URLhaus Database

You are currently viewing the URLhaus database entry for http://darbazi.org.ge/language/iyQMh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2580189
URL: http://darbazi.org.ge/language/iyQMh/
URL Status:Offline
Host: darbazi.org.ge
Date added:2023-03-21 22:08:07 UTC
Last online:2023-05-13 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-03-21 22:09:10 UTC to info{at}serv[dot]ge)
Takedown time:1 month, 22 days, 14 hours, 37 minutes Bad (down since 2023-05-13 12:46:33 UTC)
Tags:dll emotet link epoch4 heodo link zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-23Ljuo55RNY.zipzip d3dd064d5e494ce23acbc3ee95ba094d9257def9c9de61fae0c7eb4e3e374da4n/a 
2023-03-23F7yAapv7FEz3CqtXy3Q5u6ysadTH.zipzip ea903958184fdf9accd344c3db36e7918a91bf5972449c301879a3ee67ba9577n/a Heodo
2023-03-23Rswhebe9Tk83FREncIrYMo55G.zipzip c7a764d32acd9cfbbfef131804cb5c5cdc2bb3fb96bb250bbe9930b8d69b1a4fn/a Heodo
2023-03-23i5MNmI3O6mkes6yfdPh.zipzip 704795218c812e9e22569d60c83e4d53afcd88b056ffc069ceadd19da8fd6d2cn/a Heodo
2023-03-23L21uTAZ.zipzip 68981c3d80d738efef9da7f435edb8cb069667fc3c8a19dea41ed05c44095cabn/a Heodo
2023-03-23ELc2UUSfZT1OHqyxGts.zipzip d6b8432227f1daa325e502519d02ced0de65be49bf003898f1d83cda4fca29d1n/a Heodo
2023-03-22zyP2c8lD0COnmywiSNTruGdRY.zipzip b1120c4a97415607039327346f5017b981469ebed8778f010d83e8d5fd394e3bVirustotal results 13.33% 
2023-03-22lIepk48jyCO9ORDmmcIQxSRFxNbD.zipzip 98ac85e40373cd16f6910cfd4bd092ab15a6eda3b513bd09da39b6a29fcb3504n/a Heodo
2023-03-22TeJsTmh.zipzip 65c582b4af763c0d479bb52e80e2866104115644acb061ad46271606ae71fc56n/a Heodo
2023-03-22n6qTpdO9Vw5fttpUMpz7tSvtFp1F.zipzip c5fc19176e3b7d86b5c7ddaf2f0dd92ac5fa326008cc45eeb813874903e90cedn/a Heodo
2023-03-223XbhF8FqY.zipzip 85a4d72d3b4cc661fe38e69758f6ef221cf10e1a6d2e249e36311de6efe8f2c8n/a Heodo
2023-03-22lWh5oQeDpqvd00fv8x0pL1M1N7.zipzip 7f8e76b4032f73ca0fbc56ff02e6806a5e89794ca39cb8e4a0a1a4269d0556e1n/a Heodo
2023-03-21A4Um5h2EvRiSoMprTt1G.zipzip 71e5b8bcc439d7c28ce77eedbb8416f8934ad7565c1631ec8208a0b2bfc174ean/a Heodo