URLhaus Database

You are currently viewing the URLhaus database entry for http://zenithcampus.com/l/yQ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:937535
URL: http://zenithcampus.com/l/yQ/
URL Status:Offline
Host: zenithcampus.com
Date added:2020-12-22 07:37:05 UTC
Last online:2020-12-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2020-12-22 07:38:11 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:9 hours, 38 minutes Good (down since 2020-12-22 17:16:21 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-22vuN.dlldll 470a8a5c6b3327b1eff6a4d47556a8ec1c05c868b979a982872be8bf4279270fVirustotal results 14.29%Heodo
2020-12-223GUmOE.dlldll 624e98e953aa371cca55d10692e1c800904ed3f364c98900e0e9b96bbc2e3aa1Virustotal results 36.23% Heodo
2020-12-22Oow7LHVIoFfAnyJSvNw0Y.dlldll 11ee0b0de0bedc1e7939286b7a57e80b3496b1880c9780188f4ab25b902e70a3n/a Heodo
2020-12-22Jo6E0Lmjh3Kz5ie3P2RQA.dlldll 09f04287d408aacb330323d421006ca29108293ebd84bf1c39f6bfbe7453043aVirustotal results 33.82% Heodo
2020-12-22OIliipUvGjLqt.dlldll def01122e051b79de812c18d486b133e7a3821a8b300d2badc61b588d7b89607Virustotal results 34.33% Heodo
2020-12-22JOky7o2B2f.dlldll 645496bfaee93c18028224db1be7a13d7b6d6b2eb07a9fcc33ebaebd6afa1f04n/a Heodo
2020-12-22cf5aKuokE3.dlldll 205b8bf5627f0eedb77b1046d1bb65c0bb73b44fa1b4d5739a1148fdb94653d6Virustotal results 33.33% Heodo
2020-12-22nFH6Lq17lTcOZ.dlldll 579c9e483c1f20964e47fc4ebd938b879320edf99a9ab9e70531a5531e467af2n/a Heodo
2020-12-22r4oTLspePSTzO.dlldll 67ddb6c43ef34eb80947337e8f1d908984cfccda867b8281d5108e1e2ed712e6Virustotal results 31.88% Heodo
2020-12-22dnTDMrdr.dlldll 7ae431a7af0152d4ddd11311b2ad60ba6ec1fb4429015c87c62cf3920e1617b4Virustotal results 31.88% Heodo
2020-12-22TNfPOkWpAc.dlldll abe84d12d77dec85b418b20ac0ea7cf3fe1f2c7a7dc5a90cb9f4202a10087b4cn/a Heodo
2020-12-22yEXIu8VLYgp8Bl2ALEw.dlldll d8a6f2e290476faeb91f9caa6759e6013ff1b5819022a49c20e99605afc309b4n/a Heodo
2020-12-22Zl5llPOaKkIs91XJp5.dlldll 646a9b7319beadd9fc6030ad4a211ca5d05a94d20b06a6a06005dbbe02c9c7ebn/a Heodo
2020-12-2295WJJ1.dlldll 471407ddc0c1307c13f90b208c4d426806514508eb5baff8b75db0cba6d34434n/a Heodo
2020-12-22AM8HoGIKGXc.dlldll da4ee949c8c46e0f6a6dd855af7f6208b568297fdc62fe76cdd3273c6ed50c82n/a Heodo
2020-12-22UwRq3P5WLyf6YdE1OIO.dlldll f4fe5045f065663c40a8eb791609a3d770472bc57eaf779780f157f0e4a9e30cVirustotal results 28.99% Heodo
2020-12-22ocLV.dlldll de5cc3e32b1d749d4d025ddf3a3cbc7e9be4b18aee5cd3c6870c88f41ca35bfcn/a Heodo
2020-12-22M0HkOBaGxcWRu1.dlldll 62b5badc64e2f7e152af49d559c2d12689cac075027b5182482a6906c4786b1cn/a Heodo
2020-12-22EO7kCEEttiwXwsnMOWWh.dlldll fa1a734976f2606e2d0529e364b07360c6d15ce4bfb8cc38aa34cd242302d0a5n/a Heodo
2020-12-22NtsKk.dlldll ea39bc7447d8a1b11a27787b363ed3f38a5ea8d78c1314fe044795f6399806a0n/a Heodo
2020-12-223Ov3q2wwr4nV5pmvY.dlldll f836b530aa0aad30865fdbcebf050871ac1099d17719be35bfd8d163587c090an/a Heodo