URLhaus Database

You are currently viewing the URLhaus database entry for http://dusangerzicgera.com/App_Data/RiZCHA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2251483
URL: http://dusangerzicgera.com/App_Data/RiZCHA/
URL Status:Offline
Host: dusangerzicgera.com
Date added:2022-06-28 06:26:04 UTC
Last online:2022-06-28 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-28 06:27:16 UTC to abuse{at}oriontelekom[dot]rs)
Takedown time:1 hour, 15 minutes Good (down since 2022-06-28 07:42:51 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-28SSIs4aNUUCh0PdiOOXiGdDEvnMusgGl.dlldll 4dfdc33feaf6efd5855a629e256ce0a71af5aa64c9f1b9a5abc64fc0b0874f5bn/a Heodo
2022-06-28VPuAzOSMvLQ.dlldll 893515d5d5351b6be89bf3c6f2cff21004157956bbcf0a3c1fd6c473bb3a4a9fn/a Heodo
2022-06-28FPRInlSyJmDFt8KlGJO5t9F.dlldll c90a89600639066ac1d5d9a3e97ae4651bdc81cc0b23d0eaade61225cb18f3edn/a Heodo
2022-06-28rjjE9V1h1dohJQyxWMO6sPBWmITqY8r4U8.dlldll 90b190af282c714d2c0b53387eea3effa1df2b0f7bdf06f8028e88c4d1eb997dn/a Heodo
2022-06-28uL7USUKDItJWjtFoayZx7yMcn.dlldll e676cfdfb2cca699d23dbfc2641a463928d6d67b3b6b79a7d06fa7e1b21fe787Virustotal results 28.36% Heodo
2022-06-288kCUIj7.dlldll 5e39d7926b2705e9ac21a13abcefe38d48830e3e12309b1a7f162dcfc315831an/a Heodo