URLhaus Database

You are currently viewing the URLhaus database entry for http://bwsengineering.co.za/configSHV/H0Rs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2404995
URL: http://bwsengineering.co.za/configSHV/H0Rs/
URL Status:Offline
Host: bwsengineering.co.za
Date added:2022-11-08 16:39:11 UTC
Last online:2023-03-01 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-08 16:40:10 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:3 months, 22 days, 18 hours, 10 minutes Bad (down since 2023-03-01 10:50:12 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-10dLa1DnMkTQg8m.dlldll b88577b3d9a051360d05f5953ad9dc045d9b2acaec898620969751363fab5bf4n/aHeodo
2022-11-10h8XYWYAQASQERT.dlldll b75287de9c69929d4d82242854de22ae2c58e271092292af620eab66e06c24cen/a Heodo
2022-11-10SUatiR9NVeQQSHDU.dlldll a878f61d63fff69d86480d40fdbc505936da57873114dff088eb64fe7a3bf011n/a Heodo
2022-11-10DYc1aqDk55VP5VWHsX.dlldll 333867001e4088c2e50a049a2f65d522774f81c7937df179768332a60a23460an/a Heodo
2022-11-10UiMi7P9ZobuP7kF7JH9.dlldll db3675468cdfb6280077a7005d6c422d75beb8498c15c4b99a15991a1c0299f2n/a Heodo
2022-11-10lwoQL.dlldll 2c16ad61e36b0a61cb19deaadc6a309df4655f953650847147f024ad5af7e127n/a Heodo
2022-11-10W0H4Al0Gvnf8GQ.dlldll 4f9d65bab2179e1bc6c3ac1e5768061581bd08f494da91e0d284eb9adc5a86aen/a Heodo
2022-11-10x8tEIArncosHJ.dlldll 19f67ce4c70f9ec5549f8f9f8474f255a9adbe47a4a748b70e818fb3908f7d5dn/a Heodo
2022-11-10hnsHQEz.dlldll 6511b8ecebb4e7cffdd4d12962a1a03ac595db917a500cc87bf9833960e29cd2n/a Heodo
2022-11-09uLqac.dlldll 66320969b3998e05f4882920497d60d7a158da98496bc8fa24e50b05020e959en/a Heodo
2022-11-09mt8D.dlldll 2a69f4bc63aee995da04d9908bc7d37ae72268bba8ec1e59e7e0602e95ca841dn/a Heodo
2022-11-09ZwF52klqOc.dlldll bf3383dc9dd4ee43fe571ba2e4d9a86f8d159a953c81579fa6f6ed1c32d27925n/a Heodo
2022-11-09W1MN1WYN.dlldll ecab3b0c3deb377e311a31c6b37ed95622adf6964c33e5b7d7f7b1ed4bb6d5d3n/a Heodo
2022-11-09NxjZcRhQXQs15vLbp4.dlldll 5b7935f17a4a440571154572ecce6cd0ede5122e06af07b752b7146c83ae631bn/a Heodo
2022-11-098w3.dlldll 8f717a28f94e32faedd80bbc144a969e604ef9fbc7656141ad243119af0702b2n/a Heodo
2022-11-09v1XVo4o.dlldll 9dfbe7d1769f2d96c75ebcb2318eb06cafb3fd2e0fa4e7dbe947a87bcd65b214n/a Heodo
2022-11-093nJgtcvXQCIeWDwN.dlldll 3f911c0e7ec2a9ed7af8cca4f143cb2ebd7beb92a880ede839747283d14288dfn/a Heodo
2022-11-09xAB3OhkG0bBRxqtqI0Q.dlldll 57af9c6e7aaae384f6162cce5d00d4169088b4a62d6fcfb5283fd4980bf036c3n/a Heodo
2022-11-09x4b.dlldll b88c36245929fe34deed992bde08881e2caf3721ee59837bade84a1c6d76049bn/a Heodo
2022-11-096fiEQiNYVabvCvJrS9.dlldll da2a6b17e5ff7fcbf4c216b8c8fed3667b750848630b0e38671cdaac04e2a1d1n/a Heodo
2022-11-09cy66.dlldll acc50c329d6da587219f4e39f2cb84ee0acc61b7e156eb73a49ee84e15161d8fn/a Heodo
2022-11-09c2TQvSYas2wXFe.dlldll 06ef8ab852fedfdf98865e2fc0cd73354d2881a5f784be6a18d5337612c94372n/a Heodo
2022-11-09HFsEI.dlldll ddd05841759e2ef0b216d9cf41d8fca3b29d1df3371e57366ba2446263556540Virustotal results 12.68% Heodo
2022-11-09IzaNFB.dlldll 024ef43d9dfcf9c0f3b65162441de4c2257737ec096fd5552b83af6b16ec4832n/a Heodo
2022-11-09tBIN2VVrxmkOcQH.dlldll c8bc2419f46427146ecbaf636a5a99c2d1c18b34494e50a2570633b966d8d545n/a Heodo
2022-11-09I4xVX7gnztg2R1LMIT4.dlldll 6d6e97425934b4a4eb10b3eddd23f18f96d08290db621efed7fb6b33968e6767n/a Heodo
2022-11-09hQfLggr3UTZYr9D9fFr.dlldll 12b99a82fa552cfd6abeb9df83bc20a36190c23a1c40ec3778b0c101f8d14ae7n/a Heodo
2022-11-09MkRsbhhJJktuMo6pz.dlldll 050b0386d8b59ec8b9177efe9c44acbeb055826aa52632c95aa66f632e7d5105n/a Heodo
2022-11-096F8wU.dlldll 25ad3d08cea675697cc511361b9be333242c0b4d8e5bf3775bb734b60e57ee73n/a Heodo
2022-11-09cj7keSFnEkWQ88y8f.dlldll 8aa4768739ee664dafed2d3c11d88a1a39d5b004f2eaa3d1ce1d5c2773e13cdan/a Heodo
2022-11-099J3sSh9PzmFuGGa.dlldll 0452bf33afa25d2e5b2f4f0e347afee9daf662194852974c31c85a3e9aeb5877n/a Heodo
2022-11-08bktk.dlldll 1d3d2d4d49a58f5770d5a4a4036c9e4dbc75a120b88464c39d949a37014f4353n/a Heodo
2022-11-08vQDE.dlldll bb216edff0b43f30c98904d4c4eb07ea8c3c795afa6ed0b460cc1878dab94a6cn/a Heodo
2022-11-08HqRis4HyxpSs.dlldll 24950a6d188a0b117420ce7cda0e9b75c5ef3fe11bcde22adfb6e85522770909n/a Heodo
2022-11-08C8yM52.dlldll 615a8e748a2f82616953f00f2d45f7e250f5c30b5c733db806f15d8d1202f70fn/a Heodo
2022-11-08VixMlvMY.dlldll 78682be1a9adcebfd5452284bd66e5ec0bf418b5a6554c138c06ba7da227bd06n/a Heodo
2022-11-08Feuq5hgNIcVyszTSe5.dlldll 7af384cba96a8dc93bf0032e3ef6a73bcdcf3af8eaa1d2069b43c76a469eab4bn/a Heodo
2022-11-083Fi6wLjaq1PNL.dlldll f0e6077375f73446317623750d565d6c7b38b071b0f9d642effd417f85001929Virustotal results 14.49%Heodo
2022-11-08lTGfCtD6J860NILKf.dlldll 4a91b92fb470d0bfd76d6bc4c9cc5a9cd2c08ddc7bc8dd09ecfae961e42e80d5n/a Heodo