URLhaus Database

You are currently viewing the URLhaus database entry for http://memoria.od.ua/wp-admin/GbLB2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:944032
URL: http://memoria.od.ua/wp-admin/GbLB2/
URL Status:Offline
Host: memoria.od.ua
Date added:2020-12-28 21:05:07 UTC
Last online:2020-12-29 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-28 21:06:15 UTC to network{at}abuse[dot]team)
Takedown time:12 hours, 38 minutes Good (down since 2020-12-29 09:44:23 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-29HX.dlldll 8dde8e96822c3ead6bf851b8e9d8e1f44abcbf576e3fb2b3f1c5145f7dfd7bc1Virustotal results 28.99% Heodo
2020-12-291xDKG9h5T3gbEq3x.dlldll b4da253445e3cded2f79779607743d057c118672d4077fcc2aad081f149cc48bVirustotal results 24.62% Heodo
2020-12-29V18.dlldll 43656bf9c73bb89dea806a7212a87ba4ccce91a5ff13e170e4f6f7ac6eb810e0Virustotal results 27.54% Heodo
2020-12-29y2emC4x.dlldll 3ed67c89c8a1aea33eb6bd07dfb34832327154f800e9dbe64a2116091c7ea6ffn/a Heodo
2020-12-29M97sgWcxK0EjH.dlldll 243dcd5509dc3e4a1f5362d94757c3a296474c21331e856a9d238d3c3f11aa47Virustotal results 5.71% Heodo
2020-12-297H7FvdPVVjydnBPejnyq.dlldll a6284f860916852edede1e97c9343017f78bc93309db89c517880e1e005b08bfn/a Heodo
2020-12-29cFfFdrAWHR.dlldll 920f31292bd09bbe10e3ad5f02a7477774bdb73670e682a91b2e4820f84d2c0cn/aHeodo
2020-12-28AgGpQc.dlldll 518e3dadbc77e6141958d74953334296be5d735366429fe96e85f289512feaccn/a Heodo
2020-12-28Y61AImLdpjlt2zOZj.dlldll 1af9c318905043c6a6c5e29e54fe542afc87ab9439050bdd533112525423abdbVirustotal results 7.14% Heodo
2020-12-28AlRiZ7MMO8YkZpB.dlldll 6691d2a96a8e71dcf6ee6cd35e1c45caff076340ceb2f7d3e0bbf84823666ab1Virustotal results 7.25% Heodo
2020-12-28gGA.dlldll c7467352ef4a46e75be07e79c6f32ba814e03736a6d00c01aeeeeb7ed1dd8923n/a Heodo
2020-12-287cM.dlldll 38863fb5fe531414f0e1ffa52a4da5550e0cf21d227890aef8a5a80f39d982beVirustotal results 7.14% Heodo
2020-12-28JLjmjjurIy3.dlldll 3ef2249c512db07fb077ccfdb3bfa3f3cf5de5f7784d27855ff6963e2dba6fe3Virustotal results 11.43% Heodo
2020-12-28dFducDJnRTACskN.dlldll 55d068ca410f026cf73b198e5627c88ca182356b95230b4f7bcdc5479b2ec7e2n/a Heodo
2020-12-28dC3H.dlldll 3829deb06b411fa911debfd715732fa832d636d8b3806e71ae057fb9ca123423Virustotal results 11.43% Heodo
2020-12-289.dlldll bf051891d0ccc5bfdce31ba5cb84adc9890e3e992b8bb8dc8a9ce9f5ffe2748bVirustotal results 10.00% Heodo
2020-12-28tezR2rBqkExw0Q.dlldll 9022c213df4695a4cff09a601ad4badb96d355d71de526288c833a12220626adn/a Heodo
2020-12-28DJudt8StxaUi.dlldll e2dc392e48c80da559934c785c84a86703b8200d03ec258c755d7e16ffc0f9dfn/a Heodo
2020-12-28NsEC1j.dlldll 918f65c306f63670f9296d6d877f1ee8998bc389df9bea7ff018a527a317d2efn/a Heodo