URLhaus Database

You are currently viewing the URLhaus database entry for http://members.nlbformula.com/cgi-bin/vazlwkU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:944468
URL: http://members.nlbformula.com/cgi-bin/vazlwkU/
URL Status:Offline
Host: members.nlbformula.com
Date added:2020-12-29 10:39:04 UTC
Last online:2021-01-05 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2020-12-29 10:40:08 UTC to abuse{at}liquidweb[dot]com)
Takedown time:6 days, 20 hours, 17 minutes Bad (down since 2021-01-05 06:57:08 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-01xtu21B4Y4gtC3lUUQOxAU.dlldll 72200f1829c2e5df537bb7ef57a1a7c863b7b1553bfca02bc09ebb508256c2f6Virustotal results 8.57% Heodo
2020-12-29ZZ2UPpxQFiM6PA.dlldll 10736083e82db6367a75a7fb0dc2860cacd1e17828bd4fd1e05a592d0b37a39an/a Heodo
2020-12-29jmfkNSMS6s22D8bSCjxOdd2.dlldll 1c6aa8a98f24cd667ca83c18b834266869d9313a8089363f7c784329c267c6c9n/a Heodo
2020-12-29JiI868.dlldll df6e0bab8e6b6d3fdb17cc177c32693a79bdfd41f48fb62d582e6d785a92d88en/a Heodo
2020-12-2906UC.dlldll f0f316ca64087a046543c0f51c201b1f0f41a734d8a3a83aa69b8923f0dd6792n/a Heodo
2020-12-29l6O6.dlldll 37756783074ed94b95274084149a0cfaf5e13ca681a3c2195b5b0220bdf36c6an/a Heodo
2020-12-29ZtyeKNB6ESLJWtYfDVFU.dlldll 67b951f595cf462c41c50962491b17d524cdc3418c82116a177d9b602a99de0an/a Heodo
2020-12-29uumAWc4ss7qYuHjB.dlldll 07e4cecd120c63189b2ac8bccf39937ab53a46979f8f0d219526990de015d333n/a Heodo
2020-12-290n9J.dlldll 8f901be69d6a7ed3b3bf6d356d5d131f9c5c717a5510af3259ece7973be9338dVirustotal results 8.57% Heodo
2020-12-29XAUe7c.dlldll 23a1ba8b7d5de9fd8a02b63af2a95182998accbb58f046288e06eadb9d912ba7n/a Heodo
2020-12-29aTeMTj4UOmb5Q.dlldll c04252749a6949935275633fe7950808971332a8c49d36a6a72b48d1846717bfn/a Heodo
2020-12-29CD0fc.dlldll 600881b0123f0ee1c4fe7ee3ca21a933f63b5727a4de8e72c9f82ccb3ad9c1edn/a Heodo
2020-12-29DjzK2oZyeDBl8vR86l2.dlldll 30dd0e6e0b639317d017384a7fe9aaffdceb4d35233ef116ff3210c1cf142219n/a Heodo
2020-12-29NhEI.dlldll 8338392f5f27454254313c7e8c0b89a777fb6a65d03f8576370d1651f601a339n/a Heodo