URLhaus Database

You are currently viewing the URLhaus database entry for http://wordpress.agrupem.com/wp-admin/jimjzu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2231594
URL: http://wordpress.agrupem.com/wp-admin/jimjzu/
URL Status:Offline
Host: wordpress.agrupem.com
Date added:2022-06-09 12:26:05 UTC
Last online:2022-06-09 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-09 12:27:10 UTC to abuse{at}strato[dot]de)
Takedown time:8 hours, 57 minutes Good (down since 2022-06-09 21:24:19 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-09DmUxQiZXUI388Vm.dlldll e1751aac72693d76bd04358b00a436702392c4a9f909e03291fc6c4fe9d8ea7en/a Heodo
2022-06-09Q2RnqF04.dlldll 22d39e5b96d97ca36ab44d317d48d0a984c384318c0af0e11a97c614f717fb94n/a Heodo
2022-06-09PovtrqiS4dYk.dlldll dcb25bae8480a140b720bdcbb254722e3c317470cfe4ed3eb9f2b435d6f038cdn/a Heodo
2022-06-09WEhihJMy7oAR.dlldll 834d5848c6fe36af0df58a1063613607b2cbb247ebcfa9ff97b8d512bdeefebbn/a Heodo
2022-06-09rmjnjDw1.dlldll 07e87fd028a23cfc0c27815606f26c1ec4eb53ad6953abd35130c97803ca830fn/a Heodo
2022-06-09WjguCSAzWtS7FJvS.dlldll 8a03f41b87e24cc290abe833803d3096e2cf78a9bb8a8aa7f0d4734313333cd2n/a Heodo
2022-06-09nCSSVA.dlldll efc335f6678fae2bb53a39735edfe35e4b8e274d655521edbc5b1de82fe3a70fn/a Heodo
2022-06-09K6a.dlldll f3e945c7a277758afcd3d089165299307f1c4c10410d4c7a022c29d57803af7dn/a Heodo
2022-06-095cw6k2u1fyf.dlldll c496b8a89450a17a02e4461f50387166605b376be92c3718d6505f0224ca55ddn/a Heodo
2022-06-098hAxYXW4.dlldll 1a0eb63e548b6f6a23dfc68b269d8fe7396e9c4e2c0dff48e1447495b9e8d9bdn/a Heodo
2022-06-09HHlQIuoOf.dlldll 5093032a2c978918028b78d6c83df9f6929080e92caf0978b7cc9451b03c02dfn/a Heodo
2022-06-09ZIOc.dlldll 6dfcf15800fc5aaf387fa3f6a6a6d64cf10bde6ce96461f7272f1beb17cd5421n/a Heodo
2022-06-09VE2H.dlldll 99fe1f1140cba50f9f63e0d7fb44e693ddf9736dce921434a62329e12a9b23adn/a Heodo
2022-06-09CwQqMCAVbW1P.dlldll 49039d7bf934e41af23527e8c2e7277de6ab568854fcc32a0137b4b75b90b0aen/a Heodo
2022-06-09IuHZbE.dlldll 3a6acf95cb8a011f39c4915e158585be264faff01cb8d773328ed723d0c5d1afn/a Heodo
2022-06-09hpd2Kru8IZWp.dlldll 2bcca7ec292da54b4735cf097ea0264e95209e9ce173e6ea50d1d032a7acac0fn/a Heodo
2022-06-09mcwfwwiWBW9hI.dlldll 1dc882a248a7145030f85b14b154fc63c03334f09f1894acf63102380d38c9d9n/a Heodo
2022-06-09IpLuIrJ2kngcc7BgQa1.dlldll f288109b85a0a9cbb0a9533bd5e91171312741ed57db537140ad3aa1b7d682edn/a Heodo
2022-06-09uZkPgzBcSUDnguQZ9.dlldll 2310dbb2583e0e37f29a2795c5f28016b0751036f9621b852918cf6fc4a075f2n/a Heodo
2022-06-09BMGR2JWm.dlldll 5f6173072bf8c064adfe04ae89f0d5ad703faa30646d7debd2cc3d972678d4fbn/a Heodo
2022-06-09fh3olTCdfX.dlldll 525c8c87ff536a7c07aa0e0985995b3d541c7661431fb4748095c12f3f19e6cbn/a Heodo
2022-06-09Ekh4AtFW.dlldll 0e86e3c5bb5d1dc3ecbb5834f56aa5d63ad478743ee816492a5bfdb26788ae38n/aHeodo
2022-06-09x6nNszA30RhFD.dlldll e78ec94b40b6e30cbcd4b62efa8abe6c0f4fee2715a41cf6d30aba929956ba75n/a Heodo
2022-06-09y1IYUgUK.dlldll cafa20ee442781574083a6846299daad641ade842e5ba01f77036ad872e1237cn/a Heodo
2022-06-09nkJ.dlldll 501f0d399054b746522f5d01266dbecedc3f0b0793d6cf820d690ab098160cb3Virustotal results 10.61%Heodo
2022-06-09XhbnOLik.dlldll 8fe83c2df7a686845e7a388a2afdcc413dff36f12ea81136ae696d1d412d6d3dn/a Heodo
2022-06-09XtTOqJDhLy6ilPKaUz6.dlldll 005ddf8c90f438223d5f60a58bdea391e9f4a0e7ccbe6ade64fd6c53f0da48d1n/a Heodo
2022-06-09Xaxcib5hhwp.dlldll 6ea01baeaa431b3a8c1aab488d103b14a95bc73d4ff4dc7b27b41eb381215439n/a Heodo
2022-06-09VI4OQClacPU2b.dlldll af9a80ed2701d16d0b411e782a9ce58e9af1cf5b8ea7f621322435b5cf12500cn/a Heodo