URLhaus Database

You are currently viewing the URLhaus database entry for http://members.nlbformula.com/cgi-bin/Microsoft.NET/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:955804
URL: http://members.nlbformula.com/cgi-bin/Microsoft.NET/
URL Status:Offline
Host: members.nlbformula.com
Date added:2021-01-12 16:57:04 UTC
Last online:2021-01-16 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-12 16:58:05 UTC to abuse{at}liquidweb[dot]com)
Takedown time:3 days, 12 hours, 25 minutes Bad (down since 2021-01-16 05:23:13 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-12aXsy8X.dlldll 4a196ee4aa45bfe3b0b45a9760fd16beaa33e827837f18a00af674c906aab8c5n/a Heodo
2021-01-124KQQcq.dlldll b4078b1dfce7f799d4d64110d6a18c8a0ba34af65dd19806a9619829ca7a251en/a Heodo
2021-01-12gv.dlldll 9f223d189ab7d9142a1c97ea88a99e4aafa61628b6e81be0cb35bd7476dbb1d5n/a Heodo
2021-01-129RFTLO3.dlldll 621d122d509078aaae222445af72e4fa1181fa86a0a1733241b67eb131c6ae9bn/a Heodo
2021-01-12O8Qi9i0Vrlh9QjY.dlldll fc6435b986a3db65334fc17491b4288482bf8c63d7e54235a8966dc1f2254cf3n/a Heodo
2021-01-12GYXX9bkJX.dlldll 47d80255451b77889c934e768de9c8b64b0832dd4a712c55606505f501304d9fn/a Heodo
2021-01-12SqeFEMOKtAAUGhbI.dlldll 3ae406ce0713d71bd8bf863b91891cd4008ef5559318f96af906f43132631b6bn/a Heodo
2021-01-12YFmC.dlldll 20e119d3ed2dcc701464b076211dada84afe3fc5bbcacd6f0f02301386013035Virustotal results 26.09% Heodo
2021-01-12ps.dlldll d4d10def2ca1d1d04b4c50f8a1a2f68bfc63d3f543573bce68a45885cd653bden/a Heodo
2021-01-12MkeppTbrZW0pksh.dlldll d8196803a15aacb8797b29a589b137a8656149f38c524dd86dcac7ea8ec5af6an/a Heodo
2021-01-12cCk.dlldll 472cf49fcae5f3ae82c79ec28ef258c98c223a143bbc7291ff43faf55fc9d6f9n/a Heodo
2021-01-12FIjevqusM6o.dlldll 2729bb91323bcbc34c5ba30bb0b25fc58b6ecf41df1d90ba10d9a5781a2fa911n/a Heodo
2021-01-12L9Ti.dlldll 9e7c4f5580d4333988b4b36c0187e88430a446d61ce8bf1a87ad413f1456491dn/a Heodo
2021-01-12XkWS.dlldll 3ab7831aeb2c328ed79d7f724c15bb798cd40d9e240bcc212c928f1dfd08d3c4n/a Heodo
2021-01-12gkWmgym.dlldll e061e384372c851c4faa7a9e9ef452be7c75e4ebda95cb669c79c1459c7ff1e1Virustotal results 25.71% Heodo
2021-01-12AQUZ9DzJKNYgFy1uUvwk.dlldll 7590d346f04858e7710da34fbd4a67983f2ab7c8e9aa2a5e2ee3bee77b2d45ddn/a Heodo
2021-01-12cBFZ1XDG7iKral.dlldll 5f8a297ebff5b408d992d97a796181bb3d3906adbf55ecd23d1b089e2a4e4fc8n/a Heodo
2021-01-12hzppKYxFKeZUAuu15Zj8.dlldll 33b4a9ed01d52fa57173ab62e78fad6c33ea93da707a08a120889a947f5e8dbaVirustotal results 14.29% Heodo
2021-01-12wqSygLaGkkGTfFUDHN.dlldll 44490c9e6c70f8601697f83cb0a6a3296a36e1fc2640bf3caad0c01ec6cb0197n/a Heodo
2021-01-12TeY.dlldll 20ccb7ec8da02b62b5c58de0b586d6d2614f4524fa32041e917690b698385eaen/a Heodo