URLhaus Database

You are currently viewing the URLhaus database entry for https://web.ferno.sk/wp-content/pWLdtgNRJjGIs4V/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2408080
URL: https://web.ferno.sk/wp-content/pWLdtgNRJjGIs4V/
URL Status:Offline
Host: web.ferno.sk
Date added:2022-11-11 18:14:12 UTC
Last online:2022-12-28 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-11 18:15:14 UTC to abuse{at}telekom[dot]sk)
Takedown time:1 month, 16 days, 12 hours, 34 minutes Bad (down since 2022-12-28 06:50:09 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-13nzBCgwU.dlldll bbb4af4e6bb7d68bcbb27d3c6c837ace18683f997b86abb5bb8d403336e7560en/aHeodo
2022-11-134F7.dlldll a2651fd1495a9920c6cb2fceaf2b22d0c661e08f6a5abba7042aa8d39b95f553n/a Heodo
2022-11-13719jCLIAs.dlldll 2b08efae4c127709c06d87fba7e9cdf6f51281ad3585d9eacc18102223182b9dn/a Heodo
2022-11-133Ie44qHZ4w.dlldll 5933e54e118afb32b0923011c4a2cb73fe8468f7932ab9ca8309087b711c2e55n/a Heodo
2022-11-13ebguO.dlldll e75eae63a48e7b79f6c9eaaa49b4faa828ef5688e0e9e46163ffc9b91269da72n/a Heodo
2022-11-130aj70z.dlldll f3ef62fd44b26096d9a84aba17ceacd0c9a86b04a4614880334419846360dc21n/a Heodo
2022-11-13SK4hSohktuZhi.dlldll c52f289cc55c4a1d1ea8328dce9f51171cfd40a543f0fc248e79e4b0c33b88e6n/a Heodo
2022-11-13mu9PY.dlldll 1bf4684d1b6e866ac5ea91563504bfaa1cf2e349161dac935a45ebfd5c20e8e1n/a Heodo
2022-11-13JkxVWUZGUzzjc1.dlldll 844a814164db82c4e6de7440ae02cd838fa0e951eed8f57592f72b56926e79bdn/a Heodo
2022-11-13ifbh2RTwSdt0R.dlldll 95649b68567b47ce8b58c50b85bfb2961d307eedc26d547e237c6f11b7574637n/a Heodo
2022-11-12RutgeWL44WQ4qKxR.dlldll 0da907fee18b74019c853240546efebbcaaacd4381b856f6ae0e2e18ee58309fn/a Heodo
2022-11-12NQdutwxCzms9.dlldll f143527dc665b055406fe61aba89d23f01fb1c44a0cadfb4c34d047d631fd492n/a Heodo
2022-11-12zoswUk.dlldll f40e32c237c1771b68db19441ed46a5f94e58490020de4c44d9590444df60268n/a Heodo
2022-11-12XqIEWNyqgjOAfOz6.dlldll 0ca3a4cdbcc6fdc0b7195b2581449e66cb39ef9cb4dfd8e155489da653a75118n/a Heodo
2022-11-12gTWUfl81LVAtK5mvd72.dlldll 62ed00ebf89e440c9190ae37a72780916e447d0933b21f2f14f6b7d4e6eae8f0n/a Heodo
2022-11-12KyhD2.dlldll 13f5f01bccf1507fad8d77fb9a1081e58ce786a1015008835dde2a4a3d827e2bn/a Heodo
2022-11-12pQzVpfkS5.dlldll 2ea041b7018538a47f19b4957c979b438be101cee25da3d741fc21c75e6d2750n/a Heodo
2022-11-12OZzhOh.dlldll 7232920a65a842d3fe71974dce621cb2721572f3499724166d618bf77c5a9a66n/a Heodo
2022-11-12KDqkDQ3dn.dlldll 11480029687c484538cfeb794c196f1224b20e92f227e8436680a98a61975321n/a Heodo
2022-11-12ljHGtz2D4b.dlldll 32776db3eca985cf892a9ea4a51f8a6f16131e15c2124e7b546de05c248a028en/aHeodo
2022-11-12MxnJOMf1oEN.dlldll 12f9dc9d59bb5b204f9b29e034b95a4d40e9c4511b07c8c83e30bd75d50f0e2bn/a Heodo
2022-11-12GtuIbNSQi7LA2PfOSFj.dlldll 2c7df73a50800ead1adae7442d8c7ca097769930da2a62837e718c297d2b76ban/a Heodo
2022-11-12EEhrS7AZeujn.dlldll 9edd2fab45ed5f837357c15ddcf8e768d577b338acb3f7d15daa67a805a46432n/a Heodo
2022-11-12U8N8tGvA9XTcG.dlldll c8a515b82851afd3bc3e8150bdc99feea2ae3860c61bb38b100973e861ff2927n/a Heodo
2022-11-124BeN81tcFVXvMjk.dlldll 437a79d4c8a494530ac1b1e8ed5ef02dddf12829119f0019b6e73860c2ce5964n/a Heodo
2022-11-12ABov1C.dlldll b8a3c91c6083d0eb1435cf82695e2d56e14c9015d8758ff2da3d9395d2f3b01dn/a Heodo
2022-11-12X6zEtboyJ08.dlldll 4c30b8aa7f44fd4f1ea3aef224b76efe89f5a3c8b5a9389b9cb7afc4136dd340n/a Heodo
2022-11-12XcSNhcRXipvOF.dlldll e7b793837f70b2ae64613246f97d51119139292f10d810c01401aa6991200eccn/a Heodo
2022-11-12NfjSQVNxxS.dlldll ae63bebf78a7c47344209a8eeb39308f41b73d98ace11289e42b2c366482bf75n/a Heodo
2022-11-12SWabEbr6iAXNUFfk9gU.dlldll 5959c2acc31f687580594eb882dec7a300028cba163a19ccc2ed30052bc608a7n/a Heodo
2022-11-12PzocnjigNr.dlldll fbe728559c7f2c4a00c2e19ac0e2c04b95fd6e184d296db1a35db9d8af0ffe3bn/a Heodo
2022-11-125I7eYcV768lEwl.dlldll c2f4f9e4f271d81ed8f28e19c3aaeb52fbe0b43dab6d99f9d504fafa926c7690Virustotal results 18.57% Heodo
2022-11-12sOFsS8e3GTT2v.dlldll 123d8247d1fbef551051592a8fb4649431a8fe10eb371e3678b3c624bcc1a6e5n/a Heodo
2022-11-12hPAwl115lXuGE6cF6.dlldll 4d15ceeab7bc51bf58efdd3c58e1a9ec572404ffe9daaed49a7229950357d399n/a Heodo
2022-11-11a2GMJiJqBTxRn.dlldll a03d4aecf0df3f254b122ceb09a6b2884eff60824b64461ff30ad25dec816abcn/a Heodo
2022-11-118JDS1rrJ.dlldll 91c542ba105d3bc7bfbc313fbad6ea101d8e25b3676d346e2150a3a18a5e286dn/a Heodo
2022-11-113jbQLNqTvWSrKn8a.dlldll c60ab9b822549681cf49da21e83386ed7f5c383fabe7a0c085291a7555bf2643n/a Heodo
2022-11-11RCa.dlldll 51ad324cc2141ccfb73e0f8681b32de4e1a2b3826dd0380aeba1f2e25e7b61b9n/aHeodo
2022-11-11DOHqlmY3m.dlldll 15abfe8a1740ae88059790cb8c11e7aecb975529927f7499a5dc00210b9a5915n/a Heodo
2022-11-11166E4QaFb.dlldll ed2d92813f15aa1f2526ec11ac55fcbaa5e719767bd246b671e5636262700901n/a Heodo
2022-11-11fhcj.dlldll 91de5016342f040305c1328ccc1d925b1200f1ca66f6c9ba1c0af2ba58986416n/a Heodo