URLhaus Database

You are currently viewing the URLhaus database entry for https://e-fistik.com/ajax/PnA23/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120483
URL: https://e-fistik.com/ajax/PnA23/
URL Status:Offline
Host: e-fistik.com
Date added:2022-03-29 20:00:07 UTC
Last online:2022-05-25 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 20:01:07 UTC to abuse{at}ihs[dot]com[dot]tr)
Takedown time:1 month, 26 days, 7 hours, 2 minutes Bad (down since 2022-05-25 03:03:55 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-30YmIVboKpCIpp57HV.dlldll 8d3d42bef9fd408a123dd6eab36f020e0c0c3d6fc492faa0ae2d086192ab4069n/a Heodo
2022-03-30ZqremlVktdgVnn.dlldll 6d4a77d64da5eacad1110ae19994df0c769d5e10b059791aed46cf867fa57398n/a Heodo
2022-03-30eogF7F.dlldll aba5a1ec13fac61874c437c8abe2951d5cbf4e4a6ff4a60c895870187876118cVirustotal results 46.38% Heodo
2022-03-30FVuOSagwdpA.dlldll 2a91694aec028388667efa971fa116247485de7babc84a243243526ca4b948f6n/a Heodo
2022-03-30I3iGjt7sm7sFAa.dlldll d90274f65dc0fa4e83f86f179a4600f1f1126578143e4e0e505c3e98c19c0a1fn/a Heodo
2022-03-30I4j1QyCYK7xhrxV45JOW4zLLO50.dlldll 5ae6a41eb7f74665f1ad639c90db1ce834aa4402998253798167e30ac0f56bcbn/a Heodo
2022-03-30TlEINYZ.dlldll 66c1ef13e895f97cee478e9a31c37f84fe30eef6613e7532118b906d91d26ea0Virustotal results 36.23% Heodo
2022-03-30qF0vgJ8nZ.dlldll 5cfbb280f66236620d24668416939d66dc17e94c2f826b02db47f2f9091e257bn/a Heodo
2022-03-30r5Qy1FUsE52Cta82JZNWb.dlldll bbaa2109d1728745b79adaa17b168b3e8cf47c6314ccf2b728ad443f98eb458bn/a Heodo
2022-03-30NboG0qbmPAkh7V.dlldll 70c9936c9dc22cf55e86c1b288ead8f62e296721f925d8c99cf66e16296b3ee0n/a Heodo
2022-03-29QlNZowuPP5eh93LfH6KBsq.dlldll cd456c6463de844997e75a72fe04974ab93e2308f226d9a60027847a16bde4c6n/a Heodo
2022-03-29kSvfdn43cG8flGts3yoBbJmjG.dlldll d85d4a87015e5a952efce6c8fcd291d57c66b8621bd752f55e1f2ff094fbd8c9n/a Heodo
2022-03-2976oeYxDxo624bDq5.dlldll d8882a584bbb89d0483c5a4c80a68ac69d7c7c16b65a7d1eab3b417b1601ab23n/a Heodo
2022-03-29kzGTEcazMpL26.dlldll 2828f42385cf5715c60e446a9f3c17bba84a38e71aff4df26b330ffad47787bbn/a Heodo
2022-03-29WTz22pLqzZgzXJqcwt3vrPpDaM9.dlldll d46a637d8fbb63d17fbfa0daef8ca7a06d44686083a0fd237653f808909ada73n/a Heodo
2022-03-29Wy4mmF78WYJz8qfn8DB5BJ8ClWCVP.dlldll 250f901c21b015388313378585de67c30812cb9c4dbb5e09b97321511c0cae6an/a Heodo