URLhaus Database

You are currently viewing the URLhaus database entry for http://morel2.gotchahosting.com/wp-admin/GCwwBB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2198900
URL: http://morel2.gotchahosting.com/wp-admin/GCwwBB/
URL Status:Offline
Host: morel2.gotchahosting.com
Date added:2022-05-17 07:04:11 UTC
Last online:2023-01-21 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-17 07:05:15 UTC to abuse{at}ovh[dot]net)
Takedown time:8 months, 9 days, 3 hours, 29 minutes Bad (down since 2023-01-21 10:34:48 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-17DAqHbQBiQ43IU.dlldll a52fd260665295cf2c3c16c1c007ec6916fff7e6ee923658eefca3ddb1b1c78dn/a Heodo
2022-05-172qkOU7Oi6.dlldll 342cce54dcca323c111c8ae55f702b7db336e2e214472df97ba25601d147034fn/a Heodo
2022-05-175VmJjydfG.dlldll ef5d995fc84c62fc85a37c71ad65707ab6f3fd5332efb7e4e16226a2f32a6ee4n/a Heodo
2022-05-17cuLUqwtrHyDv.dlldll 78785a479765c9e069ff16cab90e0af91ed6927aabbf476ad481ee0d68e3cf2fn/a Heodo
2022-05-17pJqzWZN5uVhxM68UYdSlL3CcSkzUOiUaGTe.dlldll 0b87b9b6bec21d4f945609435b2a86586a17e1abccf358cfb2d368483d3ec349n/a Heodo
2022-05-171XBhOpQnpFs9YWIppf2tT.dlldll 4d36c470bdd417b87bfcb3c1605cd5b677da3990aa02fb168828c3ce9bea424fVirustotal results 14.93%Heodo
2022-05-17xR9qbdEIctzAZFzob8vXOuNzjq.dlldll d3f2534ffa3ea1b20b6181abd10f412a3137dcb46b8b5fddc59bd1af5819e075n/a Heodo
2022-05-17wKvq1A3E2Nq9mvfelK6iz.dlldll 60011a19a16de56a2674421532d5fab09ef91afa0b28f0fd97f9273a07fc7d62n/a Heodo
2022-05-17oO0YmvpMBg1zuE7UmddrwuxLuMg.dlldll dc6f9dc70b77bb0d5f793de9f699337b467a4f98c6d812a5449092630548cc17n/a Heodo
2022-05-17ywwrWogNqDF.dlldll 0cd2ca4b5f143a22f9d2beb89b5ea0d27ad1e0ee2c22961f4105bca5a617f782n/a Heodo
2022-05-17FbWwkimjsIdiagyIW3W.dlldll bc3a7bcb6904b422e4c42977c265a3be9e4c1e9a96de8d70a6183b97baff47a7n/a Heodo
2022-05-171tgbq7vZDa.dlldll 62e8182ef973237377fa1ef84bb1d92a5954d1e5fb75c251bd4f37aa277a9fe8n/a Heodo