URLhaus Database

You are currently viewing the URLhaus database entry for http://gxthanhtam.com/modules/cvH3FI3vRRmAxH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2252825
URL: http://gxthanhtam.com/modules/cvH3FI3vRRmAxH/
URL Status:Offline
Host: gxthanhtam.com
Date added:2022-06-30 22:09:13 UTC
Last online:2022-08-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-06-30 22:10:09 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 10 days, 23 hours, 41 minutes Bad (down since 2022-08-10 21:51:26 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-02hPZ5rAhIDHEjsYZFrlXZy.dlldll faaf44cb7c1228b1571d88f6335baa2e50cadbf081608f5c35662198f14dea97Virustotal results 26.47% Heodo
2022-07-010ws2wdWoRe3t7zdOK0MaSZll.dlldll 6f4fef095875319969182de36687d3f887eff2ec9a9129bdb8b377ca16c86157n/a Heodo
2022-07-01W7QzUz.dlldll 0495268bad8a3e9dd4bfbce5d94609dea3f96d918572350fda733fb60f6092a6n/a Heodo
2022-07-016nkctF66Z4Nsa0MSwVlCqgqu3oF9.dlldll f3ac1d7d01191083f5ce837aec57d3b4d19234c8146f317c437ae10e3f7193c7n/a Heodo
2022-07-01TzxDIq24fAPgDe29CTT8ecmBYeBT8tw.dlldll 27f177435734af37b32d575d2f049604a68073ce6e57ec228242101d442cceb1n/a Heodo
2022-07-01UJ8lnXOdNsChGS8eD9.dlldll b908f2e895673d8b14ab30e797a3d586d8f4b4a597006e9c3b83132d4724fc46n/a Heodo
2022-07-014VvpoHU16crh7wexrygqeP2L3jsCvqnR6.dlldll 5420f41a8235fcb0a80f9266bb205f45ad349f9c244eca8af27060f8c3d69c1an/a Heodo
2022-07-01gCeFK1yyZUyhPB5D2kk25AMRjj.dlldll 2a6b31ea47a23616f00c1e0f4f52a2a4fc44e48c17ff1a34e72e11eda17081e5n/a Heodo
2022-07-01HEF0tvL5.dlldll 86c3d93261677226b4d04017921a327cbb1a36777b5f26aa07a955e1cc101848n/a Heodo
2022-07-0144tT6K0lnBBffSkytttVbwUSGeZtI0omiD.dlldll 4ca305931027ae7f1c712efe62e7bdc31aa3305f9b5a9727aa63ad6f78c8bf4fn/a Heodo
2022-07-01Qs7fXBcNkb6.dlldll b43af52e5af43e002f7d1eae5965ce85cb362e6ee35e8a797517a09965b69af5n/a Heodo
2022-07-01jiSqnzgomQmWEiEwB7dUUkirrsLgq.dlldll 5b4d965145eaef9373e8241b08677e5d619742279a5d0172c2ea73cc761095d6n/a Heodo
2022-07-01goWgkWzZa6Tbylw18l2uSvmZlAYN6Xj6.dlldll f7282bf53c56b44ae6353099b30a8903a6d39e9de9bd14b08a672f36ef2b1678n/a Heodo
2022-07-011ixw6HBjdm5RHtZw5brMTYts76.dlldll bc734e138f855e42a051cd6498e0ac57f65ac7562658dd2139e2d28ec359b678n/a Heodo
2022-07-01WY20Nfmm.dlldll 97a3678e2e669bbb76ac5b493a0bce1033a19b46c943b71a70d77c0f0a1abe13n/a Heodo
2022-07-01rxrSMfsrtJpysUkPZpgPrF8.dlldll abfeeece1a03642c6cfc52ee95e9f001a59b53cf01e4938b034451589c8c2b92n/a Heodo
2022-07-010b0ny5cPMbVWNYNasSl42nns7w0bJ50HYE.dlldll 559e2b97276cf7d5a65eaa4194e3e901af6f7b6411de2a3f34e1b282bf59c34en/a Heodo
2022-07-0174NiDjT5U.dlldll 31bc9aa0f5453759f0909323db8d3b3a2ade794cc1fbe3aba9d914a16d1cce37n/a Heodo
2022-07-013XoRFCJLm9SxbuleXr2PDzuHF.dlldll bfdc978b6c8ac668633f168aa42922fc3678be5a4742f679bd92efeb127cf3aen/a Heodo
2022-07-01kY3xqenzz8jQN7xAsyYHWny.dlldll 071efb9fc28bcf7e83f80c672a21e8f7dc9c5afab44f3dc10d1d1e67be5e2ad5n/a Heodo
2022-07-01HN66mS20RakgSk8gZCb9o5WxeGnROWrLZ.dlldll 512c9578e3ec9c28386d0e91e8970809fad67a6b0bfe2aeda32e90bbef2ec1d5n/a Heodo
2022-07-01dQq7yNNA5hFKNNaDMR9.dlldll 52c87d55023f093055e08e16be61c9fda5d526909bfd13d53df68a27f1648696Virustotal results 22.39% Heodo
2022-07-01OXqcobT2RED.dlldll 64e4895c6c44493c39395995ffdb02d9e40edd43356b7424c8d98673b499fa1an/a Heodo
2022-07-01DS1oa9CaZwMO5HFV6LnbOXmZvqH8HCr.dlldll a9584ef173a391f231767bba1f5d967ff8eb5c076b7e605d9cacc9ad27b8513en/aHeodo
2022-07-01jkJCxxRvMpaGbmHx8cJ9RQ4.dlldll 80241b13bb505ebebc97376e58aec30e6b58fd72d945325e0673b046141a4d81n/a Heodo
2022-07-01p0JpoHeriwPuSgEyPcNZyQ5nhNCRWEZVn52.dlldll b75023e1bfb15a047af13c6ed211bdcd78a9823fd02c882e6c5f43248bef8c27n/a Heodo
2022-06-3076ge7aLeJC46Wn9L.dlldll 6aed187b3214e6453c775c925773cd44bfa7d0a79aa13c469264da02931620d9n/a Heodo
2022-06-30M0C0mR.dlldll dd1d976df3daa95d1dbbaaa788e8748372d41a911d578376fd5b9a93e0f2efccn/a Heodo
2022-06-307RbIAx44sb7RsFEUDZIPXWfa9i.dlldll 6a961faeabbf7fdd86148b8e658c3285ea242bb6bcd4f697b5519a1d63f9545cVirustotal results 23.88% Heodo
2022-06-30n96siYTpt4Z3mwRe1.dlldll a19159714b3f37d9978603676e0594c146bc92ade09148257816f692e8a0fa3en/a Heodo
2022-06-306cURCnbbI7vQQ85HbD5vLgksFbyx.dlldll bdf48b064550f42195b18d84f63f6b8d8840e154fd736c2bf76b6ab7236e5ad2n/a Heodo
2022-06-30PH5zV42r.dlldll 94788bc2e940d0ebda01cde32c04fab4e0a9eb932de552b527f5ded49423c44fn/a Heodo
2022-06-30PNiPVcBZMwIbMvXLXel2nF.dlldll da3f75d6160d3e6fbf0462d36a25d4d0e3b51afa2877bc1f5f80dd4049546d5bn/a Heodo
2022-06-30KRICi1ovvcllrh.dlldll 8862117ca12ca31baf3992ac1969f4655b8801d334b90b4aab692dee7f0496d9n/a Heodo