URLhaus Database

You are currently viewing the URLhaus database entry for https://www.comhina.us/wp-admin/BqXXttOa3XLjg1u/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2251355
URL: https://www.comhina.us/wp-admin/BqXXttOa3XLjg1u/
URL Status:Offline
Host: www.comhina.us
Date added:2022-06-27 20:13:17 UTC
Last online:2022-07-05 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-27 20:14:09 UTC to abuse{at}webhosting[dot]net)
Takedown time:8 days, 0 hours, 47 minutes Bad (down since 2022-07-05 21:01:56 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-27GwhyZlsXmMNLXxCb.dlldll 3d97c4fde7c8566c062caabd41b9f3f9be1a6adfa8739ef13b5950c66eef9245n/aHeodo
2022-06-27B2pOG0ttapC12bAI.dlldll 4eaf772b2393a1b5c66cb11ee03d7df6984b08eea6abf1a6030a42d776c9f9c7n/a Heodo
2022-06-270gJw.dlldll 665ac856de677d162368a50020c2f1c272409d8dff90c36e0b1ad2e033f60119n/a Heodo
2022-06-27ljHLokhzCnRE1HYyf.dlldll 80e1fd56cd2e27de15df677c60cb2fe01a409aa6443c1afbdfa9fb5133c4e25fn/a Heodo
2022-06-27EKhL41Q7yhQCZQ.dlldll f818efdeda8fa4bf1845950a19b187b4daeeee285c4c83a60370db304ead3eden/a Heodo
2022-06-27Rp7j3exG0AUyKZ3.dlldll 2e9024fbdb748c5b5e24f27aa7173a0b1ff94fd681b1174a45c7e7a348e52c3dn/a Heodo
2022-06-27yh20.dlldll a5ede26c5a8d7fa8accbf5ae125e359795e29d8081561fa253ecef7966a055fbn/a Heodo
2022-06-27Ol5.dlldll b0cdb4f9355de6b26cccfd761a43ab7b05f7a5bcff1385197fb046a6892c084cn/a Heodo
2022-06-270IRbp0KlNg01m.dlldll 36549ad76265d6c93dced845fbd935aa7b5d0738b3ef4f72632d6f55d0029c6en/a Heodo
2022-06-27dsQ.dlldll 70d5f578f69e4d17d87db2bf9bbb5a4774d12a01c49d80d7b6120599b76335f3n/a Heodo
2022-06-27y27kzxFqsT9kqbw.dlldll 2fb21a3d0e701a51391eae24c7227236700de14fc8c5d345c1bbdc651c3ec653n/a Heodo
2022-06-270X9BM8Ua008Hbg9wOw.dlldll edc26edf9ad445b59f3968ed5144b3c469e9276fce46d9195df67e430932f880n/a Heodo
2022-06-27xW1cghDG.dlldll ce7450be81daad07d0802c99ab778a465840e689b527b9d5dc0f7b049da225bbn/a Heodo
2022-06-27CaGPWm78Jfi.dlldll dfdf1cf7ee1d677a5ebeedd910a6d345c656f000cedb828bd89ccdac9ba80d54n/a Heodo
2022-06-276oOMCBz9.dlldll cb369a73e8032697f062cb140de44a83a706087a42a3f9c5705cc502ba7952bcVirustotal results 18.46%Heodo
2022-06-279rHWEmN33HnwpJSO.dlldll 3536479d976fca2a1f37035806b1824780ee13daa89e09ee1d6721a34c9936e2n/a Heodo
2022-06-27G03IqPmaSC.dlldll 8408e76c8933a7aca6006c544db383b706ca67909b55a5e92da1614819a0a550n/a Heodo