URLhaus Database

You are currently viewing the URLhaus database entry for http://alsafwa.com.ly/webcal/E3Yx9UarfMuz6sk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2255086
URL: http://alsafwa.com.ly/webcal/E3Yx9UarfMuz6sk/
URL Status:Offline
Host: alsafwa.com.ly
Date added:2022-07-07 16:49:04 UTC
Last online:2022-10-10 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-07-07 16:50:06 UTC to abuse{at}ipxo[dot]com)
Takedown time:3 months, 4 days, 14 hours, 25 minutes Bad (down since 2022-10-10 07:15:30 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-08-02EdwLcJVCRa3v9.dlldll aaf5b64822d32a407209f3b667686ecb2b4a68f534e8c1f0dd4376ad591b9921Virustotal results 64.29% Heodo
2022-07-07uY3qaeJV.dlldll 9d5ccab14311a235cd712418dc23ef590391955f950995ca56246a10b8cf3628Virustotal results 17.65% Heodo
2022-07-07oMpZNNT.dlldll 315d3f3602a10ec4be255f2205ea55664f870e9a7632b02e050e98cb79479a0eVirustotal results 17.65% Heodo
2022-07-07GWhqVil7cRcgvjjsMY.dlldll 3d42a90cb1583a11039d7211f34d610265475ce3a881471bcd8625b615a87080Virustotal results 17.65% Heodo
2022-07-07CCzl.dlldll 0b7fda5ecc0ae9a8b7bf4a8b683b7a289b5815d8ad6f6374a4aa0217eb328320Virustotal results 17.91% Heodo
2022-07-07I55FTVBOie2S7glZm0.dlldll 5ebb68749514992167869a19319b650b6e433160028bb5655df4aa7594b317f7Virustotal results 17.91% Heodo
2022-07-07HbBSv6wt1rToBNeWc9.dlldll b4d28f5b237daab8c0824ff77380589658d2cced45713a47ad88de2bbb2b7b46Virustotal results 17.65% Heodo
2022-07-07UyMU9bXPF68dVyW.dlldll 0e43c4b2b7027cd1f09b967a1936de49d47d40c48b15b7ecba8b31588e1daa6dVirustotal results 13.43% Heodo
2022-07-078P4Jno86TD7Qx7RIi2.dlldll 4454116e023e3b6f395d2c288de2cb3d87dfbf5396ced0e6676fec88a0ba8ae7Virustotal results 13.43% Heodo
2022-07-0717peh4Ohmnjg05WsoN.dlldll 4f75415f3a52663fef3da96aa47661d61dfb71e3f8cfde499a3cc7c61fb4525fVirustotal results 13.43% Heodo
2022-07-07Yh71BOqHjXWdGG.dlldll 57c456adbefe0129b2d439d55520281ca5b35113b96b2cde9f1de777ad6cc8ebVirustotal results 36.76% Heodo
2022-07-0705QHb56qK4p.dlldll 030947556137ab9db7791477c1f4fa4c65d82dde9d1269f891da5501be34c220Virustotal results 39.71% Heodo
2022-07-07g3pVJkz.dlldll 3090438fbc13dad888097d81da3170698f4688d561167b3706e4e929e4cc76f6Virustotal results 38.24% Heodo
2022-07-07QNyIyNojI.dlldll c8e0369db99e6c5881559b240935b47c3745faa221bb758153923270aa8805a6Virustotal results 36.76% Heodo
2022-07-07gGlRNqv.dlldll c634329accbaa7d2645a6c5a7a35b9cb71040ba6e35060d3dc1d83679cb3cad8Virustotal results 37.31% Heodo
2022-07-070QU.dlldll 5e7489b4b1a6564f2223f13c11bf99b9827f6378092002eca4af59bd80ec1f89Virustotal results 38.24% Heodo
2022-07-07dReexZMl8.dlldll ab53bee0c0fb4ec9080c5bb568135941b68141e32eb644d33e7e15eb23cbb486Virustotal results 38.24% Heodo
2022-07-07mrnTKshjiPCGXv1m.dlldll 1f0fafa282cf9ea6d905365decb800e59bf7e821e49b839f132fe03588b855f9Virustotal results 36.76% Heodo
2022-07-07w36kvXOkUNMLV.dlldll 4f8f6ada15c69d6cc332305af8ada50f9d37b682b29e81ac559f41ea5a3f086dn/a Heodo
2022-07-075OOD.dlldll 5035dcac19ef62b42978264bd61fa48f4eee696571b5c36639106efad2bdb8c3n/a Heodo
2022-07-0766gUKx2YlKT.dlldll 3d8588f6f6d889098879d325d8f1d0551237d1e40658390577d7c87c2501ed86Virustotal results 38.24% Heodo
2022-07-07fC0.dlldll 51c0242abc2393953ce4369af9094a671bd369124ef56905e636f93d3c412eb4Virustotal results 36.92% Heodo
2022-07-07ws0C1pfIsgE0.dlldll bea85cc480d85c3166b2b92c078b941bd7a7861851221014cf2c6b68318043e4Virustotal results 36.76% Heodo
2022-07-071AFAjzjltLRJN2.dlldll 1694a9cbbfa30d68aa628f43b75b7977ca4c14324edb1dc8ac575d0b2dda6195n/a Heodo