URLhaus Database

You are currently viewing the URLhaus database entry for https://lastfrontierstrekking.com/new/2OaabFU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:955632
URL: https://lastfrontierstrekking.com/new/2OaabFU/
URL Status:Offline
Host: lastfrontierstrekking.com
Date added:2021-01-12 16:10:08 UTC
Last online:2021-01-12 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-12 16:12:08 UTC to abuse{at}servercentral[dot]com)
Takedown time:7 hours, 2 minutes Good (down since 2021-01-12 23:14:10 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-12uvM.dlldll d30effa910dbccd624fcc20e41629bb2f12dcd4d62b25d906fdc74c3552a917fn/a Heodo
2021-01-12MawoDGXPcg66BZRSNEMa43T.dlldll 151c396daf368d806a9af523ba307304816163908727cfdfa9f5f3b3ee4d5367n/a Heodo
2021-01-12X4Y77GvWnzX.dlldll b6106b28ad514f4b979f1d3eba57621b5fed2a80ebfeec802c33e747a2cab76eVirustotal results 26.47% Heodo
2021-01-12ewSTBFwgTUe.dlldll c26380822e787b0f89fee3d60115f6f472fef725eedb2d444d4d312215b77b9fVirustotal results 24.29% Heodo
2021-01-12qPAmHqdnQ2At0sm.dlldll e9852e5fc283930adede7c8550406463c8487339a7248ba3f2a66508f6dca495n/a Heodo
2021-01-12IODZEPhl.dlldll 1e51c6268d6bbd3c12b074080a677363a8312d6e404f363ef4fad65aa1a34f74n/a Heodo
2021-01-12YcXVIxWl.dlldll 24cf020c0c4b577833b1e05bcd5f801721f258e58c39e2c67f0b09a350f9b6abVirustotal results 24.64% Heodo
2021-01-12WsJThNC7l0SlD4.dlldll d6e6d48d5bd7e120b7a51d3402b58f45faf262b46c058a1911b038ee3d93c912Virustotal results 25.71% Heodo
2021-01-12rPusHFa0n672WU1.dlldll dafdcc91584db166149b62ffda56bf6d94a84f8dbc358fb18c7b95ba62e36c14Virustotal results 24.64% Heodo
2021-01-12TlbxJputxLT6so.dlldll e2c4f56664040b5187467fb98545120901446db890334c9a52438ccf0ec2368aVirustotal results 23.08% Heodo
2021-01-12fHjtmfb7ekYFjzkseiNP.dlldll d3653a32f0b5abeac2c0e2fdc78897ad096fa0caffc744864a395ce7368a2051n/a Heodo
2021-01-12yun1PzF4O0Pu.dlldll 6534ae73f1ed57f3853956dd534566cfe3dc4ca35c88b7ea0f1d5cd92f2d48ecn/a Heodo
2021-01-12JdId6pRgfCyt6YsxoiQV6A.dlldll 6f664478e62d125cb25f670d76ac445d7442c06bbca36f84f78a16764bc84591n/a Heodo
2021-01-12g5J5rJZiQK6kTUakNf.dlldll 3c8b9f8367c44f237fe3687ab1921e3d8ee55ed72755730db0723a74a1c27fden/a Heodo
2021-01-129Z.dlldll 958af16e38cd619acb45b7932c15c6e03a0b68b4eb04e40f91d5313ca0943761Virustotal results 26.09%Heodo
2021-01-12rGiPeZWd4XOOAjW5lALb.dlldll 8ea72f220d8840e8389457e84e0e754b8b6f3b8245c3131c29eb35b4c2280f55Virustotal results 10.00% Heodo
2021-01-12TNzJtyBZTu.dlldll f2c7ff9b42b7822f6fb75620274bc780cba9ef30e605179cd9e4488cf43ac2e8Virustotal results 10.00% Heodo
2021-01-120fzpOqG2oaj.dlldll dc97da935b94564ebb5f28bafff3b5aa2382dc537abd5a22cf6dad90201f1ab9n/a Heodo
2021-01-124Ml2Wzd03Y0WDoYima.dlldll 3b42361f227ad1f7f48dbc5e2cde15c5e5df57acf5b06430c950c65026da1883n/a Heodo
2021-01-12FyyvnHFBnmOedk7.dlldll 17ba3dada2bdcb46b91af4de19971a0b4fe278016da89f1d5d2ce5853b2e49dfn/a Heodo
2021-01-12JIacCtXrXFqX.dlldll 4bed3b3e5389c7c69744d97fe5c757a302ba0439dce7ace1ded498468cfe64f3Virustotal results 10.00%Heodo
2021-01-12ViCr18LBR.dlldll 6541580253433e76eea2fdfa5fa2e02a703ee53e8550cbc779a506566e92628cn/aHeodo