldll 651351cb3e89ef35882d202f32040f2574a624df64bd2ef69dcd4b6df05eb75eVirustotal results 25.00% Heodo
2022-03-19L5zGqXppYGGMUs.dlldll d55c4ddd77da04eaf38d16ba057a3c3cdd6097c6a3d20095922b15feddf398a7Virustotal results 26.47%Heodo
2022-03-19ypPckEukTAhYSJTfh.dlldll 23717c94ecae69f9e389c66c5c0a76628c33fbceca6bf072b1e61f154944d3c1Virustotal results 25.00%Heodo
2022-03-1955Vr6doIM.dlldll 05e11fe7f9411c89b8a9777e032dc2686c8d61062c696ed5fec491ff51d43700n/a Heodo
2022-03-19xafpIB6QWI.dlldll 2c3f5c956909b23a19a8b623e3c60fb729f7f651d98c7d62e58ff80b4764acb0n/a Heodo