URLhaus Database

You are currently viewing the URLhaus database entry for http://cubicegg.asia/assets/hAr6tUluhw785R/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2407043
URL: http://cubicegg.asia/assets/hAr6tUluhw785R/
URL Status:Offline
Host: cubicegg.asia
Date added:2022-11-10 16:30:13 UTC
Last online:2022-11-12 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-10 16:31:14 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:1 day, 22 hours, 23 minutes Poor (down since 2022-11-12 14:54:38 UTC)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-10yQREDp9KDikUx.dlldll 92a005c6b4899ff9c0f4c3903aa3bb9ce27a0c2d2b4a94e241bf35b9760ea28dn/aHeodo
2022-11-10DEIGSlo5u7U7SOBhN7g.dlldll 1799524d42e0521acede73f3ba0ed5f4142b3fbbde75f82c3ebabaa6fc2c3be2n/a Heodo
2022-11-10VeAW.dlldll 800457b8de0b46789d67a795ab406b8204c180c873069816607b521cba0673bcn/a Heodo
2022-11-10zLaKlwKy0ZdrEQ.dlldll 4628a8dc2756302963769ab06556b933cffad77f2a07c173974862a182b45e9an/a Heodo
2022-11-102YtMtCxAZI9M7w.dlldll 345d2c9e5a64a470a72312e0fb1efdfee52e46ee54de84c008329834e4536e75n/aHeodo
2022-11-1092Wuv509Qago.dlldll 197801e2161b97d62f541877490ca6ee42d88916fb5f4f798b55d57fba2b03b9n/a Heodo
2022-11-10zVsxYs7LwonOiWu.dlldll f4f4d8d69088eee748bdd3dcce8069c17b05fdfa892f382536f2ae67505c0a71n/a Heodo