URLhaus Database

You are currently viewing the URLhaus database entry for http://1roof.ltd.uk/creationmaintenance.co.uk/TOqZOS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2205801
URL: http://1roof.ltd.uk/creationmaintenance.co.uk/TOqZOS/
URL Status:Offline
Host: 1roof.ltd.uk
Date added:2022-05-21 21:22:03 UTC
Last online:2022-05-22 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-21 21:23:06 UTC to abuse{at}uk2group[dot]com)
Takedown time:12 hours, 9 minutes Good (down since 2022-05-22 09:32:12 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-22WYIH3VSAJiU.dlldll efb06eaa91bc378b1df5b920f68acda5155bab478aff33ee023ee8d624c18afan/a Heodo
2022-05-22pAzKLrl.dlldll 2a694c560b9367b2fa3b9282754536122cfee2d941f2e3cf4d6c6fd211c72c66n/a Heodo
2022-05-22RfT7i8Ld3M6CUOOhfV2Ymr1Jtt2Ek.dlldll 62d631deb30a793ecfd8b2ca62b74456b6b8d38d7f72d2e8248038e45cf393e9n/a Heodo
2022-05-22KrrkDzZLsgTXKfu0TFCjTioSaP7lGeW.dlldll e69ed0370bce79fe396c47fca614e68c3d7183b7deb7cfe2aa1bbf2b4641397en/a Heodo
2022-05-22mYMPs4Vl8kEpBOXkw.dlldll 289c713f4d28ebb506eede6349cdc1e94e02f4d922183a87a6237dfd578f5834n/a Heodo
2022-05-22DzggrxGJeLWq0WU747jLGsyO.dlldll 113f47befa5ad19546e5fd60bc2cf30df9ae71c1171374fbff6530b57a4490e3n/a Heodo
2022-05-22CoFhO4BHn7YD1KW6qwZtA.dlldll 775510c5c5ca97ba75d302b32baedca7199e16c9136dbce9f8733dad70711c74n/a Heodo
2022-05-22AUA8Io48lVvWyzxFkJ.dlldll 940cfcd931b546f4e22887f61d56e0dfc79ec60d7e34c4f47c1c7dcce4abb245n/a Heodo
2022-05-22OMUqCxhYH69gSLAmR.dlldll bb8d18fd7df492a6812b4f6c96a3739a3a72ed0245d7363445805b467a149672n/a Heodo
2022-05-22aBaJ2XK9d6.dlldll cc771cdadaef9d5bbe62ed2b3ab6d527ad4d315772d63d9341c2fb383696e2fen/a Heodo
2022-05-221zrxxZcLKeJjpYPOEcjm.dlldll 8c554fa30ee9627c72e08fa3987cc681ecd1a63192067849790c9fd3cbfa081dn/a Heodo
2022-05-22LU9TjWF4ClGQohp2FIZKa4w54hBY8LwCm2.dlldll 29f40d485bf363d63226d4e3ec4c870d47e75a749e41a7da2d2745a2e6957b80n/a Heodo
2022-05-22RvyL0CeRUFb0iq6FnBN5I0dNZs5M.dlldll 5633dfe469cb54994cb8edffe6f7fc1331dafb9b86386bff2f97e3543f9b9338n/a Heodo
2022-05-22d4gPNgD9Dp0IutN7gg6vaagBwFx.dlldll fca1491910fbd11091be960e23566b11cd0710566e6e7c01d6cda2b09600a85cn/a Heodo
2022-05-22ilQqpMnoIfcS4Ua3jJQ6zwWWWz.dlldll 8f617d9f52f42d408b3a2c43a5fd0a27c4829f16427baee3297d4e8a0e94b600n/a Heodo
2022-05-22Ito8pNaH.dlldll 60c8f875e3d3c58cc86093cffe77bae6d2aef76fff028a5ef9ed80939035c90cn/a Heodo
2022-05-22giRUVfqw9wQYpFGmS.dlldll ba7064bea74de45e5fa76a0a2fd5691b32ffd2388bb518944a924d6d8fa9b734n/a Heodo
2022-05-22vIl7SYiDuvWy5EPfWVyCMGARdvtjj.dlldll 8e81a5bb3312e0c2374f33ddaa4417b2c24053443febc93f492211de52bb0e06n/a Heodo
2022-05-22TiIKF31agCsrMy7zMPZpWZFsdWS6erNw.dlldll 17d6d66306d8ed9900702d3cde2d6aa72d8fa8a303a88c5310e392da0cd4df2fn/a Heodo
2022-05-22DxhsxOmKGYY.dlldll c8dc03a49f91c31fd37d4d118079344cc7567168072a7abc1f5f96c96dcb8ce0n/a Heodo
2022-05-22KkCJtamCMBAi7UzSf.dlldll b8c6c3fb43791128792583f91e6dc48f2be6997df5a00d5463d9857e688a6266n/a Heodo
2022-05-22Xig9F9GrQPaGgij4jjULG3igzo.dlldll 1b53ecce63d8d236dd4e03f285d47fb4a39734c880895caafad6c3d75a4ae5c2n/a Heodo
2022-05-22OCGyPMhA61EhL5bFYx3IOh7ngyLU.dlldll 32e9da16cf0eacdfa8ea1d32737dc5da6b35755ea9a01493a129bd54ce7bf15dn/a Heodo
2022-05-22tMtJZcyd4.dlldll 0248219008b0949a24f8f48a07423b8ed20053edbc88c36a78925cebb655de79n/a Heodo
2022-05-223JsILrpYBPAEVrX8Sc35G3Y6.dlldll 525b8561d65a62d014839ff0238ad1cf0bcf211082c9c613f0805565cec20392n/a Heodo
2022-05-22fUo4L1BcE.dlldll 80e3ad3a9fe7361461f3d79fac990403393ae358f76d19ebef075dc26febb908n/a Heodo
2022-05-22Pzf96VR.dlldll b3052c0245dbf270b7eba9a53071253b31f549a20852a1a6a60d04cb30f60e56n/a Heodo
2022-05-21c60hgmXKr8qYgd.dlldll 2e69e73e8150b6d293f33ea9b9155eb04d2e8802af8b14503589ef5579d838dbn/a Heodo
2022-05-21QBWGtNDOGk.dlldll 66d6d63027f4d678cf0ab5624398f6dcebeefdd3b15f3de96aa4c730b8dd37aan/a Heodo
2022-05-21d1Rk9oUKuEOBjRUer.dlldll 5f34eb2b52fff6cda0a982245d5f574cc416e2902d289adb7637f39f5847a170n/a Heodo
2022-05-217W8hSZTFu.dlldll d35a36ae71badb5e541c1464f23bbcd939d967bfa2c453a287ba332ed0382f70n/a Heodo
2022-05-21mgFxZzv01TmvQ6AybXB.dlldll e4999742b3c60bd9e14da650ec7bb25ccc568451032c9387ea729b441c0a7213n/a Heodo
2022-05-21QhhbwG37JkQlQxEcNOr5Ax.dlldll 4829c34a462a2a1f507a71620a7c32872a572c902b3f33dd442cbfc0813468d3n/a Heodo
2022-05-21AG8u4ypyGN7Bgdlm51P.dlldll 76331e601e17a52b626e634ca28099b5794bca7d4564180d8de2cd32fbb88df0n/aHeodo
2022-05-219SS7j51qmSGnc.dlldll d1a8dda9b1d05837858141c2a191e36906453a886d9670d260afd298601120bcn/a Heodo