URLhaus Database

You are currently viewing the URLhaus database entry for http://paulscomputing.com/CraigsMagicSquare/csrJgJZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:944870
URL: http://paulscomputing.com/CraigsMagicSquare/csrJgJZ/
URL Status:Offline
Host: paulscomputing.com
Date added:2020-12-29 20:30:08 UTC
Last online:2021-03-01 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2020-12-29 20:36:02 UTC to abuse{at}he[dot]net)
Takedown time:2 months, 2 days, 0 hours, 49 minutes Bad (down since 2021-03-01 21:25:24 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-0148V8gNoqPdPvAN9SZPQ.dlldll 4b83f590891848f16b5e5d34440289917220f3b8dd71ab58dde4150ae78d5034Virustotal results 49.28% Heodo
2020-12-312BKBQcEeUbdZLrEq7vFPM.dlldll b72a3db712dce766f5cef90799d2a8e22fd18d572ac80cbaccc63c8dd9772ee0n/a Heodo
2020-12-31WsNm20CK.dlldll b474a55c19699f6c33dc687577bf4ff282ec832184118026ae90315251270727n/a Heodo
2020-12-312R7n3KptdmJwhO.dlldll bc7477c9aa3c375dd6d8fb48efbb6034339d7d2ebe85146ce1ca4c350af03038n/a Heodo
2020-12-31p9n4tBNqtyXJ9B.dlldll e743b5e93372f5d541bea6a00e5f1b0499b3151ce5f9065440b237616299dd70n/a Heodo
2020-12-31161OEZWtX3hTWZXdmOlEtAX.dlldll dc6763089cb565849770639155b3acba5cd83f730986029d2eaac430ca8e988an/a Heodo
2020-12-314AlBStQbYlVn.dlldll fb2f20da48ca2fda7b3007d8c540573eb49534348e6b35b48d476dce86c63df6n/a Heodo
2020-12-30gkpsskGpa7g5rz6JP0nkTdS.dlldll 4853ad7ae7b3177309bcfdc89e65d9cbb50a2a7d1d84c552d845071070461199n/a Heodo
2020-12-29Z8r.dlldll 17452342262f0f401bda459a3716af7ef1e1be3ca528f0d4210b04d2c8b5e95bn/a Heodo
2020-12-29LOZmyhzf3LhddUNXwUIQ.dlldll a3688d882a569851894c1017323ae75cc9cd210cac7a72a64d05a2500604f4bbn/a Heodo
2020-12-298KZ8mPkJa0pgq7L8abOHa.dlldll 22fc733981981e20d1e83af1a742442519ec7bc32b98b4a8f4768cbb69fa5e02Virustotal results 21.74% Heodo
2020-12-29Gr.dlldll 21f9565bceb24cf55d24afa0c2adbb6469c31f993665e0600b557b3fc858c566n/a Heodo
2020-12-294Vh3wiyV.dlldll d70ea674cc4e22b2c915a1c5ec7e79a6308a612e77e6754add55ba0bca28a744n/a Heodo