URLhaus Database

You are currently viewing the URLhaus database entry for https://4fly.su/search/NrRU1QOR77up6YK5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2569808
URL: https://4fly.su/search/NrRU1QOR77up6YK5/
URL Status:Offline
Host: 4fly.su
Date added:2023-03-14 10:38:05 UTC
Last online:2023-03-19 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: pr0xylife
Abuse complaint sent (?): Yes (2023-03-14 10:39:06 UTC to abuse{at}simplecloud[dot]ru)
Takedown time:5 days, 9 hours, 37 minutes Bad (down since 2023-03-19 20:16:24 UTC)
Tags:dll emotet link epoch5 heodo link zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-15KhrLv2.zipzip 893d4943146db4f539aa2366c4f2fca98fc628d540589254c8ab86d764fed8b0n/a Heodo
2023-03-157IEM5asnMIFMmn.zipzip d8c38c1a4ee9198e568bb70296632e50c6e8a8f1d7714838c0e1440a47ef9d5an/a Heodo
2023-03-15pSeOaYkiBF4SmpU.zipzip c631a9dd14ca4ddf2b94b5541e749e0595767bcc9cb581466e597230ea9834ebn/a Heodo
2023-03-15jMwIuo.zipzip 8160966529f7a3cb532bfeeb331d34670bbee834dcaefcd77a76f7bd47ca3ca5n/a Heodo
2023-03-14HvZIr.zipzip 670416298bf65b798bbf1195a4b235ed579e1c96cae6628e1a2d9fde1a2858ddn/a Heodo
2023-03-14m4oqbnyhl.zipzip d657cc8c2fbff96e1c3fdf9474878f1b0e5e6d5d4284bfbd6345822e10bec87aVirustotal results 9.84% Heodo
2023-03-14kVx5.zipzip 44ecbc3d9a52b4af26daac6c091026d51f7d00403d7574ac1ebcb604dc66b725n/a Heodo
2023-03-14LWAH55z.zipzip bcc355d65dedb5e97a3784bf66e8a3882444e600a9ccd19c6934855f032cde0dn/a Heodo
2023-03-143U1yVWmHkSrfn5.zipzip 1f3637d31d17d996f4379866eb06ef9b96ca97cff179c931c1fb969f3b9a5ae7n/a Heodo
2023-03-14w62utVLeAA.zipzip f5dc4943c4a24fcdf13937b0a6e484b90955ac80bf874483785a25cc82d164c6n/a Heodo
2023-03-14Jpe0eBJkwfW.zipzip a9de2a7fb170756cdeff00a4ed19574ffaaf1d59383728002390c8784764912fVirustotal results 10.00% Heodo
2023-03-14RtIJ4o64JEm4uIFp.zipzip 498c4a7c1c1ad66267c35639ed643dfd17922febec4360fcaf5459c06359093fn/aHeodo