URLhaus Database

You are currently viewing the URLhaus database entry for http://ctfilms.com/ks/2ygJuGV0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2114424
URL: http://ctfilms.com/ks/2ygJuGV0/
URL Status:Offline
Host: ctfilms.com
Date added:2022-03-24 21:19:04 UTC
Last online:2022-03-25 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-24 21:20:06 UTC to abuse{at}aware-soft[dot]com)
Takedown time:12 hours, 35 minutes Good (down since 2022-03-25 09:55:42 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-2598sJSB8HM3dmBzC2qyyp.dlldll 27cb42499a8cbcce160ea270584b40555821660443e5f3ec46d8389139012007Virustotal results 30.30% Heodo
2022-03-25hBgGzD.dlldll 64a487871f2a3fde8ebcca640bfb0587a08f812e39992db67da84202ef14cf80Virustotal results 26.87% Heodo
2022-03-25f40bnw.dlldll bb1877d5efa208b0294264da6f7d58ee6c6034f9341b84f5129379892aea0c9fn/a Heodo
2022-03-25W1ha9Wmsd0Pg6QyUC.dlldll 96b89e7043d03ec6c64d90f7b53af3ecfea1bfaa2778560be49c8c32bf21f97en/a Heodo
2022-03-25T7vbsZWfccsTF.dlldll 1ca8315474e5dba8b43b5382bd9e07326d9fc2a341882fa02ea4c88265fc62f5Virustotal results 25.37% Heodo
2022-03-25Q4Yf5mHFsSpC8SD6EHvrp.dlldll f652217e10e3fc5386f45c470a52a3f9bfbc81ca414ee367e341b5fee31dc3eeVirustotal results 26.87% Heodo
2022-03-25E90d8eUpjC8UUQOIG005fhwUQh.dlldll 6478c60b25711aab93883e65b50102a5ec90a8bcf603837cb66705fdad028449Virustotal results 25.37% Heodo
2022-03-25wcsSBvVKFJDIiAXAJXme4B00tdR473QI.dlldll ddccf6d41262c84d26d72d253f232cde1f409d93a1e350d35b007dc4189743fen/a Heodo
2022-03-25wdqeaWPCD7rhZ81D.dlldll 910abc0a4905726b47eb849395044808cf26f8e498c7c1165a0984e98c346312Virustotal results 23.88% Heodo
2022-03-25sLwLeSrbkC.dlldll 0b20dbeebc479142143e56f1c0e7973fa5266de794b10b758b703e6d53b7ca7dn/a Heodo
2022-03-25pNyZYPxqt1p7ZAkUFF0ah0LE9bQ7t.dlldll 0d5f52b4fee943f9ef848e9835a3ea17a06a95f3cd8156ccfb31f1a45794d562Virustotal results 23.88% Heodo
2022-03-257oHWSG.dlldll 334bbf8c41a58d52126f59ea7f0461845c847498ef75f379dec50444241e16b5Virustotal results 22.73% Heodo
2022-03-25appkW3I0jAMQzx8eVVqjgOBjDIgE50lQbS.dlldll 006fbbd5d30db1b145ddd3e756c2bd7af7e0a9e3b1f9c796c6888de5f3113678Virustotal results 23.88% Heodo
2022-03-258G8ljFPMd9s1bfbNvlUOfF3.dlldll 46845d0c1fee490e32ed4e5d1ba5f9f99ab88ddcc7c83888b4932ac65eb16dd1Virustotal results 22.39% Heodo
2022-03-24PZcbGEdrOprW0diuvtFepH04gl.dlldll 22b7eb665d47c061de1854ef2615a7f6cba6e3c4838474a805a5bafa7740a459n/a Heodo
2022-03-24n6EfJBnc5xJbJCIdawdad5.dlldll 6d2fffd32bd0897c391d3a9b5baf6eac7d97ad9f7cc86bc540a0d89085f4f272n/a Heodo
2022-03-24jUSXRUbj.dlldll df31f5bcdb93c150d90433504ee55344caf97d63d39cb4684ca7038d23b5d8c4n/aHeodo
2022-03-247dIffYKagxRBcD8Suah1G938b9mVnsscE.dlldll 98eda8c927b248b68196a97ec97789c3e705551b5335429f6765a747de174134Virustotal results 20.59% Heodo
2022-03-247kmHUCW7Yp1gO9FlNpnoK0TBGTE.dlldll c12a21064320369143cfea63e2f20a13091d13f2d0f3eda63260d293fc438e05n/a Heodo