URLhaus Database

You are currently viewing the URLhaus database entry for http://eznetb.synology.me/@eaDir/7ks2a6g9TV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2403001
URL: http://eznetb.synology.me/@eaDir/7ks2a6g9TV/
URL Status:Offline
Host: eznetb.synology.me
Date added:2022-11-07 07:30:12 UTC
Last online:2023-03-20 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-07 07:31:11 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:4 months, 13 days, 1 hours, 5 minutes Bad (down since 2023-03-20 08:36:46 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-086wKQEaXCD.dlldll 3d3110c125ae63baa9fa3811d133d72e17621b5f6f2dc8ba2dc3e3aa320a2b31n/aHeodo
2022-11-08C12DncoJez10Cg.dlldll 55c885a7f64d9edaa108cdb8317f2e8a0c72eb27691024df30ec4a1c9c68a258n/a Heodo
2022-11-08NaUf.dlldll 8f4af14339fa6eb04aa40b12eb20d66c77d0ca9244ef3daa96332472c7828bf8n/a Heodo
2022-11-08XOcwb5bHDewm.dlldll 119d1de288c76ad14a27a73bd05877c3ffca295fde74a493103839be5480a13dn/a Heodo
2022-11-08gwnJ3K48mG0.dlldll 9c1f4232104e75cc1fa25c58f5daa352c8530b5e955e391ade2b12c6cce8b535n/a Heodo
2022-11-08VDhatUvOaEqvo1m.dlldll 4c88afd77e3bb014822ae878d3c081951596d79ebc2e77bb0839fdbc51daf13cn/a Heodo
2022-11-08EykR8qjtF8LCdeh.dlldll b133c89485565ae57a8781ecd3224eeeb39abeca0d3acfb485adde391c7e7e17n/a Heodo
2022-11-08z40USIBLy7eNogk.dlldll 8e49c777c2e46fc275579dea48d41d7c71ede22e5c232b3d7eeac29bd09681e6n/a Heodo
2022-11-080ALCBT.dlldll c5b34fc1611978574ef8bfeada572bb3b688f84147bfa6d16b400082bd1c320fn/a Heodo
2022-11-089U4Qs50Y9c.dlldll 555e8d233eaf46aa6490086cad7246def75a07b1f4e4634494534803ce654d7bn/a Heodo
2022-11-08kwihafUWlvEbxedMoPN.dlldll c4a98bc3809381c7b4663e3004b7662575f89081347ad76539834a08f5eef036n/a Heodo
2022-11-08jFp8.dlldll 4cd0351a22a9e5f2cb6ff45b4ff2c308d9a51482dfd63ca84eec20d13713209fn/a Heodo
2022-11-08DsviBlYTAhBOwD4PJe.dlldll 9fda39333e3010662b1d5bd0b9002219e4b4c94d76427b24e4060f6708203713n/a Heodo
2022-11-08YfwtVdZ9bRub.dlldll bf137ac6b188fbd2d34636fbc8ea8605a55953985ae0b30ca89d09059895957dn/a Heodo
2022-11-081o1VEbmSNd.dlldll 79873b81c20f8f3fb021a45b123112ae24ebcdb8c9f0d70000d4b155e52fe5ecn/a Heodo
2022-11-07eagFsWGSZACiG9LZH.dlldll 76f9f4ed137b2c2cbb4e8abd1fee6220a88fb7b3cb67ef8c1eff592f3bd3add5n/a Heodo
2022-11-07U4NS1d.dlldll 3ad2b6e924692bb56f39e99973d8caa9609238f827dbc9d71d06b63f63079959n/a Heodo
2022-11-07C8q6Brs872L4Zs.dlldll 55541fd04174eff810c45a68f36619c23b08033d3788712436a4a36c56acf7a9Virustotal results 7.04% Heodo
2022-11-07TALp5RRSi85f.dlldll 5360d5e75b41a42ea55783e0c7c2d3c4bc014d7b005c67185c08c90b0796f50fn/a Heodo
2022-11-076Gd8BrBPSmS.dlldll 1bb587b77ddc5dae87364853953277ac519f1439d0450c7a14a7518f0533f9dfn/a Heodo
2022-11-07ODDROKxHferz.dlldll fdd8209938067264abdef165fcd48cb9abd21ed2eae9668215746355bf0e3ce0n/a Heodo
2022-11-07WWwFEe3FYY8OGeql.dlldll a9633491e8de3efdf7ccd5893b7a134c1d17839c4982b679ab663fc02f34fe0fn/a Heodo
2022-11-07PZ7QXTo.dlldll d4de5fbb25fe1e6919b10d560b880c859c6c60241e5a086b396455efcc6d5566n/a Heodo
2022-11-07etwrBzaxZFJbWtMdFj.dlldll 70fe6ad39317785438b2ae54e5fe76a2d69271211836df9496b820909598d96an/a Heodo
2022-11-07NYoAjggZ7rX7.dlldll 008873e2b9c191599174eaf62b60d04a62c6e13ed5af7820fc274286a9c829fbn/a Heodo
2022-11-070hT0YTaZxHe8KyM6T.dlldll a0d170984753ef3b687488cc3eef3aef8f032174a76f6c050a0a5f17e0aee980n/a Heodo
2022-11-07akvebTrw.dlldll 56278035854ee60ed3100266d47ab7c7dd55fe7daeecb0838655f4abbf753415n/a Heodo
2022-11-07PPfYLCCzA3KCyJxj.dlldll 48d38f08afb411383302bbb2e2ca8ae70dbc73b7c3afb69ea43885523177e17en/a Heodo
2022-11-07ZYGBhnwAOKUJDu8.dlldll 9dd7beecce2cceb036d119e18defa4000e94637a87da711e7e64192a77144adan/a Heodo
2022-11-07FLo.dlldll e7728568a6dd4067e50865488781177d675c3f66bc2d2cf22917b934f3dfc689n/a Heodo
2022-11-071bZiJDwgOkKtBu.dlldll fabff41ef51080931ad3355e59c03794dbef5ab6d25376f29d7e7ad6e2860e7dn/a Heodo
2022-11-071gybZFICtTx.dlldll eb1f4d81b71f5462ad3f195655dd011cb7ed30d072c73584f26d7dda30a0a5bdn/a Heodo