URLhaus Database

You are currently viewing the URLhaus database entry for http://test.ezzclinics.com/elxaji0/BnqhzGnKzDEi01/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2108706
URL: http://test.ezzclinics.com/elxaji0/BnqhzGnKzDEi01/
URL Status:Offline
Host: test.ezzclinics.com
Date added:2022-03-21 07:31:11 UTC
Last online:2022-03-22 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-21 07:33:01 UTC to abuse{at}contabo[dot]de)
Takedown time:1 day, 5 hours, 2 minutes Poor (down since 2022-03-22 12:35:04 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-221VUfcggTXFh6.dlldll 8f3a61f16c6f0d93de8909dbdb5bf9a28208667a90439333d1f40417f5fe22b7Virustotal results 42.65% Heodo
2022-03-220Rh.dlldll 38c88390c943b0c1d4623442ec44ef4629d711507940fa13cd34090a172a82bbVirustotal results 45.59% Heodo
2022-03-22EZi3ljjZsh2yj.dlldll c23a88c51a11cd18968a924da6789309c1dbfe62cc84e18f3cf58ec3dd4701d9n/a Heodo
2022-03-22KCfxJ5ygBeMHgSJ.dlldll a36733a0060fcfcabfa10faf8f94378b162daee3ced586a4950fd73549ba03ceVirustotal results 36.76% Heodo
2022-03-22r46mlfPJzb.dlldll 7506fb7c55e85e372eac126d272a9ed1b84b258e16965843af7d6e4261b2f6f7Virustotal results 38.24% Heodo
2022-03-22pBM4aJVIwH5HvONM.dlldll 5a1347595cdeb137b68f7b71ecd7d713da39f385f6385309977ca66004f9c367n/a Heodo
2022-03-22JYnPoG5gUdWWoQzFl.dlldll 5254e038d3ae277c9675092c745fde202a6c573621ca920d6069939a15e67b18Virustotal results 38.24% Heodo
2022-03-22J250.dlldll 39fd5f52d4536cfc192f2147757ad446c2c13b2d648aa3bcdcdd8d71b4b50c76n/a Heodo
2022-03-222pG7i7yyOcSpzGr9.dlldll e4155cfa7005b103f8a87d85e5b076ba93e9d7d8d70df37bdb335801dbbe251eVirustotal results 42.65% Heodo
2022-03-22c67.dlldll 75534c017b453864a1270ad511298af631c6db76fe8938632714d14a387af485Virustotal results 40.91% Heodo
2022-03-22l6Xz9ZwoWXs9jW.dlldll 13cd76080f6166c5234405378d3385bb460d227f0d8b1debdf84f2bda80eb1dcn/a Heodo
2022-03-22KjGj8sMkzYJdO7.dlldll d183e50becf3673e6b5187622849973f2da140b00001ec0e0160a62f4ca3557cVirustotal results 35.29% Heodo
2022-03-2253WN0LR0Y26E2trAm83.dlldll 66560b80d9b2636ffce3496b6dde4cf499394076bd149a01e9da571251d210e4Virustotal results 35.29% Heodo
2022-03-22UbhSJ.dlldll a89867f1cff50a0b83ab6d65065498f87cb23d31856555ed879a284b88c3fe4bVirustotal results 34.85% Heodo
2022-03-22JVaKfgWM6iUow570IKQ.dlldll 4a053fd9743628b1af7f8f9de7ddc7df60c341f671d06fa9f47613e4b9c8a62bn/a Heodo
2022-03-21oCspuAqpUyjjjS9d.dlldll b92eb0604c359e256df89a6547e75f7836f70f8126a192c1bbb3e2b4cd09c1e5n/a Heodo
2022-03-213eun0.dlldll c33fec60b17343d6cc605eba82a407d2a857d6da2afd1f7b3bfe520fd6cb1b46n/a Heodo
2022-03-21Xgc9MHSSu5J7kUZLKDw.dlldll 52764196f87a48c27a828cfa0be03c0acd60473d72dcc1d1b49d080d02ab1478n/a Heodo
2022-03-216jxKdnK4BNWIe.dlldll d5b0ff0a199c8dea21ce64c2203e4f803706b4efc4ab475e83bf845577a26693n/a Heodo
2022-03-21j6NFyxsc.dlldll 7edd2cd74d11c7e20f63337fc5550aefbd7820a4ff0b0fa7b535a9e9706a607dVirustotal results 25.00% Heodo
2022-03-21TEUTeR.dlldll 1893d1d4c567cfcdb3eae8514ce9cc0627b35cf9f58eacc75b802494d8eae6aan/a Heodo
2022-03-21vDQl4GVO5nf.dlldll d4ccdca19b056b88e4671e95dda991a38613a3f163e07f9204cdd9b49a349e44n/a Heodo
2022-03-21ct7zleEBd.dlldll 3b2416402725a6d18ab0391630aaab188ff9f14a2f3082908165142bdb481ad8Virustotal results 26.47% Heodo
2022-03-21JQXZVbvWFDYt2.dlldll c97637b5941e83d4f3ab78e846d7951d3d498bfdeef2814a4c3614a0f5bc61e6n/a Heodo
2022-03-21YXnHyUq1.dlldll 9e35abe195e1b34ec78b5f0cbe3cddd49ad33f76cdfc31bc013f65f47779babfn/a Heodo
2022-03-219sKjmBZb5Av8.dlldll 41921bdba4a111eb24425e811b9bc1d14b41b7ec31a01c2c201f7304bc279978n/a Heodo
2022-03-21ghFd47k6LAB4uwc1iy.dlldll 4d01557865dcf8a562ef934fd53eb695002dced2cec7c0880a06c587a3a11075Virustotal results 23.53% Heodo
2022-03-21yi9g.dlldll 6fdd81288df0f7bde647c2b8d087f4f09513ae7953ecc293abad6a0f0f2a7e21Virustotal results 20.59% Heodo
2022-03-21HbalAyKY5aCgYDefs.dlldll 82c9d899b91cd709a0626b53355c4b0c7d7ce1a8ea9bb5c87e8d50639b70b3d6Virustotal results 22.06% Heodo
2022-03-21gBAYXhLgc30Cgaqeuc.dlldll 30abcf4ca04caf7bb663e2efc69dd12bc132b6c496a14171ab5c1aef7eb28071Virustotal results 23.53% Heodo
2022-03-21CNu9v5mPBgJWr8qg.dlldll af34ae1751cf25e6486b0b33e6030009e50ff4299227ec17a935c2be1ae6b232n/a Heodo
2022-03-21xgNNH9rMM7dRP7.dlldll d10443267f68d3c008cda60cba7c1b8ef10faf7b7c1f57f2bc2951b80bc4c5b7n/a Heodo
2022-03-21G44nPp1A1hJI1VDt.dlldll 88049ba4ad7aec7020f1a2f1bb483c9b839713e1b2069140248f6397fec92976Virustotal results 22.06%Heodo
2022-03-21SXYvY0QkoA3ZpUT7d.dlldll 46e87f5d7ff9d2bcae7f1d8b4c79f8b63090a1f1e8414961ddd4ef7e6a57640dn/a Heodo
2022-03-21IQjw.dlldll 950fad506659180555d52eabc40575c0283323e60c9f72f6b3968b3ed9573b30n/a Heodo
2022-03-21GliIzemoykHFwGpUvRy.dlldll 2abc555e6381b82becf4e21c73d9f8f34f96f8ac7364977e8b4be6f6d9e75b0cn/a Heodo
2022-03-21FzuCODNyc.dlldll 300b8db8e6284d9306c396cb9a2aa4b8b38914a8c5532164cb6ef2fb39685165Virustotal results 18.18% Heodo
2022-03-21wv3wULphLWDnQZA.dlldll 9cca533d0f196fa194cdce4d696ffe31fed234656fc29cfcae061e194aa647d0n/a Heodo
2022-03-21aUbT4o7.dlldll 266935ed67ce4b73ca7f2a4568690e72ef50aa21bf257fe2de1205666239edban/a Heodo