URLhaus Database

You are currently viewing the URLhaus database entry for https://hellas-darmstadt.de/cgi-bin/ZSoo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:959742
URL: https://hellas-darmstadt.de/cgi-bin/ZSoo/
URL Status:Offline
Host: hellas-darmstadt.de
Date added:2021-01-14 04:41:03 UTC
Last online:2021-01-16 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-14 05:06:14 UTC to abuse{at}strato[dot]de)
Takedown time:2 days, 9 hours, 17 minutes Poor (down since 2021-01-16 14:23:35 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-14dfqVy6NyIeZafbwNr7bX.dlldll e6828981676b0ab339ad85e3b951bdde0f68f8f31802999f211afe00552bdae2Virustotal results 38.57% Heodo
2021-01-14pX.dlldll 8c300e8b73539dee394f36fc10baa5cbada8dfefa8d3c02a54899670723c749dn/a Heodo
2021-01-14N3f0Oal1kBGJFW.dlldll eaf84327f17495957732070fdc2db37c0e4a48d952f5a9b54062bd6b91eae001n/a Heodo
2021-01-14Z.dlldll bb0c88e74a725e8334034ebac362493cfd24ce08752ba4962e2539befc17c5a3Virustotal results 36.76% Heodo
2021-01-14gQww77IRxaK3s0uVB.dlldll b93ad389f58107779c12c6da6b81d008245e4b022eb57234a7f0d4f2a6e295a7Virustotal results 38.57% Heodo
2021-01-14r25Xh.dlldll b36d9f30f62c42b58f927d7b457220da046ec12260ee5e5df988b4329fe3c88dn/a Heodo
2021-01-14XMcPgydQje5EW0AdCQrp8.dlldll a664caacf8efb5b8fd21b6fe7b8f5ef499253654be9967bb62e690665690498an/a Heodo
2021-01-14o5Gymn9NIr2DsEA.dlldll df4065818793a1167d8108c122729d28c78b660d366f7f9af4ebdfcfb1532719Virustotal results 39.13% Heodo
2021-01-14CxuFL6lWDQKXdRRn0xQQ.dlldll 509b0da2a695d5fa2e58653ce9dd43a32196fc6a71f6773a82ddd6ca1e48e643n/a Heodo
2021-01-147iieLEni8dAf.dlldll fc189837a6c09312b80e6f86f7c63bc98810cd73218eb89c38cfa8bc3bfa16d5Virustotal results 39.13% Heodo
2021-01-14zSr4KZHjko1.dlldll 7f03dd5756768751b1192abdcb72f9e8db470966a19e745257dd49b069e24511n/a Heodo
2021-01-14DbSpT2IaKT.dlldll 14939b8e7df0fc6fdd7d6f8d4462af6ae79f627add9c0848aa6a239b44fc632eVirustotal results 38.24% Heodo
2021-01-1467ploZYI1snZ4HD3Md8.dlldll bb5b04f053be7f861f14c592b6651e7043363fa2053453b67a3f1d70a95b9fd2n/a Heodo
2021-01-14SSBfLGo27pbJ2okIAt.dlldll 6f11656c12dc262a71d920f139bf7249ee0e1fea85c06356af4746df37719598n/a Heodo
2021-01-14va.dlldll 440bf890ab30f18fd7c36b30d179c07a089b487d2d2184d67f56f61cb9747507n/a Heodo
2021-01-14IXPEMPeYmu5aCmpNZsA.dlldll a1e1bd6ca53701a9b307634fa22000806d15267b1b95a79722c133e15d8d5394n/a Heodo
2021-01-14BShLLgO8.dlldll dcb6cc19d7775eb67e8da8b1ef462a6f32ff06bf81d5f8eaf8929ea611fa8f9fn/a Heodo
2021-01-14SgOjOHmY3BUKOvZlXjfX.dlldll 07a9d84c0b2c8cf1fd90ab409b9399d06920ab4b6efb647b5a3b9bef1045ee7en/a Heodo
2021-01-142Ik6oQ2XZIYQaNSxl.dlldll f680ac6b410656c7217ff6a94c360b6e57d4d44f16f33748773e9660723fcab7n/a Heodo
2021-01-14dYctKE5.dlldll d41c4ca130162c22ead82224088a59d262ea5d099bb8bfc61a867ec8775a778cn/a Heodo
2021-01-1451OdMA7P3pJ9W.dlldll 1acdf0f437c813d742a94a20833663ee648de753a319e6437637e0014ae2b5cdn/a Heodo