URLhaus Database

You are currently viewing the URLhaus database entry for https://aesiafrique.com/azerty/Xiuf0wUfv1yl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2237665
URL: https://aesiafrique.com/azerty/Xiuf0wUfv1yl/
URL Status:Offline
Host: aesiafrique.com
Date added:2022-06-14 11:19:05 UTC
Last online:2022-06-14 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-14 17:33:07 UTC to abuse{at}lws[dot]fr)
Takedown time:7 hours, 52 minutes Good (down since 2022-06-14 19:12:10 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-14gpy.dlldll 8d5fdc1348706b1221518c65263eef19f884af328127d76091340ff70cde195cVirustotal results 19.40% Heodo
2022-06-14xNCB.dlldll 89dac591e75cee145005fd1de3a14e53450182e42323b5618e2e34787cd8bf16n/a Heodo
2022-06-14e9vpae6ieAuZBytiE8V.dlldll ca20144c61067213610f5f48d3f0dcd26c192b2d11a90fe54f6269d7eb81411en/a Heodo
2022-06-14mDDPyVQNus1I.dlldll b0f8d33be0960fd67dad1c14e890913b10a491d65f72a9ed3052692d071f2fe1n/a Heodo
2022-06-14WAAh.dlldll 78963d52c02036da54b8eb0120ea7a97ebf34b3b3e39d99ad1346f16632d6a6an/a Heodo
2022-06-14G0RDZj7MYCuJyPoPpqn.dlldll e22de498009998170927f8d8efa25fdd4a64afaccd7d62c144f1ab481455b73dn/aHeodo
2022-06-14bCZcrTdAezA84of.dlldll cab5575483f78702460156cdc60d2e4a3981e868625bd27cdacc8f4d683ac83fn/a Heodo
2022-06-14hkkmh.dlldll a84f0d50f56e19974463c2f114f8264e9471cb3f40ae5b92de0e79676e9e552an/a Heodo
2022-06-14vxQp7.dlldll d663f2deaac027d7a24ccc3c22ea5231de5b2b7154b34eea7edfd7b5eb439a1bVirustotal results 32.84%Heodo