URLhaus Database

You are currently viewing the URLhaus database entry for http://watersgroupglobal.com/cgi-bin/hwCu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2230898
URL: http://watersgroupglobal.com/cgi-bin/hwCu/
URL Status:Offline
Host: watersgroupglobal.com
Date added:2022-06-09 07:44:10 UTC
Last online:2022-08-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-09 07:45:11 UTC to abuse{at}networktransit[dot]net)
Takedown time:2 months, 15 days, 5 hours, 43 minutes Bad (down since 2022-08-23 13:28:59 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-09xN0wdip.dlldll e49e85f091b372054395f3df0f3da656c5ef30501b04c214cd0d1a12819e7459n/a Heodo
2022-06-09SjNNksmq.dlldll 09591982a0b5f82b72faadab1ff9ed3e62216875e5f5e7db9ef79b2d3ca32f6dn/a Heodo
2022-06-09K7UkPMeyZ.dlldll 0b8fdd0142834884fac03d33f8408c7ef1328f3dfc8e5d73187df09076627b7an/a Heodo
2022-06-09UbT27TwYZBsE.dlldll 4c83ef1603f60cbb39c672a7b8a27fe36e5ac22f6251f81b1413bc872f0181f8n/a Heodo
2022-06-09y6kCZ9.dlldll a328b30a3a93102487e8a8544f54e26b3751d384a578f5efc65267857a66abd0Virustotal results 9.38%Heodo
2022-06-09ExXBmji5DVM50W5Br.dlldll b97d46905680588af7a3c0e406787b86a9ec11dcae80d4b41b0caff6fc7a8b43n/a Heodo