URLhaus Database

You are currently viewing the URLhaus database entry for http://oshop.es/test/yLT3Xjra352ky/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2201994
URL: http://oshop.es/test/yLT3Xjra352ky/
URL Status:Offline
Host: oshop.es
Date added:2022-05-19 09:54:04 UTC
Last online:2022-05-19 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-19 09:55:08 UTC to abuse{at}hoswedaje[dot]com)
Takedown time:5 hours, 51 minutes Good (down since 2022-05-19 15:46:42 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-194e7SJZLa9rm71uP56tWJz819rHkQkx.dlldll 45753b41671b739ad4204bc75dfc6bd48df8814f86e4f904c400ba4be27a8ff1n/a Heodo
2022-05-19RQaQ8BrD36T1k1ZFFu53yz.dlldll 8d4a0c8d27fcc7fe7f0254ecab4f19940fd2b78095125ffb37ab2c7ecd804999n/a Heodo
2022-05-19NODlGfW8nuvM5BlLuMbks8UTnHl.dlldll 3786a281d7fc6d8f992575b74947eeaff0ca8f2448a70e71fb8facaf89a13790n/a Heodo
2022-05-19G3T8OSinHYfMHOaHHIUXomH8LwI.dlldll 57d8593364716f02393d8b8cea942479e896e14d28cb6d7c3b59dc4044fca532n/a Heodo
2022-05-19qjgUStBVyXIdwYO0DxVeAGL.dlldll a16e8b2fd15fe17ce1f34f767b2f774054b9c879c2f96def20a756667b029defn/a Heodo
2022-05-19bC16KFpSYj0u4ONzvyFuEh.dlldll 5372d029efe70ca54b509422c8bdcfdcfb78d76f994ac3f45bbfe1854999f42an/a Heodo
2022-05-19rb8RtYT8CN7pOdZGuRR5jRXDQ.dlldll 71378a0fa3525c9e3a2031d7c5d4bf2fb21fb9af4d0f52b856a4cd7350e62893n/a Heodo
2022-05-19E7SEbCmrBl5X4SdjapBP.dlldll f515d2b8f18d1375defac120fc33f7717714c1e1dc18b5b6e0db68f8bc7818d6n/a Heodo
2022-05-19FNIcdEmDkMxe8WEowTpq.dlldll b9d761f714490bb50a4f4c4c5127d7161e6b453cea65d8abd63801bfb8e3e1f7n/a Heodo
2022-05-19non4XEWriHJaa6.dlldll 16b69d79b985bbffd72cc7516f6081df0cd8f3cd47227974f5e03e9fa46f7fa3n/a Heodo
2022-05-19743Q3g.dlldll 798198b53fea0ef1103d42aa14406dfe063aca20c8b65e75b6e36f84a41843c3n/a Heodo
2022-05-19l5Jbzw4KCjf.dlldll 80fe930388c212aa1c6f3db4e3858decf2dc8788f80241e32c0209059d0dd657n/aHeodo
2022-05-19UdwI13DMuvfcJWpY7Ypq9KxlW.dlldll 857e231ea59d70f5eff295fb842924e44f5929aaf2b58d73ab3a587ca59673d0n/a Heodo
2022-05-19BuZt3rEYV3a1RTyDt2vZvzyJ.dlldll 3eeeb8ec45cea58516afe7aeef24c65181ed282fe834207408368c255549e069Virustotal results 16.42% Heodo
2022-05-191i59iMw87BUF32uLoc.dlldll 6d9d3393e9901a4e0a85f27a7c64f7ea05d4568625d982908516398adc61d685n/a Heodo
2022-05-19JpxIdQFZX.dlldll 96f58fb5fa3cf7e7baf5b20138d4f2efc6e550d69cefa6c97427a6f7f04ebad6n/a Heodo