URLhaus Database

You are currently viewing the URLhaus database entry for http://void.by/wp-content/Z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2228440
URL: http://void.by/wp-content/Z/
URL Status:Offline
Host: void.by
Date added:2022-06-07 11:19:05 UTC
Last online:2023-01-21 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-07 11:20:16 UTC to tech{at}zbscloud[dot]com)
Takedown time:7 months, 17 days, 23 hours, 6 minutes Bad (down since 2023-01-21 10:26:32 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-07nWlE4tRQ2fVRVdn907ZbJkyLWd.dlldll de124f0b4e1724da297fe9d448975c940f1466b7e39408626d1fbc171ce3d5e7n/a Heodo
2022-06-07WHAvvXwEMqeBETg8w0889LHyQkuckbBG42.dlldll 1ac06d7daa5e777c1805c7d1c5a6bf98f42acdbd8a71ba9e724353f7ba338450n/a Heodo
2022-06-07s7wRyzY2jbkGGMZnSQknLPmGWjdPV.dlldll 31c3a555ebe4b4952bb31bd39510e0f92485421fb3946bca8bf7f132ed98ff11n/a Heodo
2022-06-076fYcHWQXseMxUrWVPh.dlldll c1ec07e3c37219b1016c636e9552024f9e946a662089bed270199f7039f92e8cVirustotal results 13.43% Heodo
2022-06-07ttuKFg3Tx8qd2s4GuQcRw.dlldll 6b4b94e73fffb31204f6bc50e25bd767ec8853d96ad9ef448839c232698fcbc2n/a Heodo
2022-06-07qFnJb3m4T48cmmQtKE.dlldll ce0505134d4713cde48432c1d52e8febc48a0b409c5b95d91a827eb9e3686ff2n/a Heodo
2022-06-07ftVjE1OgmERcb4CNz1SaaK2FtNxKQWL1.dlldll 599443e7e99723b84fa8b162b826b81a5583c3c20c1debad0bbf7cd7e402a1efVirustotal results 11.94%Heodo
2022-06-07DlQTYnCw07RiVtHdZF1.dlldll 26b75615642270ee17df3f733f7b774f2b3780a1534da1aa01e2407f37661b93n/a Heodo
2022-06-075BN9Qo9EI7GXKyLZvF8Qxtqc76f0foM.dlldll 3755407912d3984abef7f317af9d0a1052cd7209315dc7240e28e3c15b4d57f1n/a Heodo