URLhaus Database

You are currently viewing the URLhaus database entry for http://www.metalgas.com.ar/wp-includes/2Ecobg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2198901
URL: http://www.metalgas.com.ar/wp-includes/2Ecobg/
URL Status:Offline
Host: www.metalgas.com.ar
Date added:2022-05-17 07:04:15 UTC
Last online:2022-08-30 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-17 07:05:18 UTC to abuse{at}hostmar[dot]com,abuse{at}dattatec[dot]com,pablo[dot]pepe{at}adinet[dot]com[dot]uy)
Takedown time:3 months, 15 days, 16 hours, 28 minutes Bad (down since 2022-08-30 23:33:40 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-19hBTNNtkC67.dlldll 206a23a44c5805bd328c83aee79328199e745f2806acf22a87c22b84271dde08n/a Heodo
2022-05-19HYUnDOycN2RAAmYWw3Vn3gUe3PB0gelUwLI.dlldll da80572c7b389f91c832febf5e69ef82db6f73943a8fd15ff8a332416101b163n/a Heodo
2022-05-19qJyBRGI6k7v6Ui0x5pbUPGRQ4dbCn.dlldll 82789f7be59bdaa59bbe6fed33d24feebaace352ba461033b1812bedfdde339an/a Heodo
2022-05-19g3ktfrYqnMBZLv6XuXD9teir.dlldll 4073a9008388cbd96bb79bacbb744b2c80349b2d819bc4fad98ca477703348f2n/a Heodo
2022-05-19wEnF1IxUWUuWcz.dlldll cd61409e23f3432965dc41d5cccecd51c066709d654719f4da1db2bb15e69d49n/a Heodo
2022-05-19rRbEocU4f7ERF16jhO3TC.dlldll d75135b6d0b3822a253bcb9ede98df5a27fac6fd48d114139602d03c8ddbabd6n/a Heodo
2022-05-194zjOJKvdp4sksFgtlamvM4dZf4BzavvbZ.dlldll ff4c340e78d10d1fd1a7102de4bad0d3da08c005b9ab0adecee210a8ebba9ec7n/a Heodo
2022-05-194qB5jJbPZ1rHz6G7CQlCIvVGDm.dlldll 106526a2f25329908d121a993ac4aafda0b08fc7cd41f7af4e6c8a146f975009n/a Heodo
2022-05-19IIt8o8dc5gX4.dlldll e27d47f3ccca03181c75beadd3b880e206d7355396c5126b696dc3c79fc65b69n/a Heodo
2022-05-19NE9atHZUjYp0p3iwEnSu.dlldll 7c9d540566e55a7aec3c866ce34abc95cf1d1975d3466338843658f86693404cn/a Heodo
2022-05-19Wy0lbFR3mqdV7HEnnWWp2nQ0I3.dlldll a3c9d130bc2e201bea26342c95f4658f6bdc4af8f9f88626f909aa4cd95ad7ccn/a Heodo
2022-05-19b4UDOn22jzl.dlldll d3d28769c28792d850ca9a941d0ae61dffcf650d7fc697c319a53a3f6e1d0036n/a Heodo
2022-05-190EgtLdKKV141RBSuR8lmRwchDvC0.dlldll 6af1b19f9ee5a9b894b3c2a6966c7ffa8d146c4431a05421c4990b05d50d939cn/aHeodo
2022-05-19NkOqr7wLoR5EmAZAz199jj.dlldll 4bb4cf08ae31ac5526f27a517ba3a64c4ef20d33affe33ceefa51e13c0e5adf5n/a Heodo
2022-05-199ExQlA.dlldll 0d8325183210d859119562a26b9a2c61d74f07d36cbe7f29a31d3d29abe55675Virustotal results 16.42% Heodo
2022-05-19HHevlAGfxfQyshptIxYcwvCHGiRKc.dlldll 4c0142ff7b581490998c6cc47100adf121987ed68d5ae6ce89c1f258c3acb9f7Virustotal results 16.18%Heodo
2022-05-19XClplKooJuFeexURx.dlldll e74a53b3a9266ae93c9e42528e8124014695f7d7a4afdbc5ca25ebc0ce207719n/a Heodo
2022-05-19s5K8A58sBbI5IQBOETG5v9qKQ.dlldll dd235654116ac0c2957a9b9a10bb37cecc648e466b362abf0c16c31a29ecd317n/a Heodo
2022-05-17gXm8lJalEoK.dlldll d3c5f3d36648827162ab79eacd13f5e911fb084879ae596435ab0c471c95fabbn/a Heodo
2022-05-17sw5q59bzK9EBuXDlWyCpYi.dlldll 48dae81aa1d2e76dc5f26125f419850baa304908e4d38a45fa29b7f9f0f96baen/a Heodo
2022-05-17ewWViesCQMflTy1da8ZZL.dlldll 3eb7b4e88567f32284d5973167f73fee0babd3c268b252847d0b5146da0c29b6n/a Heodo
2022-05-17O6LNyP4Wf49LFOh.dlldll 25bc5cb2ca2cd50d9eadbae03e7a1e8b84425373fb9ed49e1c9494e7dd98070dn/a Heodo
2022-05-176srNt2ttabfxt7vdYclPQQDbP.dlldll 664a1782c641c00b2e8bc7fdf4ccd437a12b33eaebe86b14c6e2f14e0d77478dn/a Heodo
2022-05-17Ws6bRMxLaNDd.dlldll 5ae696ef4b9a6b04c78fb13409adebd143dd3ec17f0a16d2fe498db6b8376335n/a Heodo
2022-05-17nlRx7iirWwgoD8bYlzR.dlldll 698625aa38dc2c381b96b2aec29014476c2ca1f69ce8d03545b471b2cac89407n/a Heodo
2022-05-17hChfHTWpf0WvIuAMsrZABEivHQ.dlldll b47f79cab7ee952c9a92d8776d008fe61bc70c07c9c884b597f3df2c6f582dc5n/a Heodo
2022-05-17HdfuYoocvSgvh1vGjMR.dlldll 0f5c7fe33099c12c9485ecf1e781e2a5438031cb151e5fe7bde55a3e14e57f8fn/a Heodo
2022-05-17phhIafPm9B5SBHvFFU7x.dlldll 80951b25e0bd633e2d6e4ea5a6b8e1ad46aa7ffb4f3723bd8914af5c447301fdn/a Heodo
2022-05-17bwtGDBkHa3pZEfwn.dlldll a3cb8db0a725137824e9a8806c9cfa9fe74aa231734c8ab23385bc9e565b18f7n/a Heodo
2022-05-17prbEtIUJPy5pNBsE3feWeaY.dlldll c27cf206ed4823c00d579aa73c333c7eb8d8093f972307b5841e8fbb79551f67n/a Heodo
2022-05-17JDVH1dbpLYFjDwqHhnuw7.dlldll dd902339f83fe8da9865e6f337a709c361a1b3337698f74bec56d1f43779e8f3n/a Heodo
2022-05-17HOucQPaWrTZAlEy.dlldll 413fce832966979bdb2af8e682e02e0713d1cec51a1d23556117a018b0c8af43n/a Heodo
2022-05-17IVUWdey4NG7dNPHFTjSK.dlldll b994322beb9d6f16f54b73f2b734d3d1fe94d1a401343ea57a54f36a068fc26cn/a Heodo
2022-05-17v5kBrTI8ixZcsyX.dlldll aa9289a4004b4a46323b52305826088e5db5c110dbfc2aee7699fc034e80e053n/a Heodo
2022-05-17SgAvZuBcrRmdI6.dlldll d52dc453c875dbbe9c51c5b394ae503451d2160910de706e29717ca2e7a6d1c9n/a Heodo
2022-05-17rPZIMOHV5aXm4iTp.dlldll b686a84504682214b9970a8f09ec8d004bbf19efa165af851582bbdaa7caf6e4n/a Heodo
2022-05-17AaMdZ8s4KxJKdtzbp3q6rro.dlldll ae25f4afbbd12ec28eecdff45ae177f4aab0fb3ca1c3f8f7fe8f8d2e292599b6n/a Heodo
2022-05-17MZ4SXHt.dlldll 2128c0a730a4e6df07bef8cf82b6d63a58660bff40e7883167ffa29602cf2523n/a Heodo
2022-05-17ijsUa3.dlldll 50187d54253d0a44d7661e2a18e8f787fa83a0751ded23b93f096b94bb10a313n/a Heodo
2022-05-17oBHydcAdzNMtGAwwrbjU2c.dlldll f232faee725602817debfedfed4c38b4dc4a9a39128768885b083103e95aae7an/a Heodo
2022-05-17Vzbrll9JRk8yUB2pUXAr6s8PeD.dlldll 976dfe90cd3b9d4030eee50d965d073aba7687e4d28f12fa258fb901f804e86cn/a Heodo
2022-05-17aaOZjR39EoYL.dlldll fb1941c83d52248dbe969531538ef73fcdea361570ae1ba21d35882f3f0c59adn/a Heodo
2022-05-17L8FmdxsOjXyxqT45.dlldll 2abaea28a40645075fc01232ca3d49ccfe12542b0e08c477056ff7f421f10ea0n/a Heodo
2022-05-17OrhDJNBY16WBW1.dlldll df4e1118a5bd9392059254135e4c8b4a73af3c90d4ea03fc1ed3530c3f04ea67n/a Heodo
2022-05-17zZ1o0U2XH43RfR00Nj.dlldll 760335078225c9a61fd50f2d8b9995dffa3718ac60f2f4ae54bf0e0c244906d4n/a Heodo
2022-05-17OODKmNb.dlldll 25804825cdd1a9f09dd461e275421d84ef8fea152fc64243e882b74c925faf7en/a Heodo
2022-05-175BTkL0TG8Ls4yTksd0L7e1dZA.dlldll cef92e65beb02fb87352310ca7bc7a2c725754b05e284eb2b5dcda3580cac6aen/a Heodo
2022-05-17NnODtVyIdlEAT3G3DBSmKnqwFkZVzKB.dlldll 55d5df25ec2ae44fd2f5df7bdca21c6c8699d624943598756027bdac92b53cd0n/a Heodo
2022-05-17YB7KpjK5wnt5H1.dlldll 5a98c588595d3dc2ca7c723021001d769c966a953dd4041e4c7e26fb6da20782n/a Heodo
2022-05-17iDNrK47LwwiCNF2xiNfRq.dlldll ec4f1f1792662ede7f0253994b1e33693bc2b39bc1cb3f309b5808d32f939c5fVirustotal results 13.64%Heodo
2022-05-172Llu7vDNd.dlldll fa774d59638c6669ba754f2287439aee52ef6cdc8f91a9c7be5b231a852c354cn/a Heodo
2022-05-17Gz89PoS1N3W8dEC.dlldll b69189ae15a28edee71a112453ffaa1b4c71217ecfed76d64446d20106d9052an/a Heodo
2022-05-17Z0sKVA9cP4N0XVfvaUTeX.dlldll ed525aea4cdf881ccbd8cdbaf64de4be7192248c009c4d310acc57308791f1e6n/a Heodo
2022-05-17nXMu6TUg7lnu.dlldll e8cad4eccb1b38af24c66563661cf9d85caeb23d035e68eb2d05105253c12d9fn/a Heodo
2022-05-17scyGiuFMef.dlldll 53eb8f467283763b4fdd468932a9d7ead31f7a6c37159680b8bd9ee6cb93de00n/aHeodo
2022-05-17i9S3H5r9qecaqnuxqX6cm82JeIKJkS.dlldll 0815cf8c1b4adcf980b1a2939cecf49a64b922931baba2e4794ea071a5fff552n/a Heodo