URLhaus Database

You are currently viewing the URLhaus database entry for http://virajindustriesinc.com/fonts/OxcnRyYlItMhvrsn0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2210488
URL: http://virajindustriesinc.com/fonts/OxcnRyYlItMhvrsn0/
URL Status:Offline
Host: virajindustriesinc.com
Date added:2022-05-25 08:05:09 UTC
Last online:2022-06-10 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-25 08:06:11 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:16 days, 0 hours, 43 minutes Bad (down since 2022-06-10 08:49:47 UTC)
Tags:emotet link epoch5 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-02Pu4EaeiOFrqKTlq.dlldll 892d8bf264a6520a899a71e0dd407fdcec6b97ac565cd42da1cebafda377a348Virustotal results 52.94% Heodo
2022-05-25BWn8l5z5dvk4C.dlldll a3be11673338865e881545787321ce37d60bd69562584ec250caa5842aba237cn/a Heodo
2022-05-25INV3ENzPemz.dlldll 44087a261fe29953689505faaeaed29e84e5bfd97f80ec6d4e4c82f56b39ce49n/a Heodo
2022-05-25xKzDF4MH8VnYAcKg6Ga.dlldll 7c89abda066a615ec9468f2b4714d28f0a8c1882b6fa0546fca579c5f5cc50b3n/a Heodo
2022-05-253DnGIm.dlldll 9549783d5fb46103834e588bcd776f2629b54fed73aad8d44de96f2727d87e8fn/a Heodo
2022-05-25OMb7XmfIZVmKf.dlldll ac46afbf455e92f5140d31789ab5c7b3638bb4a3b48e2ff5b5dce01c945d69bdn/a Heodo
2022-05-25xGYqCu1KBbqt.dlldll bf05611d8fe5e94fab69e560681e01669b54f52a1c46d0b6e23ed46ff1349530n/a Heodo
2022-05-25yZUOljOgVvvDeMP.dlldll 4883040535608367622fb09546c273a3d1ed5331233b9d9895fe291dfaa51a5an/a Heodo
2022-05-25ESLD.dlldll dd71c29c0deec6372aef1f0187c5e8a5ea976ac87c94d59b5cf3b9557bf0d9feVirustotal results 29.85% Heodo
2022-05-25SMMn1T5MzYArF4MtlmK.dlldll 3518c8155c998ac7b903c7e5bdee470ebb2e4ca42bda1e045693f2b0c2654f29n/a Heodo
2022-05-25Kj9cylH0je.dlldll dca1515e3538238d7dcbc360bc05fc4fafa596d0da954ae0e108bbcfe612db4en/a Heodo
2022-05-25Jvvz5KSZudvn9m.dlldll adbf601cc8cfc30aa6be577c5aec5121fc0ab8b56de53b5185e2db46a79c0675n/a Heodo
2022-05-252tT4.dlldll c583838ac520ca84e265cd2a3ff42f0e60fbd46e0b53747ec3f9e2633efc8103n/a Heodo
2022-05-25Zgddk00nUU.dlldll ba87613bfd400c4aa4a119231b59358c6534ed9b665ed716750640b324c12115n/a Heodo
2022-05-25xTd07lmqmGv5sHt2st.dlldll c3436b16f7ba57f3a1a454aeddf9290016b3ba807de94c84dadc57a4e0dadc89n/a Heodo
2022-05-25boyTtk3DLwfcZa.dlldll 6faf1553158a929ac7ecbfba7dd3eca878e912bda2234cbc6bfa7202b3ce48abn/a Heodo
2022-05-25gfvAKtLn7iiY44sYq.dlldll 7d5d3b9b6f00ffcda723ec7f7156d94d5f84ee321b3ba71e8f6950192fc35ca5n/aHeodo
2022-05-25wNy7995sv4R.dlldll 3f7c207686b3d58278ed156355aeaf1d0839364d14aa4abd734a9c69acbe22a3n/a Heodo