URLhaus Database

You are currently viewing the URLhaus database entry for https://antiansiedadeaformula.com.br/wp-includes/ZePhcZZ5w/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2104720
URL: https://antiansiedadeaformula.com.br/wp-includes/ZePhcZZ5w/
URL Status:Offline
Host: antiansiedadeaformula.com.br
Date added:2022-03-19 00:09:09 UTC
Last online:2022-03-23 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-19 00:10:12 UTC to abuse{at}digitalocean[dot]com)
Takedown time:4 days, 12 hours, 11 minutes Bad (down since 2022-03-23 12:21:35 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-20IlNmVio.dlldll df5f183c2fdfb9d1632a7ffbbf0b33511b9ba2a4ffb07446ccfa3f3e50034acan/a Heodo
2022-03-20jRrK6e.dlldll 1b5de8cba4100501431754f01ec90eb26649a9c05cc18fc1695e301c30f8c211Virustotal results 47.76% Heodo
2022-03-203o4WLP9OT41zz5eqiyj.dlldll 2091da4623e5c75010df259dca5c4efa1aa4da6cb806ccd7c99fd3e50eefa01eVirustotal results 50.00% Heodo
2022-03-20navmFUJozD7Of.dlldll 787cffb2e6f30005c70c890bf02f714f5112c6db65fe918a48722d79e3f551d8Virustotal results 52.24% Heodo
2022-03-20umsxyWPAVCoIzCUDY8.dlldll 5b6c2fc4b3a2258c4be49c36bc7c0b85e907cd5f8091c003c9ffe8bcc23d7c46Virustotal results 48.53% Heodo
2022-03-19M4PyyPT6Qgen7wd2w4.dlldll 3147567a85eed34ae6f2be040bdd81edf905384597beb99fb462ccb1ee975e43Virustotal results 44.12% Heodo
2022-03-19VqtrAhDF.dlldll 77f95bd489cb5eca6bb62e47e3953629a06bcca3d7ec861634dafcb2da26151bVirustotal results 45.59% Heodo
2022-03-19UnxcHuc1N6paY2.dlldll a640bd07cb2ebf924f5f364b733532a1e9de72e2784cca26584b301d4d481146Virustotal results 44.12% Heodo
2022-03-196ovQ6wRUOecwTugq9oF.dlldll b29c4a9cba679065204c1603fc2f962b1383bb348e6c17d20009be0c6f8a8489Virustotal results 35.29% 
2022-03-19qY0RHhX.dlldll 85eb931e0669c2579925d8df51b280e6749d52c61031c6e5678f70ebf2c6bb6dVirustotal results 29.41% Heodo
2022-03-193pNrJYsQBELWn1.dlldll a2d0ee86a318f23f468ebb29e994fae6af0207b2c188690235e68d1a92e7f67dVirustotal results 26.87%Heodo
2022-03-19u5tOUrL.dlldll 20bb4365f7f51ccc8f2e3b66c664f3e3918c86fd21c7b41d4fffc865fc65804dn/aHeodo