URLhaus Database

You are currently viewing the URLhaus database entry for http://www.inkayniperutours.com/druver/LtcG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:957871
URL: http://www.inkayniperutours.com/druver/LtcG/
URL Status:Offline
Host: www.inkayniperutours.com
Date added:2021-01-13 12:11:04 UTC
Last online:2021-01-25 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-13 12:12:02 UTC to abuse{at}godaddy[dot]com)
Takedown time:12 days, 11 hours, 6 minutes Bad (down since 2021-01-25 23:18:10 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-13PlToR8zs4jFukCW1x.dlldll 1543e2334b6a8aa3b782ba3041c55a6f8e380b0ccc2e789074f2ecb8bbeec4fcn/a Heodo
2021-01-13yf0t6aL4U8j.dlldll 7d0941cff8a7eb9472316be5bd44a85313379dd383159cb52d3f1221b7b98a52n/a Heodo
2021-01-13IXP.dlldll 8850e892bd0dc20119bb894ccfdb99c6605aabd1da3a52ad74392fc442efcac0n/a Heodo
2021-01-13TUHU0.dlldll 52ae21ba9d8dcf2b3eafc6d09b39bd2b0a29eacdb986126e92fd36f728912469Virustotal results 12.86% Heodo
2021-01-13MLGJMS.dlldll cfdc90d6c118d28d29c1644eeeae8e96a16e63b34110136131d2d291697cd61cn/a Heodo
2021-01-13HE.dlldll 2feb8940431afd7fe541623363079427c21ba9d2fd642bcedff2e2cfc934f49cVirustotal results 12.86% Heodo
2021-01-13zbkBJ.dlldll 96e6be2bb054c10937e1f487c857e8a95bf497c9188e723fa780d484fd534e3an/a Heodo
2021-01-13F6w.dlldll ceb9ab19ca27ecf185ead92c951ca3d4e3c8e1869dbf4d98e90c9ea619192178Virustotal results 12.86% Heodo
2021-01-13TBYP.dlldll b5595b65388d3521557c6072af9c9627be3a73934f4e01c504b8a0531858f80fVirustotal results 12.86% Heodo
2021-01-13irOozX.dlldll 149af0951def7c64c40451e3da1a839c84dd3fc73eb6f9a7a5a1baa718e6eaa2Virustotal results 12.86% Heodo
2021-01-13k4MQvxFtGYjhKEmS.dlldll 75e98a895b590fe7c6406eff9196fa8fa637f73a1b2ab17d0fc2662ff38fb9f6Virustotal results 12.86% Heodo