URLhaus Database

You are currently viewing the URLhaus database entry for http://woolloomooloo.nl/cgi-bin/zIdwNC2d/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2236449
URL: http://woolloomooloo.nl/cgi-bin/zIdwNC2d/
URL Status:Offline
Host: woolloomooloo.nl
Date added:2022-06-13 12:50:07 UTC
Last online:2022-06-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-13 12:51:13 UTC to abuse{at}versio[dot]nl)
Takedown time:18 hours, 46 minutes Good (down since 2022-06-14 07:37:21 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-13dXLOb9oARl.dlldll e8385e853408eb414c1744770b1f1584c7a34ffaaf08f857761b50f1ed806660n/aHeodo
2022-06-13NhUJtRjIzz.dlldll f61f7a4daf81a8c3bb7c37d9c256dc4c73953485ab9dd7235adb9ab66ac3367en/a Heodo
2022-06-138xWyKsHBzq7ddXh2.dlldll 18774ef497e0e57b0aee51fd247701e4da29498a2bffc863b9cbd8a6f7e0d8c6n/a Heodo
2022-06-13XTExJTWcbu8EYKl08yLM.dlldll 6256a0568d780d8e81e0058e8b3af14e4bb0297b164f8badc60d3166aa311ce3n/a Heodo
2022-06-13l6HveR9W7tvaEGJw40xnmM6YJ2Qe5.dlldll cbf179604f881912e03460a9a05347441ec46b9976a3babd4af74238815639fen/a Heodo
2022-06-13LbbRuQsoEygcR67vYb7SwmRV9ienqFyN.dlldll a78bc0994d85498df3030dfb518168906313bcecf98daa95b0684e7203c57bd1n/a Heodo
2022-06-13EiP9nFRty9.dlldll 2fac4b741654fa36ce1d60ae9b3b8990f9a3547804411c882f51194bfd09d8b9n/a Heodo
2022-06-13EGmss9zuJaIFi56LdiR4iolw0o3QArbHOHc.dlldll 31caa575ca4ecf2c10b5c0f7bac62cea22326e3e232af02ff4310d32fcf0e1d1n/a Heodo
2022-06-13Fk4FHm6u5OeBTpR42DXR6QbuWW.dlldll fe454b87a43f94a7469f6a2a73defc8e0e38c93d42cfe7bf3a9c77efd34dd675n/a Heodo
2022-06-138k5xl8UsvNfWmxxX9EhH08pAmdHr6uN.dlldll 289ee2646992fa2aede803fff84b3b3f8c878483e0744b9b8ba3459669fb01f2n/a Heodo
2022-06-13yJxXTQI4DhFCeP.dlldll 02c480aa758dbead3c4a42671cd8ed387bc244dee6e8b9e72dfe969067190140n/a Heodo
2022-06-13k1B8gALJ.dlldll 57330f3c8a8498cef83603d716eb361c21d1a482e23a5acf80a032bb38c0d639n/a Heodo
2022-06-131B7pWkc5B8.dlldll 55a5ff57efc180a49b5f9095c1ffde3d270a9cf0b09621e09cdfb64990bcdcf8n/a Heodo
2022-06-13aCID7q.dlldll a5a88c5c7acbfdfee69fe777be550c9b69d7bf7d170140da29e6973bb0d07e8dn/a Heodo
2022-06-13e8sqZM3huzY6l89CjJRom8AeWKJzBDO1p.dlldll 2a5af06c3dfca89c39a966a8c5db8cf9b5699789d09661e9b10d9558afe941bdn/a Heodo
2022-06-136KB51iLM7tjjSS565m6vevfSj1HLc.dlldll d61073bffad21126631ba60eef9552dfe0655e160762a787c55a809130f0c9a7n/a Heodo
2022-06-133Hj7TcMyOff.dlldll 9c5ba92453662c6d2e680ec92704f40d57072742306a060f710a53a21d3156a0n/a Heodo
2022-06-13JTsRCw2eshlz1VnQ.dlldll f30369ead5e98f85ce2ac94a7c7a13f35891948124584d7adb187528b3797d93n/a Heodo
2022-06-13u2lw2M8rFwKTeeuPoIKJ3uIs92t.dlldll cf3615541a1938b548a89e4e346e0be8a9cf741436c5436a83b4958f8d8188b8n/a Heodo
2022-06-13OcnxCSQpp3c.dlldll dd7dd62debf55235996a6db4db27bc59b9753dde493e92a89db525c2bda5d095n/a Heodo
2022-06-1399jrRZ2SD8Sb8pD0pFU5Kv4a90Q3A.dlldll 60f467c8c4b4e8be5be873bad138743a7ef7084c9dfb44de0a745d4594326d96n/a Heodo
2022-06-13P1SSNixUUqYsZkCglMiuERg.dlldll 84969b5f1f5d2fb4be0cb816622ddd2736ddd38a5a7f170c6d8123c9dc1d3a52n/a Heodo
2022-06-13cYbtXSxREzwM.dlldll 585815d36c6a2bc0b59f37198456180eff7da6ce9ee107a8dbe3024a00b74c53n/a Heodo
2022-06-13oGMHs8qYZ4bBVBDiBmP7.dlldll eb1f9c363ff418eff6377ee5c3b2a5980ea4212d45f56bdb81914c094c1f698an/a Heodo
2022-06-13v7QNgTD36J8.dlldll 99690868ff1b540c39b30f385d13860d87055e097692d8d97378d7a969a61fcfn/aHeodo
2022-06-13x6s68N0lZe4T8D5CA.dlldll e46761511fb671039cd1167db9e092a4f4f5be4e675cc06944d1973b2d730f1en/a Heodo
2022-06-13ab1bLBF4PRjybYbqNuRdEblJvc.dlldll 844d3c170ab244120dce6cdfc3570b45b1c081cda44b1cacc49ae6d787fa3f0eVirustotal results 22.39%Heodo
2022-06-13QmAcFx.dlldll dd32088ec6f7cef98317963f12dddda86c1727af8a5d73768f6c2f18986e4930n/a Heodo
2022-06-1332W47Asttvjs9SqPptu.dlldll de611d09cbc7846c704d596cfd0cff5f45e5bb2c33285a6a23dc7db51e7ff019n/a Heodo
2022-06-13KTk0zBgMlf.dlldll fa161bed7871b4b931c6a8f6e50e0491e357f105fd133c9797b3f3f2d27f8538n/a Heodo