URLhaus Database

You are currently viewing the URLhaus database entry for http://205.185.125.104/files/july22.dll which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417903
URL: http://205.185.125.104/files/july22.dll
URL Status:Offline
Host: 205.185.125.104
Date added:2020-07-22 16:58:08 UTC
Last online:2020-07-27 16:XX:XX UTC
Threat:Malware download Malware download
Reporter: malware_traffic
Abuse complaint sent (?): Yes (2020-07-22 17:00:05 UTC to admin{at}frantech[dot]ca,fdias{at}frantech[dot]ca)
Takedown time:4 days, 23 hours, 6 minutes Bad (down since 2020-07-27 16:06:22 UTC)
Tags:dll IcedID link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-24n/adll c1532b3d37ff2ec7d70d7f8037b8cdf843d3cdd24adf860f4251d045ddf9d47cn/aZLoader
2020-07-23n/adll a5ec2f495c117f199e1cecc1e2c9e5ad7f4f8241eb0784bb82da89c5ac88778bn/a 
2020-07-23n/adll 28a4011b7fc954f2313e994dc4324973d544cd252f46cd4ff7bad4f901334fd7n/a 
2020-07-23n/adll 59a1f6f4f2bb74e60bfa403ce0b66064451cc1ee6fff6d0eb43c8de4813801bfn/a 
2020-07-22n/adll fa09c9ab2f3fc8d3c6541cb835769792d6bc041ba5aa1d04a22be1608791ad9en/aIcedID
2020-07-22n/adll ee37f2e951c050965f1936445bfbea0e6c0a59c2f30063292810e2beb5489a22Virustotal results 12.68% 
2020-07-22n/adll 78cfbb4367808a9be2b5748668389b83298965ad44ec477dc39a26c3b36f8e81n/a