URLhaus Database

You are currently viewing the URLhaus database entry for http://identidadenaweb.com.br/cgi-bin/WhUzWbySU6HVi3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2197088
URL: http://identidadenaweb.com.br/cgi-bin/WhUzWbySU6HVi3/
URL Status:Offline
Host: identidadenaweb.com.br
Date added:2022-05-16 09:33:08 UTC
Last online:2022-05-16 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-16 09:34:11 UTC to abuse{at}immedion[dot]com)
Takedown time:2 hours, 16 minutes Good (down since 2022-05-16 11:50:20 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-16BFvsAzTbhhG2ayh4VtCozhAIHjXLRIgGvEl.dlldll b10923c79840d49b730032aa7c4ddccf066ea4063d52d4f67e28d7941c6db8abn/a Heodo
2022-05-168i3Qzw.dlldll 888feee0025734b3e7df4cd526dc6f02a091c3e189a0423070dcb50a2bcab708n/a Heodo
2022-05-16do9d08pG3nC4.dlldll ee9ae999b0aefbdc3d480b55f9ccc62d89e0b3d2eaa8cce009b0d3ec65463ba3n/aHeodo
2022-05-162wL8QnPcEpo7GFa8.dlldll e8ab962a8f8d798d29ebef581586a3e44cad286d1091955eb81bbcff6be186b6Virustotal results 23.53% Heodo
2022-05-16xA9r2IRewcmAie2b.dlldll f3c7d445d1414d88cf2eef211a3c663d8fb3ca098cd38ad12dc0e976fbcb1293n/aHeodo
2022-05-16Wk62oXQZm6jPmBloX0vUHA1iKU80bD.dlldll 1e115a76719bc7aad629fb6ea39f28d18892f7d39ca6d8678c257e963c2d8d02n/a Heodo
2022-05-16CgtQmf6QdVY0O4ovJi19LxrklMpPlEH.dlldll ab59cfafe0221b8e5e4044edba7bf6dacd2e291a4d24b4002c5fb05e08e31326n/a Heodo