URLhaus Database

You are currently viewing the URLhaus database entry for http://contactworks.nl/images_old/NuEAhfF0PCFhvv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2399934
URL: http://contactworks.nl/images_old/NuEAhfF0PCFhvv/
URL Status:Offline
Host: contactworks.nl
Date added:2022-11-03 21:36:10 UTC
Last online:2023-01-21 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-03 21:37:13 UTC to abuse{at}denit[dot]net)
Takedown time:2 months, 18 days, 14 hours, 0 minutes Bad (down since 2023-01-21 11:37:38 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-04gzjAuWjKrMSadp1NlkN.dlldll 2f5a1adf7c4e8f14df55d2b719d1eb146ed7faa961dfb151a7c887fe888c880en/a Heodo
2022-11-04enpWbn.dlldll 40443b90fe7a0308049e406113207b9adfe412d6d8e37451b076e36458ae3befn/a Heodo
2022-11-04eT7gYZYEiaAZr.dlldll 3959406c461aa63bf8a5c2dd603b416940133796d6b3ff929e4f7acc3c3020f5n/a Heodo
2022-11-04uFL6l.dlldll f173e87152e13e5c458d57b21beb6b7589367c8322b8b421888606383fb988aan/a Heodo
2022-11-04fXVyr98DD8JY.dlldll 51edd3d1ed514c843252d6add0c8e886408ed07e1d2b5d521c479d70467bf622n/a Heodo
2022-11-04q4hUs5.dlldll c955b5758048e79666928e7db82d41fd2d500607561ac03eda1dc2fb95ce2d62n/a Heodo
2022-11-04MMZlE9XmxDbwS0.dlldll 16682fd3ac1bcf992f08708f5557868f1b5408d26c85d4ce7633ef1d6d55bdcen/a Heodo
2022-11-04AUS.dlldll 967aa4123f86dbef77b25d14057c1bcd00b2186d6d8256d2e3d22581311560d7n/a Heodo
2022-11-03dB2GHH069AXtQ0.dlldll db434891c6577a9abb8c6eb90d7a70d7187e8b9d7d8c4d83113f81a732ed94bdn/a Heodo
2022-11-03Te4dKIxwdwMSJ.dlldll af57dd03ce50445b4b10ae181eae257ca92b74711a17e5b940c937f04e4def7cn/a Heodo
2022-11-03o7ZUcNlLpWit.dlldll 78aafa0323ca57f3ba7d78ac7ad1a2135bad2d94cf3c61c5c2a049116f2ddec2n/a Heodo
2022-11-030LUDOeQ.dlldll 6d81cdbae00a102f1d41b8cb9a0b6f53ae6196c92637436d4aa6e679bc5cb232n/a Heodo