URLhaus Database

You are currently viewing the URLhaus database entry for https://ownitconsignment.com/files/b/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:937137
URL: https://ownitconsignment.com/files/b/
URL Status:Offline
Host: ownitconsignment.com
Date added:2020-12-22 04:29:04 UTC
Last online:2020-12-22 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-22 04:30:22 UTC to abuse{at}a2hosting[dot]com)
Takedown time:8 hours, 7 minutes Good (down since 2020-12-22 12:38:19 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-22J4V3sXk.dlldll a83f8ff105bd97c21f3c8e3977409fc798dc871a3122002a43c033c5e8f00f9fVirustotal results 33.33% Heodo
2020-12-22R5IYWG.dlldll cf44125e3643ade1e1d6ab335bce07c2e9ef1345e7257fd041e6452281aa5055n/a Heodo
2020-12-22Z6VKQle.dlldll 88ce1f7fd22aaa6ccd3e1574f7cfd06ee01ab3c506f860eff394cd749390cee6n/a Heodo
2020-12-22TcooNz3DYdjcBQQuaCCz.dlldll e774bee19fc63b49ef885ad7e09b518eb708943689d207a1816ab5adedabd5d2Virustotal results 30.00% Heodo
2020-12-224YOyl.dlldll 03684c2a8d35c0345073e7290f6996f703b8b7956593790f98888087bbb1e361n/a Heodo
2020-12-22KgpRiJYZtLZQQoB.dlldll b2e1e1d2a7a03f57653fe49058db3b161af5153fe8ef93909d989889fd456c9dn/a Heodo
2020-12-220cc0t2FM.dlldll 9ca02addf9f9899acb7493e566e3aebb30e9f15e865d8947a7fb2c8b10f51299n/a Heodo
2020-12-22lmqfhTgaMrVv3K.dlldll 8fb6be0814a7c995aeef0fbb796fbee5e81a04828a399b30253b86b56a40a63dn/a Heodo
2020-12-22uLD9z83X.dlldll fc173c762bfe09191de4df58c28ed34afbd221130128ea0c9b0c750a17e4bd32n/a Heodo
2020-12-22cFfKYfp.dlldll 1487492ae34ccef495d4c035ec64c396caadb5ba6ef049f093a03f5a879babc6Virustotal results 22.06% Heodo
2020-12-22cj.dlldll c10a70bcd968d0a10a118a3a0002a613f0bc17c5f45a8896f4b54891e9d74e12Virustotal results 18.57% Heodo
2020-12-22kLDFFzcRxFVIYIRLtQ.dlldll 84e7ca64fa1dfcefc92c5701097ab1604fb358bf2c7cd6296a42a194de54e1a1Virustotal results 17.14% Heodo
2020-12-22Y2uyF.dlldll f0686a89a847ebbe6dba32e7e3de626e2e400987bf06ad180fb6dec7c29d8ffaVirustotal results 17.39% Heodo
2020-12-224KruulVNLGrZ.dlldll 9ba85b10f6ed0a559e8f8cbbdb40927397c086b2a7cbdcf17964ba9617d3bd6en/a Heodo
2020-12-22VwnpU7I2DDG65DK2rTM.dlldll 08657030c00bb6b8a0321e51273404467beac76ad60825c15a51fc8ee8f3b8aaVirustotal results 37.14% Heodo