URLhaus Database

You are currently viewing the URLhaus database entry for http://cerdi.com/_derived/J4Fu7VmGZQ7rGA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2239268
URL: http://cerdi.com/_derived/J4Fu7VmGZQ7rGA/
URL Status:Offline
Host: cerdi.com
Date added:2022-06-15 15:42:05 UTC
Last online:2022-06-16 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-15 15:43:05 UTC to abuse{at}one[dot]com)
Takedown time:18 hours, 2 minutes Good (down since 2022-06-16 09:45:33 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-16iZdtNm0C.dlldll 9b0ab6d757f7778fe8db7c504fd560e2d5f79ddb65b97e03fda2f1133ea8e1c8n/a Heodo
2022-06-16z3Gyh6pmfG80rTEJJJ.dlldll 8b6e31761f6989ea4357ebc8cabc4f532802c8d682ca1cbbad51681a65a04dc7n/a Heodo
2022-06-16e10R0sc7kiUmCDDTI9PgYZ4as9vm.dlldll 43c276c2766ecc75557c16abee1ea0a6a5361cc0645669c3a44229c1e3979468n/a Heodo
2022-06-16r87mHHIZScR3DUo5s.dlldll c6c7fbfd366537d3db2fae2c5f1ab5362e7a642934beeb08cb2ceaeb30498fc5n/a Heodo
2022-06-16K8Xkj00Q.dlldll c2fdec644adca97efe79e6094c405d1e2a8234b74e3e54942bbf7f4b6b244f1bn/a Heodo
2022-06-164dmfa6Sg3rPq6.dlldll 4ec484c270c30d21b4e41568d61be81fa9594f045ffbbae5fe00cf304eae7379n/a Heodo
2022-06-16ieRVImrTI2RnbPXcKAnR7d.dlldll 221298995e570e0c0f6a40a5efb7ad4b8528e5c2d1a2cca24d781d7259c286adn/a Heodo
2022-06-16CxSuPagLMrtVxYumKyoiu30a.dlldll 6a3c514a5b5b01553b40bea32d52f49c1751ebeda51a74c8c4a1de3fb7c4885fn/a Heodo
2022-06-16z9a4yoL6tZH2HwjfnNRj46CaCCSJ2.dlldll fbb481f129583248b56872e50ae005fa550655ca64b635b33ecac254d21f2f9bn/a Heodo
2022-06-16xysqgxCkwTNTN5s.dlldll 1934c13d0332a22aadb93e9d462b235abc9724713b89a531ae284e408aa776edn/a Heodo
2022-06-16MGc3588kOi8oYV6.dlldll ad14279f351b9105995f0367bec4e1bf966ad9874821372ed500c54f5f1abbban/a Heodo
2022-06-16n4jkQZWtKszaQX.dlldll 433949a5896e578e0023995f1e888f3b3d46d5363f03b03e115ceb069bfc02fdn/a Heodo
2022-06-16FnEfti2ui6UPrC3ozBSkmiM.dlldll 8d55f5fef88fd1cb0afab6cf4f31b4de75cb9e2178dce491c484b52857b15359n/a Heodo
2022-06-16HyTppQPKJ.dlldll 2a1f99caac296678e31eb6423cfc0f1a6075653c9122e69cd3c0f502488a6902n/a Heodo
2022-06-16Y1qM75kOp0TLhQV4d0So1EdGH5Lpis4RoZ9.dlldll e1dc4e916a438339277d9cd8d2be8261140ef1a1fe35a2ac3c7a1bd8fcb72855n/a Heodo
2022-06-155n2HsWwTozMh0VDKBP5O.dlldll ad57ea3c94936e8c82e30ad9b037a2c966ffb373930c75ab4d4e8964f8293cd5n/a Heodo
2022-06-15SRpv0FhO965VtgPt.dlldll c87bf2c7ce5a2a70e53e545d989dcc6462ee3b0dfc790e21312698d77beca283n/a Heodo
2022-06-15GSegHLGosHDHom.dlldll f89cd83b03160b731ae16b324a249c40d963b517f886c0a64731bdb917583b4fn/a Heodo
2022-06-154nSzrmLCWdl.dlldll 025c62246c85c04378e26151c7836f9554203f9131e55f23894f8b3798848cdcn/a Heodo
2022-06-15ZD9vPv3ytswt0fkd.dlldll 1c3ed25aa4d53986afdd3ed6a8ca8ed1a27218c8246c545492627d77bfac26ben/a Heodo
2022-06-15hUAvkJKxg.dlldll fedc5002246c6fbc09b1134cb4b932b959b8f381846475db6d35459de87f7e64n/a Heodo
2022-06-15GWvRBJ.dlldll 22671dbf9d9baf3a13febd285150cdae0d0fd4435b74fa520920895f2490472an/a Heodo
2022-06-15ZPwfgnxUArnhjgw2d7cQmLgIj9VIkQJThYO.dlldll cab718c2dbc7af2895e73473d760725f16246716618c7e1aa8ad46571867ab68n/a Heodo
2022-06-15c2EvfCZxq4ZFcMqZQGQEY0T8BqZb.dlldll 297a6f51228d7fa30115a3725c6303520e07f6f835c0b346606449a39c065ae0Virustotal results 20.90% Heodo
2022-06-15Kb1WgXMa2nVBKQx.dlldll 483b09eb5a03877d1cc36cb3c3cac0a246333fd56fc2facb05439199c2b0677cn/a Heodo
2022-06-15EAp6O9J51o6S13oeBVSRJp.dlldll 0cf02239857cd54c124de069fd4731b00ea6c5a6365a0d98d7f3e3b2c66b17d3n/a Heodo
2022-06-15WKnrYimINeJ1MVG7NRUobMdqV4Y40eTAS.dlldll 9f8433a6f2f8a8b69255185e02ff0a8c30cfc7f937b9578f477d8720c4de3050n/a Heodo
2022-06-15UxsdBZ11GAgF5h.dlldll a7db11240d53f7d3de85f40aa6f4b91ac19ff7b18274c43e54bcca55d8efc9c9n/a Heodo
2022-06-15D1AaCNsojG.dlldll 1f33f4b8b7a5390afd38f453af4c8c98c57f7aacfea575605aa6eee08407234fn/a Heodo
2022-06-15t8RBsFH5Tr5zFuvTTOC3tvdcI.dlldll e4498f0e0bf61920ca3addf28b1de892f83677e06cae0a767e86d333c18bff95n/a Heodo
2022-06-15S7wBovAlg5dMl0.dlldll 39228427ca4fddeb0c1f27d260352b1985fe042287f90a6896f2fe891956dfffVirustotal results 19.40% Heodo
2022-06-1567HwpTwHblzpF0UQVHVJQ3nPGSS.dlldll 1b9bd2a0c06c14d0deb6d298f67ffb1be23d3b20b55c3d96030230b51153c47bn/aHeodo
2022-06-15H8MjIU.dlldll b20ccb42bbd0b77fc3f20e6de3e76b58a99ccd21db54b089bad220b1ab09e6a3n/aHeodo
2022-06-15POZd1JvxPCxssVdJQuj9X0fWi6g5O2eib.dlldll 1373a28ea2276f6ca065fb4fc4fd09a09b0ba78cf386c24dbc9944a1d1705a47n/a Heodo
2022-06-15lKvOlSVCU04FMRnqZlIMG9WfyMYhU3u.dlldll db2df69bba13c3cf9966a55bafe8d4c3588ebc52599db6de2a8188000fd2b8cen/a Heodo
2022-06-15fp7uDz.dlldll 2778a7eac9784ea2a35ce2e570e4f91bcdfce3e5d758060dedee3d08cc1d1473n/a Heodo
2022-06-15qshrL6HfUNlF4NojjrhkSFkf8sKA.dlldll 2452e70e9a04d41c30b205c88f86886a26ce67b4a9fca41ad225c00aecfa4091n/a Heodo
2022-06-158G5e7n04i7L4lFkBAwWIElaQgd22bQM7ZP.dlldll 0dc893576be7cd5259a4a94d4d634a8fa06c2ce168deb975709edc0780285e72n/a Heodo