URLhaus Database

You are currently viewing the URLhaus database entry for https://pellesbar.co.il/wp-content/microsoft/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:936580
URL: https://pellesbar.co.il/wp-content/microsoft/
URL Status:Offline
Host: pellesbar.co.il
Date added:2020-12-21 23:25:09 UTC
Last online:2020-12-22 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-21 23:26:17 UTC to abuse{at}isoc[dot]org[dot]il)
Takedown time:4 hours, 54 minutes Good (down since 2020-12-22 04:21:15 UTC)
Tags:dll emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-22V90pIsAusYG2pNjA.dlldll 2332978cfc3cded1b5c068cbe40328303a1947b71d147b383ed5f18a021882c6n/a Heodo
2020-12-22GJWuQe.dlldll 9b03fc0f2a3395580255cc9b03f7f5d6d8563ca7b1d6760c61dd8b228ffb0161n/a Heodo
2020-12-22Nsp.dlldll 6f665b13ba7c4e6652ff691d92b1e222cd834fd45c5be579d0ad6138df451513n/a Heodo
2020-12-22Nbx58x86bbwPtqs.dlldll 79d3ce9c3c082474b71f90cbd1eef270822f9a197ecf0fb5df4dae9a9f458c1cn/a Heodo
2020-12-22Jj2qjjgz9FZ.dlldll d09290d5f9a33936e428fa24781bb7bb3bd0b2a45f6b71ebe7ab67cd93a5d8b5n/a Heodo
2020-12-22hyX.dlldll 94e18d9eb2d445b4c1b5caf0906bf6af9ddbf48055b2bc7dc954c1f1ab072bd7n/a Heodo
2020-12-22L1P34lBcNe2q33XgX5zM.dlldll 903150bae07199d4b3369d3d5b71a95e038ab3f496aab4c10460b9059a068f99n/a Heodo
2020-12-226QRK.dlldll c5223396ec7dc752ee4dcc5c1b31bd28ac8cef3e2fa71f9bdbe2601f41d868d8Virustotal results 17.14%Heodo
2020-12-21cpBR2j4nvuJW4.dlldll 099ac6a94149a85422045b71a8d4758e2383bea35e073b3556302aecea89b4ffn/a Heodo
2020-12-21XXJAtVUvGS.dlldll e25763367de948a52bd812d0c4a7f56807f3d5c34a9bdf8b743374774ce22535n/a Heodo