URLhaus Database

You are currently viewing the URLhaus database entry for https://www.ummahstars.com/app_old_may_2018/assets/Help/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:949349
URL: https://www.ummahstars.com/app_old_may_2018/assets/Help/
URL Status:Offline
Host: www.ummahstars.com
Date added:2021-01-05 09:12:05 UTC
Last online:2021-01-07 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-05 09:14:04 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 12 hours, 57 minutes Poor (down since 2021-01-07 22:11:06 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-07nEe1j9mCXnUlp0bXx902.dlldll 48e3e0a6a271a714b78a427f0fbf502301b45f9b041bf73e6d42f3606d723889Virustotal results 59.09% Heodo
2021-01-06SVNNnIV4ljQ3OONJ.dlldll 425d210ca1ee6d8b1707845fa3e4dd1e5e27d4c7bc2d692817688c4ed843d0den/a Heodo
2021-01-066ITxkYsK.dlldll bb72a0feeba080f6891dc9acc7e2eabc015317fe5424b1f666c04e4fb651d8a5n/a Heodo
2021-01-064qteLfMyugglr1tw.dlldll bb71b1a7c3db5dbb93b74ab639c48e17d2b3fd0ef6f501cd75429beff8edcb82n/a Heodo
2021-01-06ijjli7UwBV.dlldll 27c728065e3c54f0fd0ea3eb1c6cfe988bbafbb20a6baffe976283c41f78880fn/a Heodo
2021-01-06AOFd84Mecu0k0Q.dlldll 002cfe7e6cc2fcb1b66c737d1f0fb0e5ddb878e70d687fb2518b04c8bb1616b0n/a Heodo
2021-01-06HtfR.dlldll c79903a3e3f2926c5998134aead720aa8078451799b0cc05ad4a538037eb9237n/a Heodo
2021-01-066F4xxYIyoTGEU7EW2yt.dlldll 1758928852434e116973182133175e1a37a8a808758383113e5f3c435ffc8068n/a Heodo
2021-01-06YEhqjg.dlldll dcb0bd262c941356c7a02afc915f7525c7f5d4443ae4671ea7a65f7b11155565n/a Heodo
2021-01-06Uky0cxJICR4k.dlldll bbddf79a38602f3d2657b8db80fb3c609f9cf5f42932af6f7e76f642c8b05b64Virustotal results 38.57% Heodo
2021-01-06THHY.dlldll 6aad7a99b5f43328f7d034e48d8a8ef784f4a25c084850515bb1ee4d522250f1n/a Heodo
2021-01-06w79oskvqwBb7UJfx.dlldll c44b7ca538cbe3d78bb898f5f3267a71c568bd6cad21e95453d58d88fce80edfn/a Heodo
2021-01-05xZAK9MIFS0xi1.dlldll d8b08ae67f5807a63c4ffc461ec566bb918b1fbbb91920ae29f29384d3af403fn/a Heodo
2021-01-05LUwcmrGjELM5bo4.dlldll 1998886524fbdd24332d27304f61bcc61b1932a7196ea96930e6a0d18540e83an/a Heodo
2021-01-05zP8rXQHNNnjDq.dlldll e847b0e5fd86a2a0be07813b1b0590a9973b5f9e2c2999d7e214b2a4771628beVirustotal results 34.78% Heodo
2021-01-053sd7e64jzePeKl.dlldll 9f06509657df4983057639fe333abbf07153fc542495edd4f1a73dfc5144a843n/a Heodo
2021-01-05763Pzv5gpZqIvB.dlldll 258ecf87c0223bdc83fc25a1ff969d2540eac7548de3e2eadb80577064705725n/a Heodo
2021-01-058ANkktzD2FN.dlldll 60a5bb9f7c8174df1b4830cb65ba86c664c7fb884d76f774c505c90f66510fa4n/a Heodo
2021-01-051FNfVlT.dlldll 2fe4389b8a92530e380bf975f3ab83c4f1aa5508da3b58567949cd9c0cd3be20n/a Heodo
2021-01-05us.dlldll 1d1e7c5843f444e611e0b7cf3f7b2c954c7bdd75047b7b5ed0fd4aa23398b9dfn/a Heodo
2021-01-056i0eT4BuXC.dlldll 4544871a3e697251bc802007bb778e35f942491d4b0a8bde99c7bc9d65a857f2n/a Heodo
2021-01-05obpZ.dlldll dd6293a300d0bb2317897da940050def44a0c292f08b26ab7c7338e4edf60befn/a Heodo
2021-01-05xYBZYtdf4Wg5.dlldll 833c8e34b5a805bc1ff049a10134e5f5142a5b86e5e78856bf38ba0cc8371f0dn/a Heodo
2021-01-05dsF4g.dlldll 78f3d3ca83034abba251e96cdb0de7ff6449926424f879cdd34d12118ed47d50n/a Heodo
2021-01-05FzJP4pHpZy7.dlldll eba807f99ef590880ae86fb752d02a157bb5596736f786bd2b1f9a85e75f30b0n/a Heodo
2021-01-05tRbL.dlldll e36e813df968b6ece28af4a8ebb4dca2ef63ea7d8d0ff7749e6d929f39b6cb4bn/a Heodo
2021-01-05K144WoA3fRk.dlldll f2f3dbd4c281bb6e8a11c1404bc94355d3b8ec6bbfda640ba68a05175fbac9d1Virustotal results 24.64% Heodo
2021-01-05C.dlldll 8dbb3a00709daa860bbc0da5ab8c1d7b8f45c0d63c6d8678d3aea0b9c138ceb7n/a Heodo
2021-01-05unLbd2Hx.dlldll da73ed17f12c1ec3bf83f7defc5ee6cf051350f484c8f01f393f210bc361896fVirustotal results 24.64% Heodo
2021-01-05QOThqzeh4M086AtANM.dlldll 7a9cf77db8105923d2cbde050d890d0170b6304f4d05ec38982484fe43ae4bb0n/a Heodo
2021-01-05uHvpYCLR.dlldll 839446caa994d09a27175393bb962f28fa3f8d02fc8901d166b6178404af3e42n/a Heodo
2021-01-05e1rs2XQV3yCHWbkUm.dlldll 6ac3f0ffb527be6e98d0bd727099a6d8e123f608080df64324026904778ac7e5n/a Heodo
2021-01-05jc2N.dlldll 30432c729ddb0c52a07ac1215aea32db911af962bec32e04edcd355afd2b57b4n/a Heodo
2021-01-05wcveiBZ.dlldll b497bed7709a1f41c4d30fd592e71411689f52fd6261d429713113d3c4568cc4Virustotal results 17.14% Heodo
2021-01-05tUSHI4fH2.dlldll 7ee625df1018208f68c081644967c7fcd48651856bb8f1d08d576f0173b3b78dn/a Heodo
2021-01-05HaiEL160szhiBAN.dlldll 399eacf2130c533775b6e955840d18e001aab1be04356b688f7e4a68aa525e87Virustotal results 13.04% Heodo
2021-01-05aw.dlldll 82d55d7be8e82b0dc30c5086566bea3ddf05c8154feef99a2708a0fa47883a18n/a Heodo
2021-01-05YYA2ZF.dlldll 31e6ca24d2134136f8323846cdeec4974c5b613f63c5ff3025e95a0eec004b62Virustotal results 13.04% Heodo
2021-01-05SRgRfZb3oO1R4AGJu.dlldll 112ab4e08739b062d5bd619b287e994b2a5832e4afd9c1cc07889bb23e990d25n/a Heodo
2021-01-05HZYrMOrYLtA8.dlldll b00d66174767f68788e33040cfaf7b06fa5f80456769a53bade4c2eb408fb86an/a Heodo
2021-01-05fdXsLaI.dlldll a6c95fd59a61e28de79af17a764171bc6e1f94650e542ea8d377effeaee32306n/a Heodo
2021-01-05s9tQyuFuKN2HoFIUV.dlldll 690617c151c3fb84ac35844dd012a85c462219c70eb26c5dcc98bec98c3df15an/a Heodo
2021-01-05ZTVvXlz679DrEZ7riJu.dlldll 267763a28114e9029551a53d56cdc27d856391f1c4f9ee0629791a7237ad3241n/a Heodo
2021-01-05VVbtHceH4dxGHl.dlldll 58c1f4bb7814f93316f3affde7b0a382dd6c8b157b378e558b5e8fc8c0513a48n/a Heodo
2021-01-05PeywY4iL0KsM.dlldll e6c57775ebb2077b748597d78e1e5695c1ec6b1ec9d46a8f09f2a2d8c6f495dfn/a Heodo
2021-01-052quMJO7FOGO.dlldll f7e7e75f437c342283c8cb781451f1ac9cc3f1e289db1534f7660c00d6830e1bn/a Heodo