URLhaus Database

You are currently viewing the URLhaus database entry for https://zktecovn.com/wp-admin/xxfnYY4zwOpFOgu3g1t/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2229486
URL: https://zktecovn.com/wp-admin/xxfnYY4zwOpFOgu3g1t/
URL Status:Offline
Host: zktecovn.com
Date added:2022-06-08 06:35:09 UTC
Last online:2022-06-09 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-08 06:36:18 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:19 hours, 52 minutes Good (down since 2022-06-09 02:29:08 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-09xHspcpjODkMnlWCg.dlldll 63a7b30f82ed473b0a813fe545c8341c25779947a4293ba9c605fdb434ab6826n/a Heodo
2022-06-09VvvuFRbSYZFvP2LxAciAjKXAonQGYOtv.dlldll 37511a8f1e34e6d32c83b8e95bd25e801087c580974ec34c5d9c0a60a53c59bdn/a Heodo
2022-06-092XJEiCHUEC7qZsXmHPXsB7PNVbpA7.dlldll 1f5a845a759c13f94625228c3ff516b420cbc3f6cd524c8cf7ca5004c11ab069n/a Heodo
2022-06-09yYYIiXnNY.dlldll 0e8938dcd44e137a94ad48ec1f6324e7994b84fa4e1cc57eba217119339b2757n/a Heodo
2022-06-09o7aSsQr4gWqZMxQk1L.dlldll c823770683b1f8971d15dc93e5d81ff22678000c2597c8aa504b41980790d295n/a Heodo
2022-06-096eQaCcQ4z.dlldll 4ff54bb41f568a9ecc200b99b49bb98b81b2ae1618425606a15d81911ee048ebn/a Heodo
2022-06-09VSGfnG7LF8PInZr6nJp9Pr3Hft6.dlldll 6e84d4c27256e2a137ca3102489a93af6830525457daa27815632917e4925301n/a Heodo
2022-06-09U3tix9k35psi0ujPj6q0sEnIPNXR.dlldll bacde2d4b43423552d67d1785f08c384455f67a9f073c22157de085deddd6bacn/a Heodo
2022-06-082YCzxyqTqUhbdmCWkJu7.dlldll 4ad05cad1ea5a9f11c55417cdd0c0bd970803102851be242df40248809dd9ab2n/a Heodo
2022-06-08AT8KQBOL5iUG4srN7Z027qKjcSVkLu.dlldll 8747e30f5219138d072614f4fcf4c180d17bd02fac2912c4e697d6e3aad45040n/a Heodo
2022-06-08NeQJLm3th79eBgvE6TWxj7HnH.dlldll 11af2f03f30e22bed5642c95d15469be3e7292969f66c7ff306e3a78f1fb3eeen/a Heodo
2022-06-08VzTZEsj8p9rNElQ3.dlldll 4c53176a69d037e5bf85afa164741a2ac450b466a6ab10242fe6f623e2a1865fn/a Heodo
2022-06-08CmJEd1I7c1tQLVZjJPAQXAPVp.dlldll c4316e0958ceecca5fbbaf6265f454278b2c7e90f6b7745959bb90be12e221e5n/a Heodo
2022-06-08Gi0k3g1v8sTRMl.dlldll c10ec868edc96fbea50186b92aa56cc68488f90d2243585ca538793f05e00424n/a Heodo
2022-06-08lKC5Q7nO.dlldll 5252ec7cc5d1271d138c7b193e3e510b8c20c1928c6489afb953ceda6641b776n/a Heodo
2022-06-08agaAc1Lqujq8Txmt4CGsrOYq4B3.dlldll f79c698fcdd9708cf9548ec0e54e122cc92a2e10346ba83ce69cb7190a2c4c06n/a Heodo
2022-06-087ZzPxJppv9ghyjwe3GO.dlldll ba8a401cd8dc1d9142c130d643e230daa43e60c9f5366f343724f0189ee38576n/a Heodo
2022-06-08eMnviHYL44.dlldll e92afedca52680ab4174aaef1cfe039a0e32fc71e82a7749642d2794a1e2cde0n/a Heodo
2022-06-089UEzjBR4xL0wIV.dlldll 4f09c71e022642808a5a7bbb6273459c580d6b1c5c27401b91072ffb5b0337e8n/a Heodo
2022-06-08xrdNRXDKRMJAEPA0gep6Oka3FLRIAulfxnr.dlldll 2547be84e154a03e2e23edda04971166e30e236471c3862aca4d589791e161e6n/a Heodo
2022-06-087RBEooL8ZrfIgcHXGp75JgL7PZJNaO0TxgQ.dlldll 7880a452889505d62ec8acd3ce3202048efb10c838db59a51b96c598fe197ad9n/a Heodo
2022-06-08pKNRTTbSS7Yt3Dn5liFn7Wkuh6nCwBJ.dlldll cd3394dd4ff3fe7ef0cac8063496d135fcc72c925147f71977b69c58416b3d8an/a Heodo
2022-06-089T9YuZEBmKbgiZf.dlldll dd14a47bdd2276944bc50e70739425fe7251446b3a2a12f6665aae64f77ae3d8n/a Heodo
2022-06-08isLEkLPPT.dlldll 96c91e6e18c0388859a80e433bea740558c191f186ed9700436fa24210e9ad76n/a Heodo
2022-06-089JXbY5ZTFrh.dlldll 82dd4163e9f882400d33a9fc72f52a178c1e8948fe36d8e4c20db02e1c5fa149n/a Heodo
2022-06-08e28O7yxlVyH8ZYKLU66.dlldll 5267f995f723b71a35f91413460e54989130fe45934365565cb2d7b2598e31c0n/a Heodo
2022-06-08wcoin57gS8.dlldll 0d22eb62b0f2b8cd5ea0d93c84cd2dc45d6df4a33decc65c581cea4a65e1ce27n/a Heodo
2022-06-08ACCp4y9I77V16.dlldll 5af10b94720ac2d6842660807cf50d5a3e6896bd025e7e5d14989abaf53dd5d1n/a Heodo
2022-06-08nvBGeacjhHqhswSV1QwJNNU3o.dlldll 28ed91654140c2e7737b48d457d6e393a43adf151a0f103b8c6087c49471c838n/a Heodo
2022-06-08DGQ4yV.dlldll f22113116574a2b01cabd1504ac3fd24efa8a64dc169666545c53dfd5d3ce38cVirustotal results 6.15% Heodo
2022-06-08YSJr2QfuTCA.dlldll 661840d2eeb7e34db3e9fb5c3018c9c78d185111503852bf57b2e5fca5ff481dn/a Heodo
2022-06-084AbQTE1cT09GZoXsslojARGprC0WBlTT.dlldll a17122bfbf095dedcd453954481ec168f91eeb1d8001595f2a0434c90a7f2b11n/a Heodo
2022-06-08KKSjbh.dlldll 8686be0ccfdfe56b5236d9a3cb934c84401b61810357a430a2c43a8caa1430f3n/a Heodo
2022-06-08BGsL90jiGKtHsClBN.dlldll 20791627cb498565da90e492a514820616d1ff6ec2d0bb3853a81ec8cc21700cn/a Heodo
2022-06-08T7QHaVDTkNTatYeT.dlldll cf97f520288b9f20c12beed327fd302a9501fef8125558ca624979f9ed853bc0Virustotal results 19.70%Heodo
2022-06-080KrR0MuZFhJLvwxPz0e.dlldll a5b62418957616fdec4444481654e4ab8987b3754b16e435527b66ff9c24013bn/a Heodo
2022-06-08mfpWn8NiGcbQkYtNgC62yFnyhK.dlldll a11e2f533a0e42baac432048bfe92b7ad2e9d38f3af24f202bc4236f508f4b3en/a Heodo
2022-06-08K7zPqwVzbhv9plEPORTdO8lD6leHU5Pc.dlldll 2bcde55c833e1ab602c0cefe3758ca036e739f269e1ecd6a412dc862ac3d7499Virustotal results 19.70% Heodo
2022-06-08XlXYL1lB7fwI1pgIlOQx.dlldll 9e47b604311ccf1a4b61da5789a4701592494b668ca1c0bcd12a4a97ca128c5cVirustotal results 18.18% Heodo
2022-06-08nyliZzQDRvLvyfK2PE288xuZXSS.dlldll f069556d54de6419d33feb78289a52844e23e146ad13a3a9a430ffff9fe336cbn/a Heodo
2022-06-08FDfMsRgI6bGr.dlldll febd173dec63e06f7c9eeb538b427bc43f8c2bb237b877d7af75e51bd629f13cn/a Heodo
2022-06-08rY8VV0sTAPemB3.dlldll 57dc80aa8f5ba4a2c1c5a2a69777b6581e03c375d87a2ed30307018184bfdf51n/a Heodo
2022-06-08XGGTSQ.dlldll 60b48f5180069b9453d6a617ad3c3e019120fb640b20595bee6942e900aac511n/a Heodo
2022-06-083M7uZjbKU0j.dlldll 0fcdce066024c342904848c6f4e684935b887fd97e0ee870472f8dd843ccb533n/a Heodo
2022-06-08fPENFznArrRSftHFSyNzwcPah.dlldll ab702b68afaf9325ae753a74d2946b2bc707fe00e260152b36534bd8fd3b1552n/a Heodo
2022-06-08uOTIiEqVwXzBx8gE4OxFM2lJvUN.dlldll 8c3900b5f6fe23c31a228d583d4bfa4ced5ab9e3bb59569d9ab2c14d8895b475n/a Heodo
2022-06-08VN3KBdJ0YatZ.dlldll 2487f1cd452f7028094c8bee6e4a2f46edeb0817ce4b5b08d7cddb4a7785cd91Virustotal results 13.33% Heodo
2022-06-08FKg3z8o.dlldll be40e6a9d8b0098566a1d810588f4c19dd47c6e732a845c6c789e16f5feb2968n/a Heodo
2022-06-0883UoI2ywT1ej3vmBZg0yauivBXdLn.dlldll 2c2456f353f4d3aa01c9e3def4e22136c41765628ebce52d985be1072df0f8e9n/aHeodo
2022-06-08itksoCbq9zxoHKbX.dlldll f20e2ef8fc007d78462a803ec87f422a32b25df3abf57ec887cacbfe163d7e6fn/a Heodo
2022-06-089pYdueGO2psws4ORnvJ.dlldll 11c3c4e8fdc63b0eba95c8c7e70fc1e5107e0f6cb2901facb8b9e3016a0ee4afn/a Heodo
2022-06-08gz8B5oklEuuGn0h0B1gOCWvI2.dlldll daef50b35308e4e3641667c306284d53455eb24de7d1247c6f02be62db8edc1fVirustotal results 18.18%Heodo
2022-06-08WWljVnx8WSjNIp7.dlldll 2cef48458d49ea9837133b6415e64defb7aa810f8bb7adad0033810273070f7an/a Heodo
2022-06-08hCqksRS.dlldll e633048471fce349dcd6709ffa053f295c0cbae7d2b8c27b1190a156a448ffc7n/a Heodo
2022-06-086G3uRUPWb.dlldll b2925202d37a4eb966a20bd4e253c09945a07ae73d7056776357102ef7a29514n/a Heodo