URLhaus Database

You are currently viewing the URLhaus database entry for http://www.dirgantaratuba.com/cgi-bin/PX4K/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:949590
URL: http://www.dirgantaratuba.com/cgi-bin/PX4K/
URL Status:Offline
Host: www.dirgantaratuba.com
Date added:2021-01-05 18:04:06 UTC
Last online:2021-01-06 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-05 18:06:09 UTC to abuse{at}dhecyber[dot]net[dot]id)
Takedown time:7 hours, 27 minutes Good (down since 2021-01-06 01:33:15 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-062NTgf0uwaUwt5Qfg.dlldll dc508e01ef9764f69f3623877bad6481531a87e0caa2221116ac178315cdbdc8n/a Heodo
2021-01-062K0T6dl8WFlqAc5.dlldll 2a8f85cc572c0e01ac25b24f482b15db229f7650bd3428a7f1eb876897e5ebf0Virustotal results 43.48% Heodo
2021-01-06Sp9f7jyQhjQmyF.dlldll e8e4d258d12910fe7c45e49e10236a2668dae02b399709ca584091c9984f9dcen/a Heodo
2021-01-06uiyEVdv6VQ5.dlldll 888639859121f8157cfca0db3813876d85e58773c5085091fd38a4eb9f8e9d6fn/a Heodo
2021-01-06TMjkiE.dlldll f801b4ce3a206ae53fcf9d61c775a2b98e0bb3919b1f59fcc538b0c700a07897n/a Heodo
2021-01-06OU47D2RPjjGKV4kCXglh.dlldll 62441003f9177dff9266760579f08a9f3cd95e2252bd59d15f03ade2964fb6e1n/a Heodo
2021-01-06Vq.dlldll d887bf8be8f467fdfc08800bdadd04b4e465733ef57df6cf147704c80621fb34n/a Heodo
2021-01-05dGBhZS6FqF.dlldll 9613590ec587a62c30c72a071119c532701570a43664809cc28c781a26fb9e3eVirustotal results 44.29% Heodo
2021-01-05vGTVXjinYdhh5c8HZA.dlldll c4eb81dbe766b8f5505180eb65722b570769cff24874eb6f58ebefbaa8fc23e5n/a Heodo
2021-01-05cVR7XaoZoHwLRgAtzB.dlldll 8f92a0836c39fa7beb0316bd8505b655c1dbcf05e0993342325f56249fb81771n/a Heodo
2021-01-05ACLVwu.dlldll 53fa801d998ba0b1a0e327e33dcc25ee185ed29113a2ff7f45453a5140533bf9Virustotal results 42.86% Heodo
2021-01-05Ss6ZrdpWzrEfpj.dlldll 528c5458a252f762c0c82af7472b48ead91d6c45cfa2f2aa7287c577d1b259e6n/a Heodo
2021-01-05JWBEE.dlldll 69475d88be73443bf9819d19bb9fade7ddc8d30b2ddcbee91bbadcbb91f84eb8n/a Heodo
2021-01-05aOQCAJeBxh.dlldll 4053a84f3afa7a791a00399916ea4bc2b0740e41cfbeb2d709843edd0e0530aen/a Heodo
2021-01-05oI411iM3Vj.dlldll 9992b53640db1a04e10a04ed269a4e8e1586bdfc8c8d6d441cef4af31e042d81n/a Heodo
2021-01-05eTnNLKzKKZin.dlldll 43e8be12ea9ff6012f0bbaa137c02e85b73457c1a860f4746caf43d56cf968feVirustotal results 42.86% Heodo
2021-01-05w.dlldll c0cd63a82c7717c40a84be5f6efd9f876437300c9abefa225d46ce17d4e4d43fVirustotal results 43.48% Heodo
2021-01-055.dlldll a260ae7b6c57f5346792977bfec40daac63b952e98566ff929dcebc47d282638n/a Heodo
2021-01-05wUlSLfGc.dlldll dc2bfb60c2017cf680a88755237392d72eb3ed6e9c710ba67adf5e8dc49d7b55Virustotal results 42.86% Heodo
2021-01-05N3.dlldll edbda216891afed5d072922f9ca84ddffee54a5fa3a59c6d6699deee0a43f0c3n/a Heodo
2021-01-054n.dlldll 5f70262d78f750bd21a7581ba8a0f1b9f4c4bf2f383dd1d4295ec3f96fc6cd5cn/a Heodo
2021-01-05c9.dlldll 2e8cc74bed8459040724d3364e395d5ef24ffa6f6189835ea4a8fe576bbc0acfn/a Heodo
2021-01-05hAd.dlldll 54cd5cd0c2f0c84bee43511044ac57a396407b0ce02225bd0df2d55669e98001Virustotal results 41.43% Heodo
2021-01-05yCF6R44TW.dlldll 36be8ea1762aa9b7272d4f4ec20d7221ff7f83cc537974724fb4199806ae231cn/a Heodo
2021-01-05sPWgg8j8sArZ9LEZ3sW.dlldll 8936ebeef9b1a6db9b011a06cf287844e62c561b25f25711e41ba96c9aaa8906Virustotal results 41.43% Heodo
2021-01-05bndkknOxhSnlT.dlldll 38b1b1340fd7a20ed774901a6af8bed097e3b2e40b12b285996ae6ab164d3326n/a Heodo
2021-01-05bR5k6L.dlldll bf44eb5ff0aaccc7b10a5dfe1c2622e30e58d6847b2b1d286d4fde91a4a3233en/a Heodo
2021-01-05Tu2oM6gLSXmVt.dlldll 7a07c64a0a0888e7b800e4c3be971fbc2a053877bc52a8e801d97007ff577d5eVirustotal results 41.43% Heodo
2021-01-05BBfXCqkZzXtSm2BvHrmcV.dlldll bcbf5fc67a3c78f9dcb491666013cac3de1b3d84b278dea496cabc80568e96a3n/a Heodo
2021-01-05NkhNhjrUnHQq7s6DFsP.dlldll a1df28431be02a03fb1fd960911f43264084f8a70993cdf4436cf1e0755c2481n/a Heodo