URLhaus Database

You are currently viewing the URLhaus database entry for http://cannipius.nl/cgi-bin/TgPA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2239951
URL: http://cannipius.nl/cgi-bin/TgPA/
URL Status:Offline
Host: cannipius.nl
Date added:2022-06-16 05:21:14 UTC
Last online:2022-06-16 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-16 05:22:18 UTC to abuse{at}worldstream[dot]nl)
Takedown time:3 hours, 37 minutes Good (down since 2022-06-16 09:00:07 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-16DH5Y0QiAWM02eoxK9ar.dlldll 4461523aa45da493549d4752fe2a5cf2e52bb141651b0bfb6f334c60fe5f505dn/a Heodo
2022-06-16SdXRxrdZHxf.dlldll aed1ef8b7e9e76dc41902f3199cb3f8c42afb291f9c73eafea8ab215f239dccdVirustotal results 16.67% Heodo
2022-06-169ehupqgMDsEUrqvXYJdZMP8TRYzPcK.dlldll 2a60e72c546df34153e2ebc31b96e72e8195caff0e52414700cf8c707e355cb6n/a Heodo
2022-06-16lLw7otqGFAUXhfpvheDK.dlldll 77c3f30946330b81c0a740ebddcd4b05c4f2f6cdf1a84ae53cd7222968f7765cVirustotal results 15.15%Heodo
2022-06-1610mubkUw0y.dlldll 2b5ff1e993c19b849107a6b6f670e5f1f16f5e0bef4813f7ef7c30194fdc06afn/a Heodo
2022-06-16SKvrO6ptt2eUteA51.dlldll 5a23d22c660385dbf89c4f30e268f8d6c636dc8af54a40a1efe699b4f68ff1b2n/a Heodo
2022-06-16Hyc6yiEfzDgw1v5HD6WBbwF0tSzvmEx.dlldll 518b0128d1b65a5b188925e4ddf4c78a00c3a9c60c03ef39f9225b04d7ec2038n/a Heodo
2022-06-16aJT7tE264ZJv.dlldll 212870f35e33c36b2293eb58fa2800c27b5eb1b7863355a9fb44970d4acbefcan/a Heodo
2022-06-16RJR36FS3AtmH6BEXmFrAIaUr4Vsrl5ZRI.dlldll fecf94b430e34277f6298962a014eeb2915ce8b06c940748055c76b583b879f3Virustotal results 16.67%Heodo
2022-06-16DQYYLTPES5shHDvANMdKI.dlldll 54ed6001d41c79847dabf0213dd848635351b8a8b0b47e6de592853987518c80n/a Heodo
2022-06-16pasKKvttu63iTUadlDNTxObJUtC.dlldll e91a8b8190577e798001790f3696dda2423b3a3065813aef5994679f88287fc5n/a Heodo
2022-06-16PPoR7lVIOoY37gK68X0KU7Ab41MDM.dlldll a379feb3c98204a4462d687736679a334e85c629aeeefeac17b21645fb86e9d5n/a Heodo