URLhaus Database

You are currently viewing the URLhaus database entry for http://www.geowf.ge/templates/TlbsO1F7p/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2167518
URL: http://www.geowf.ge/templates/TlbsO1F7p/
URL Status:Offline
Host: www.geowf.ge
Date added:2022-04-27 13:18:06 UTC
Last online:2022-09-19 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-04-27 13:19:08 UTC to abuse{at}proservice[dot]ge)
Takedown time:4 months, 25 days, 10 hours, 3 minutes Bad (down since 2022-09-19 23:22:54 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-29h3eHFlLKzXD85LDjAeGOjf6e7Z.dlldll 314c4c4054769482d307be21a6f5b3c1bf1c392a688c8dd1060fb136ac4edfd4Virustotal results 13.24% Heodo
2022-04-29VtzlXlLXgbDns6.dlldll 5622d8bd8e8a621df2ee9b8ebcf924cc6306b0394423196df8e0ba9140a65f4dVirustotal results 11.76% Heodo
2022-04-29Qv9KC8v6yGuNvuU4pWCy.dlldll 5b2675bc983ba3885fb17c51e9a38f752a7c594a9399df610fc5e9f635ef9892n/a Heodo
2022-04-29chrVH0ByPw8n5Afogji9QZpA0.dlldll fe5953e4e6ec5eb15b77da53a719decaa47ff91319cfaa62c9e27e474afef417Virustotal results 10.61% Heodo
2022-04-29LGDBW5cQq9jaW8DVw1gJUtyPxyn.dlldll 5b02a15b55d4c2aa8d3b18b8cfe9dcb746f764932a5644a3a033827963482601n/a Heodo
2022-04-29iEdXPP.dlldll 0b0efb735899219f463e2fe3f54f36a938d5fd3802e914e7a646797e35c86318Virustotal results 10.29% Heodo
2022-04-29xt3hYpkssw2gXgnzwyBxZAWzpkDus4H.dlldll 370b4079eaaa66ce41272e5543c7a03b339c8e107f11569ff25ebfa2566faad3Virustotal results 8.82% Heodo
2022-04-29McpU94JcsKFmY7zUcBuHvjH2NEFz.dlldll 34907e167cd30b6a766705815f1205ad47892fc4ffeeb2318d8b8b027dbae98aVirustotal results 8.82% Heodo
2022-04-29cwc2Vy0tdcbECxXs.dlldll d26d51e3912e52c0d3cfc96b5c37f5ee2e7518d78844f5c7cb9d96c776344909Virustotal results 8.82% Heodo
2022-04-29EsXK3OdUCXWBFQ3qnI2PQlw5W.dlldll e7106ffba47dea194e332984eff9c14334ef7324aa4a80263e01b58a5d4d07c8Virustotal results 8.82% Heodo
2022-04-29iJIV67GXC3Xu97wVDPZI.dlldll 2f92e4c4b8a47329097b5b286d7d5016b248c57d01e9ce1af02689f1d101680cVirustotal results 11.94% Heodo
2022-04-29oBEZGkm1j.dlldll 40a69214711d3a2b4f69521938abe7de703a83c2fe309fafeb5e852480aa92c3Virustotal results 8.82% Heodo
2022-04-29M8FFaPTCp6WBjC9E.dlldll d4e581454909fc5659306082eccfde02b5258776cf63869c109628de32e2c0c6Virustotal results 8.82% Heodo
2022-04-29VOw9mlBQK2oAFcRi9y4L84aKENQPIrzl.dlldll f3aef0df028cf0d0590f4fa4affe8e61e3d9099d56281520f575ea75e7d0d1b6Virustotal results 8.82% Heodo
2022-04-294O3ck7woZ.dlldll 2ad0b81f13ea605659e7ff3f518af0cbcf2b528d199f1925053dbd95c24e8aacVirustotal results 8.82% Heodo
2022-04-29WhE5Zzz7WgNAVA32nEMPrROEdqXWML7Wu0V.dlldll d854855e9e491a8c214d24fe506ca2ddb7e681f1ee3dd992add273065e7f4ad8Virustotal results 5.97% Heodo
2022-04-29Ao1AVSlBfaUeAYGsQ7.dlldll b31e9b3add204577d136babc244076ca285705f840b9a23d38798dfe904de369Virustotal results 5.97% Heodo
2022-04-29EqHlviSyqlCFdkqBVTpatAK.dlldll 16942d1935ac936831da62ad0cc0fe5610b4511460f2b6ffbfb45315efddb68fn/a Heodo
2022-04-29GZTYEzgnMU0rN3QY1OB3BPMI7E5WhBh.dlldll a5f8ff8fc8ca73039e8811fc15587feb02d3cf814a0cc6002b30240457cef917Virustotal results 6.06% Heodo
2022-04-29xaIOB7Q8XwzqwwNcSOjS0r5BR4Ll.dlldll 6a920e41d82c942ee1113c3184139ce2d42ab8b76c14cad221c3bdf9ef741d71Virustotal results 5.97% Heodo
2022-04-29p1d9Lpj6UGC0.dlldll cd822d026c0b5bf5a1642df3d2dff57c81b0c58b4acc99b5486cbf9d7195cc73n/a Heodo
2022-04-29XBQQPXOwfuO.dlldll e64dfd100dd2046eb3d30833a5ede1af5692b7448e4fd1f89af75d05fa617fe0n/a Heodo
2022-04-29aIzL86k2zzTdRb3hHWETvBF1.dlldll 32ba890c17c3adad9cd83d9d9b90d7900c30eaf3228d790e83767b31377d1946Virustotal results 5.97% Heodo
2022-04-29M5HREuIMiFcleZ0.dlldll 9eebec5f594213b3cb3d0d773c34ec47bac8e846af5bcd5a47a0c6e516db004eVirustotal results 5.00% Heodo
2022-04-297mvXcLAyIs5LSphpTV6Tc.dlldll 0fe6418296d4e3a4f7a7f4f2819c920946ed82fedd12adb79eae29fa82ad78c9Virustotal results 5.97% Heodo
2022-04-29yS28RJD7J.dlldll 638bcc6f5cfd617c50b3785498ec772f8421a3c4b0981824dd8ffc68766ed174n/a Heodo
2022-04-29hztbgC0fF19vEe7XFgMciDoFLpavc8LsAFd.dlldll 1ca90ddb50ee325228e1d5aa5d227b1bd2b15b1bf1c5aa238082f51e27ed91ecVirustotal results 5.97% Heodo
2022-04-29CJ8utUipj8PP.dlldll af7f49e8ebfcc3c0afc5deab6b58fc6d331e0189590afb4e92a908012d03d33bVirustotal results 4.69% Heodo
2022-04-29FEodh9.dlldll 03c561771e2509c84ace5271ee2969676b602d0c39ba9c11afaca639e198cd3aVirustotal results 19.12% Heodo
2022-04-28VUyqMW.dlldll 69ea924e7e1f651cb5d53ef5260026001a553e656ee18e32255934a86931bc66n/a Heodo
2022-04-28XczL27PACv8PJo347jSBUiaP4A0Jgi.dlldll 2fc38923fc45b8ed34d328ba5bc1aa0c47bdb267642eb925e2a99f16908b1105Virustotal results 16.18% Heodo
2022-04-28RomvzwdHHUkK.dlldll e539d83654a7d2f46df45ef767839854dd7e30f54cb7a39ff21a397dd5de3476n/a Heodo
2022-04-28l9KUvzjwAEpuZcBQPbEwlmnajf1oH.dlldll 0204091a2b916ecdc6b5f327dabd6ac6b0828a073573e89a72e54722d47d258aVirustotal results 19.40%Heodo
2022-04-28W7diBhTfenS9l2AZ.dlldll e05243ec70891d75bbd33d5ac93a6a4f40adcd1d0f9e3e6f8a9cc2331b5c11c6Virustotal results 13.43%Heodo
2022-04-27MQr3yRVMgBv3ERJ3d5du3LD.dlldll b481ac05ea9a59eedf6233166327057279babef26c913a8e89536472b192e86cVirustotal results 9.09%Heodo