URLhaus Database

You are currently viewing the URLhaus database entry for http://drwalidabdelgaffar.com/dentalia/lL/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:702102
URL: http://drwalidabdelgaffar.com/dentalia/lL/
URL Status:Offline
Host: drwalidabdelgaffar.com
Date added:2020-10-16 13:38:07 UTC
Last online:2020-11-09 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 13:40:20 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:23 days, 16 hours, 39 minutes Bad (down since 2020-11-09 06:19:29 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17XsKGarcANj.exeexe 7a25db35bdc5806245a3031842444a28732394c3ba2badab6014dc3b4f48890bVirustotal results 21.43% Heodo
2020-10-17asep.exeexe 09bf94c23b331219dd96d62bd300721038076a252eb7fb282f0f11cf9fc59bb7n/a Heodo
2020-10-17IiMnx.exeexe 4d5d65357da0c96c5469fc5820cae1bc48d2d3fa8bed609fdfda491ddcdf4bfdn/a Heodo
2020-10-17ZZIjjAS.exeexe ce73ae3f3f44323652eee9356096bc9c116a61989d4193763a7fb76eb57a04edn/a Heodo
2020-10-17yfhJyprQg.exeexe ba104d4faa24dc3e92595a5d3e9a9c15c101d0e27b9d6fe5d1a473fb3b604c32Virustotal results 20.00% Heodo
2020-10-17josbNE.exeexe e3d0ae08249a111ec0569643f370ef8f213dd45d2077a3e2ecc8ab9f996e724bVirustotal results 20.29% Heodo
2020-10-17C2cO.exeexe 07a36a19007f7512328070cd58de577248580abf5ff3b5c58a46e9eb02b81a42Virustotal results 18.84% Heodo
2020-10-167S6T.exeexe 8606b356d232487a686abea871d37002a40c53c7934172421b7e5338b349892dn/a Heodo
2020-10-16ier.exeexe 59be49b69bcb9157c8d42b6c56b714f603889199038b1488a3d7deff5237aa59n/a Heodo
2020-10-16h4KTh7unQY5LkeS9EyGl.exeexe be6488193677de8c7566e45e9e6ff649f2428e3a4569032a8a8bf9e8d53a22c0Virustotal results 26.76% Heodo
2020-10-16QPVXPJ13a29YJQWrQG.exeexe 1ff092ec49896ccfb8fc53db21546fbf2d857014c089b1368ff686a4130b486an/a Heodo
2020-10-16rd7O2HSgo.exeexe 1d8393097751acc49f63a8a3e86b6b52a994e8c80eb999cbabe354466dd0c7f0Virustotal results 25.35% Heodo
2020-10-16b3Xc9s.exeexe 661152f3934c718701b79958c7ac579eb5f6d64d0d6701facbef46aec6662d60Virustotal results 25.35% Heodo
2020-10-16ZO6SMAfURnmQJHgbs1S.exeexe 7ca9883c3f172eea6a81e96bb689531e00e207daec35fdd31bc86eef9c9f2fc4n/a Heodo
2020-10-16gpzWEOU1Qg.exeexe e648652a5bfc6740346671d2971388f599a8fd1acf5d78077bbd0661bd17cd32n/aHeodo
2020-10-163JZopPpcXvzFIKndADt.exeexe c356d5c9057bff7fa6bf3ccc728112615a783cb07ef5b16ec0cf6660580bc9c9n/a Heodo
2020-10-16WbaMHlqCNLq6fX.exeexe 137fe75cfa0213a562daeef603c87423d18590af10320ddaa1fa6e1fc16e2707n/a Heodo
2020-10-164Ve3EoU3vTDLiBqWcyzo.exeexe bb2e603dbdf653857451aac908195e1c3533aac880933bce261ce0bcc265760cn/a Heodo