URLhaus Database

You are currently viewing the URLhaus database entry for http://laimesnamai.lt/Vaizdo/4Bxi5DPnmWoyixh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2229812
URL: http://laimesnamai.lt/Vaizdo/4Bxi5DPnmWoyixh/
URL Status:Offline
Host: laimesnamai.lt
Date added:2022-06-08 12:49:04 UTC
Last online:2022-06-09 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-08 12:50:08 UTC to cert{at}litnet[dot]lt)
Takedown time:1 day, 6 hours, 1 minutes Poor (down since 2022-06-09 18:51:58 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-08QZIKd4.dlldll 1d3ecf4e467f725bc8f9f9ca242ef90387d112129d7d6d73634242b05b0e0b41n/a Heodo
2022-06-083vZnxYCOCdFdo3xp2KxGD1RaGu1G94.dlldll bb74f6fd51586f7757c7a61ee53911b459546e5c28cd5c40fb6135b85ffb915bn/a Heodo
2022-06-08pc5gczhu3ad74f9b.dlldll 122e926b83758d8ea28a694dce573f0ceb3ca53cc96dc82443892bd28ffc7d5bn/a Heodo
2022-06-08Cw47KQhqRfsMNUVecZKbzC8AQ2Y.dlldll 56cb7f739ddbe714dce0546a2132715baa9f0d902ba7fecc614dfbfb73645c93n/a Heodo
2022-06-08rn2ghAyNEGghzLkmIjvhiTOs67X0f.dlldll dcabf46156d36029be0153f7095356f7503ff07fd582c583ce6335ead371056bn/a Heodo
2022-06-08moP8I0PqVjY7iJ1acIGG5.dlldll ac84e54836942f31e559ee0682c3e1e0066e8b4a6fc819fd51eaf1627fc01ed5n/a Heodo
2022-06-081uQ1NCJvB8nMQBDaUSoX.dlldll 9458e1011e5ed7f337866660d2fb61bebee1ce8611d660a4e175e4fd44293a34n/a Heodo
2022-06-084nh2And9b57egZ0TcmkwOPNZnCBQSt2.dlldll 61892d3ff1375e5459e07150a504c79af2423a389a9301a4d36679ed36b7658an/a Heodo
2022-06-080RkP6ofPboeC20fNybEhI9FhKw5.dlldll 6eb58d5482db60cde32b26808d0bff2691f51e37af82f8638ca8e87131c2c08bVirustotal results 19.70%Heodo
2022-06-08kUVDEYW5PWtXkF.dlldll b5d0e5610e7db8590efae1210e8781061dd0419a56da6bca7078aad6bc610b11n/a Heodo