URLhaus Database

You are currently viewing the URLhaus database entry for https://anamafegarcia.es/css/VGBJhjpu19eCbq8gbYnA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2236879
URL: https://anamafegarcia.es/css/VGBJhjpu19eCbq8gbYnA/
URL Status:Offline
Host: anamafegarcia.es
Date added:2022-06-13 20:48:04 UTC
Last online:2022-06-14 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-13 20:49:06 UTC to abuse{at}diagonalhosting[dot]com)
Takedown time:13 hours, 58 minutes Good (down since 2022-06-14 10:47:56 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-14SqlTIyOutDdVIod2qG0l.dlldll f78ac98c6c2d5af1542c2516f26e6af6c0e186bca4a17592e8fb732a6dcf3af5Virustotal results 16.67%Heodo
2022-06-13cfeXPftziV.dlldll e8385e853408eb414c1744770b1f1584c7a34ffaaf08f857761b50f1ed806660n/aHeodo
2022-06-13noURQPdYU8iO4G9flsgk3kJZ.dlldll f48730d7a146e88edbafa3377bf487acd17d0fb3181b6522c0eb12e2aac58b1en/a Heodo
2022-06-13qdbZyG6c4OBwJnc6nbqk91UqphUJiC.dlldll f0cf5965f0cf1300d77610951d184cf8aaf23cfd1cd6e1477e304dbeb543936aVirustotal results 24.62% Heodo
2022-06-13Ys3JPSrvlewU8AHwewp87WK3WfuJfwI9kU.dlldll bfbbac190c36403140623e188ec13e221f6139b728c7f628b72d807113588d1cn/a Heodo