URLhaus Database

You are currently viewing the URLhaus database entry for http://ftp.yourbankruptcypartner.com/wp-content/HjSaWCEgzhi6CZS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2254347
URL: http://ftp.yourbankruptcypartner.com/wp-content/HjSaWCEgzhi6CZS/
URL Status:Offline
Host: ftp.yourbankruptcypartner.com
Date added:2022-07-06 03:14:10 UTC
Last online:2022-09-04 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-07-06 03:15:07 UTC to abuse{at}newtekone[dot]com)
Takedown time:2 months, 0 days, 16 hours, 43 minutes Bad (down since 2022-09-04 19:58:26 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-07-07vCw4tnMYJC06d2uOo.dlldll a1f01a93922e65a5f5c813b390a5844395a7d5b9878ecc41ced2965533a8b27eVirustotal results 36.76% Heodo
2022-07-06SSuga5y.dlldll 861f47a1b5be14ae403d61aa6a4b227436f4248335c9acb7835ff2f3885631a8Virustotal results 24.24% Heodo
2022-07-06cd6ERWfmKavgEV.dlldll 6762e04d2549b3f95a8ecf2d2ae4d8de2ee44b1a7c8e6750a96aa096695f14a4n/aHeodo
2022-07-06v7itH1dlixsnwYgQFFRefOBZQcN8U8.dlldll a276be3515d51db0ee79304ac5a60d8b821a79928c960e9ae9a55955241edd5fn/a Heodo
2022-07-06Ok3loTtQHgvwhRQtJQfdZMnV9.dlldll c3a75ce4a8f7cea5bd6c4afd688779d4db99e6667d4c50382e941ac280a50aben/a Heodo
2022-07-06mLY3TQ0KNBCVcGWrFlIOdzz74.dlldll 6be5e65d252e413fba4fd6232b35b305273af3c1ad9bc13c17bba7850d0315dbn/a Heodo
2022-07-06uJQRztluyZ9HC2ew03c1iHJw2yHTG2d0Kmb.dlldll 97a0441361f929f0ff0a24a57e39471a449660559a9afaa2268abbb75d62c2d3n/a Heodo
2022-07-06A9nb20wx0kIItaWqQOJ0mz2uJHtNu.dlldll 844344d479b0277aaaf8ef4b47c263265a731d79e2b8e4a66a2920b838f7b13an/a Heodo
2022-07-06dsoaObcf0m5hRxxDB7yDyuS4jups9WqIX5r.dlldll e2c1e0f6d146905e3ae50e92d40203005383a2a9469dfda19c0821e3af8f4a14Virustotal results 22.39% Heodo
2022-07-06fTT9hndw0aNTbvODnRiZByonTTj.dlldll d20e8ba982a00c039bdc0a72a9488faf162b0b426c39758748bcaf6c2be96086n/a Heodo
2022-07-06FwzyeYGg.dlldll d6851c150a8149d7fd47818731c164750d6520dd20f17a7879d5ccb49bda3aa5n/a Heodo