URLhaus Database

You are currently viewing the URLhaus database entry for https://alabamaballdrop.com/wp-includes/kef1U/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:943762
URL: https://alabamaballdrop.com/wp-includes/kef1U/
URL Status:Offline
Host: alabamaballdrop.com
Date added:2020-12-28 16:34:11 UTC
Last online:2020-12-28 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-28 16:36:04 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:3 hours, 9 minutes Good (down since 2020-12-28 19:45:29 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-28JZaW.dlldll 6d0446ee0de012131c1e9eaa4728687abae2acba7bafc3d0ab6856db9423abb6n/a Heodo
2020-12-28F7fozBa0gwgoWaTM4MIn.dlldll 11871a4871fa3cac7f4acb65dc974e62f7e0793f4b162488b5df80a13e92b2f3n/a Heodo
2020-12-288ZhwXzG.dlldll f3d3d68a04a4b8680fb154cc2356b6c11aa52fb53b0087cbc49e66887d9ca8dan/a Heodo
2020-12-28PIm2GsjAIJUnXPQRxfU.dlldll 049da9f5994c464f37d44dd7785625737a9aa71739d35bcac988d4f48450331bn/a Heodo
2020-12-284jvxyow.dlldll c4566dc0af1ff866cef03dd9ee06f196a7f8f48695d55a766b8305e885ba6d0cn/a Heodo
2020-12-28BuX.dlldll b7ff4ac810e0bf243ec2e6ffb80f708b4388329ed169c51a1ea024336c4cc89en/a Heodo
2020-12-28IlkxS3C58gS.dlldll 01f0108d594c02fe6fa9d16365e755ffb5ecdc1d44a7b0ef23166dd2668c1013n/a Heodo
2020-12-28ehXQMHp9CusVlLn1uZe.dlldll 0e777b67c31af7520c2c5df8265b00c5596138f751d9796b03007c296009a8b6n/a Heodo
2020-12-28w.dlldll 3ea3463d38db4d1f523227dd2450b7b67f38c75925f904ceee8f66aed17a7081Virustotal results 7.58% Heodo
2020-12-28MTnzSIJm7JY.dlldll 4a723fdc060109209d0e4c07917bee72c1132c6f1f6d9fcf028d9c2322db6327n/a Heodo
2020-12-289Taj.dlldll 8201913204e5259b399f719adf3213311edc9eea3f4ce45bc7a88dd5947b06d8n/a Heodo
2020-12-28S76a7VnK6d8nSW9DDnOW2.dlldll 88c2df84e32cdd42a045b3da9749f9cf28960fe8a118aa050bbc8669ade8a6d0n/a Heodo
2020-12-28644n6N6MiKS.dlldll 9fa0a8eb2bdff9514eb9a506ac94c1bc9a241e6de48378327caaf8304a2d2e73n/a Heodo
2020-12-282nlK2SvWatk.dlldll 2d47e5ea99ed6926020aabcefca373f20e5c20de952d302d9d3852524353e640Virustotal results 8.57% Heodo
2020-12-28sLt3q2sKPfSa3Ip88b9Y.dlldll 3ad3038e67627089f1ac5118cbff3d7706d49a8587121f7a92fe7753dff0c4c4n/a Heodo
2020-12-28LDpgcbaLMqtfCJxfIchJa.dlldll 3cf5a2cdc11a161bdf3c6e732f0df7627f345d7e16d1b8b22411ed361538cdf8n/aHeodo
2020-12-28LtUE3.dlldll 444ffb8647d113aa531a1e319ddf728a82b33e9d4dbf3ae66c24c12fce8d5c59n/a Heodo