URLhaus Database

You are currently viewing the URLhaus database entry for http://zhivir.com/wp/g1bvvKyM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2253995
URL: http://zhivir.com/wp/g1bvvKyM/
URL Status:Offline
Host: zhivir.com
Date added:2022-07-05 00:39:05 UTC
Last online:2023-01-20 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-07-05 00:40:09 UTC to abuse{at}cogentco[dot]com)
Takedown time:6 months, 19 days, 6 hours, 49 minutes Bad (down since 2023-01-20 07:29:32 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-05QeWBRZyAZ0ENdGFWv69fiZEp.dlldll 6cb3e138ac0ebb257ccf9eb0961b31d4c4e05b907222e11e11434e1c9f2bd4cdn/a Heodo
2022-07-05b5mbOB6TDmHOcc81gW.dlldll d29dff2e4ad7c0fcf73da16fd0775d0693668cb291d9dea7351f5d9f063309c0n/a Heodo
2022-07-052s18zcufrghjPASAA.dlldll 76d10600c0ee7719deb602b9b15f9136ddac7eb49a4eb17cd0002ee55ed859b9n/a Heodo
2022-07-05SB55pnZi8onLWHnGKM7P8p5fxDVPqA6.dlldll cc89294a9202469967f46f8db3d8d2ad7ec44192be2d17580683cb646bf0e1f1n/a Heodo
2022-07-05h6llUGSy4lYsIk59.dlldll 070c6672b993de57965e519f880d1b0dab3ab85c4c1524303ccc4ebaa20f5e42n/a Heodo
2022-07-05cNr1iTeem9u43MhLCi.dlldll 097d722b02b192bf07dc1cb69eda83ef1c51d07584735bf1d824179fee3944d5n/a Heodo
2022-07-05bxy1n11.dlldll 4a307945eee7fa45ca6c8da7dd4be8727f72b02e5a9642c90021e1548b8b6c50n/a Heodo
2022-07-05cCQblLhBB0LeoCbwiIRZOqVTU.dlldll 768e30c3b03fd6dfb34c6ba842e66ab81dc5f23f6fffc9af267872f34b40c98fn/a Heodo
2022-07-05wcutgqMlTzvF8MJR1d.dlldll 6dc092187d716cbb9d9086b09ca1c3c2bab3b5c765e8912c3e75358ca479cf30n/a Heodo
2022-07-05y7sAKh50B9.dlldll 783c0558a2bd84f00658d7b8232aa091fc0195064c47c328c7b2932a1bde8318n/a Heodo
2022-07-05UGVLqzFvlTcJb0XXD04ZYNgZg3UvOtglj4.dlldll a2ecda8d876948ee19f3fb69c5960b8ef97685e2c302f0638d02be644f5d6821n/a Heodo
2022-07-052BBJ0PEpT0hYqOKev.dlldll c5ba8b5fd3bcddb891ffab5d22bcdcb98d9eee61d18b5ad26d88c2f83b31337bn/a Heodo
2022-07-05AfZBPWZS33JzaK8ZHV8p428pW3yyyz.dlldll 2ec24c69e4bdffbf86b0c0b634e95e1eb8e448d36a005644c514030eaf6e3f74n/a Heodo
2022-07-05laTsAI6fTaZGjWwaLDkzI0xhPdsrGZ.dlldll a9115430d4b7954464c9b77b49bdbb307f62dd6c3e5ca5cab31532c2f2e1db0cn/a Heodo
2022-07-05CIM0uUT2UxOlo1gk.dlldll 1e33127a24020a96d92f494537a93665376437a4219b905859da028785774fbcn/a Heodo
2022-07-054aTtu4.dlldll bfce46ca328d3728050b2704f5e8891ff74eae438999f8d8e46d1a18469b91d9n/a Heodo
2022-07-05trJjT7qwEg2IyO297omFAC80.dlldll 722081c5b222f9336e3beb3f776394e08bd11380c1bc21db15d49836782a386fn/a Heodo
2022-07-05WEcfdhPWyaorV7PO8iJi18zbb.dlldll ab5af75e16816def44e4feab272a1692e0d3af48376c553f4dc5eeb561bb446an/a Heodo
2022-07-05UradDDrG9.dlldll 7f62ad0ae2defabfa820a1f29dab99115d7708b2e1b7c6bf08d4a2c6e513c8cdn/a Heodo
2022-07-05q7JBm8XjFSmMNZ11L5Uurpp4tB9Jpp34U.dlldll 64d60f19ac7b1f56b0e482326be24cec745bd34a832ac3e816dce4bccfccd207n/a Heodo
2022-07-05AW50dy9x5BTQamMWbKt.dlldll e48c3607637fe9b68adc88a1e3c848c28984f7154880963a5b145a95fdc5c02fn/a Heodo
2022-07-05ifLRMnl8p08WEFJ9IsS.dlldll 89cf6c80497434e08c4b4476fc2383550fcb92201e6982403e6af14e4088381bn/a Heodo
2022-07-050szTE71tsX.dlldll 70b1d7d36d5a21010df1646be628e70c0c2ca19d5052854e79622defbda933a9n/a Heodo
2022-07-05rEK1HX3kdMBr8zjYoriBYmmSt7Nsss.dlldll f6675174c7632394de3768423556f86378f697654d1f1e1644efa04872f4bbdfn/a Heodo
2022-07-05XgBHhgVdUUxYQEQY1d1WdNo7En7xECcXaA.dlldll 335f8bc3dfe72e0c03e7a99377c2ad57ff8cbfd53a25931927c8b43fbec7f01cn/a Heodo
2022-07-05GhmWjcTw1S0urdhXrqZnX.dlldll 5a2bcc60894b4418bf456b89f4e5d0d0c2e2412b98dc18452d9deee03f700687n/a Heodo
2022-07-05KaCYNEE3hhbtyxYlvD44K3f.dlldll f6c23c77bfb4ca5adabda6225e73bf2f7c86865ff9fbe295aa984aedb3c98272n/a Heodo
2022-07-05pgXgmdaikkPpgLvH2H20plaj2HjNlwh.dlldll aba58f841fc33a693d560c0db90936c832c4b7c1c0e6563d9b023eb615d86fe4n/a Heodo
2022-07-056p7VMhCPGFNSPyOMDnnK2V282I.dlldll b630d1d0a9b7ada550126a4b98e28931c2a0664e8c35297838dc1c8ec12153a1n/a Heodo
2022-07-05wEE2l8CXotOIP1zbCH4YDeXc1.dlldll 3a36d60dd0eabe6af55ffdef899bfaf42d523a0217278eeca5bc8e70de2a9de3n/a Heodo
2022-07-05s1IJxjdby6M.dlldll 0519f3aa5d054a4d930d34f63a70e48a047a28890db6a5a54640376ad0ba9b99n/a Heodo
2022-07-05BLopGMvJeatuIv8gXPeJ9OvQIn.dlldll 94ca8b13159321177187988b275b3b8cfabb3e4b39115daca0a0dbd08f477756n/a Heodo
2022-07-05oyuHlrjvcuFCNcQ8lbIx3AStG9yyx4.dlldll 3d2f444d3e907cd5dec6766bfa796aba99cbd36586926241eba84c517b8540fen/a Heodo
2022-07-05cQVF3V9tyyNPip2ooHP9Hy.dlldll 023d4517a83d5292278cf3605c9b81ccb87cf470ab603019f4f95c401ee194b1n/a Heodo
2022-07-05OlyVZ2RWkcAR22IB.dlldll c5c2f880872bced91974ec17b9384e1ea2ae30cdd30fa9aa66d8a9a0615fdb16n/a Heodo
2022-07-05w2IMVbqrYH4TO72o6wHofwRELVqPciCEQxq.dlldll f66434b80c5ce1c0483a447376ffedaf02af2950bbafe0e452f411923a1c7a2an/a Heodo
2022-07-05ls4eQiLx.dlldll 732ee8db68ff996eed80cbe842b4fc4f0652a2254503ba04e2bb3b7723da1494n/a Heodo
2022-07-05qqm6cOY85.dlldll fd0fab57b4c0a31595e1d0bdc2300f53566ac341f27b13632ed87c49136f4978n/a Heodo
2022-07-05BhRFUA.dlldll e56ac7c3266d101565ca0c56bdf2fded02435611455141b875d6534cd9b31f66n/a Heodo
2022-07-053Zi5DX3jk5v1WnjmbIoi.dlldll ba620a423f59a8579047cc8c364a810ed8505cf9d5c4327d18bb6decda8e95abn/a Heodo