URLhaus Database

You are currently viewing the URLhaus database entry for http://brittknight.com/PHP/5bgKOXH0pM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2252799
URL: http://brittknight.com/PHP/5bgKOXH0pM/
URL Status:Offline
Host: brittknight.com
Date added:2022-06-30 20:41:06 UTC
Last online:2022-07-01 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-30 20:42:16 UTC to abuse{at}cloudflare[dot]com)
Takedown time:6 months, 24 days, 13 hours, 41 minutes Bad (down since 2023-01-21 10:24:00 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-03Wwg7f0Po8q5cc0NPff.dlldll 791c0f3e7e6d9c570ad29269ec3bc3f78fadc3c1952f35eb7ac694f3e31551aaVirustotal results 40.30% Heodo
2022-06-30pBXT.dlldll 561f2726fc6195cb9fb5f42a7ff2b58c98130252cc953abc227eef38385d66aan/a Heodo
2022-06-30LXxbK.dlldll 683c6eb65f206ee2754054cb0679bd97e4d433ee516dc3c75b9f9a99c1ea35e8n/aHeodo
2022-06-30A3dr1s69CzhhAdA.dlldll 1815b6d79adcd32e05e14b48c498894c8b647d9eac6b53b19f9e2f7d5a574eb6n/a Heodo
2022-06-30mVWy2F3ALU0W.dlldll f6c84b7b746c3bebfa2aff8c180154777d5cf31efab8f70566da387210a98bcdn/a Heodo
2022-06-30OXXAtkDiaah.dlldll 29e3307c9af3511426f4714de0798141c9fb2362411dbba18e502bcc938154bbn/a Heodo
2022-06-30I0osKTOa4BVP9VP27Rh.dlldll 50342046b621ca0462961cec63d11130c48dccb18d0991b44b304308b13176bbn/a Heodo
2022-06-30qsgqotDjL1.dlldll 5fcaac185b5bf929f354dd459f30c635255b633003995f95e44bbf30f0b181e4n/aHeodo
2022-06-30GJoskEI.dlldll 9340af36d5adcea5e07c3b4abd4fb308f6ba8d50c466465d45a457730ef8361dn/a Heodo