URLhaus Database

You are currently viewing the URLhaus database entry for https://ummahstars.com/app_old_may_2018/assets/wDL8x/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972165
URL: https://ummahstars.com/app_old_may_2018/assets/wDL8x/
URL Status:Offline
Host: ummahstars.com
Date added:2021-01-20 09:53:03 UTC
Last online:2021-03-03 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-20 11:28:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 month, 11 days, 21 hours, 27 minutes Bad (down since 2021-03-03 08:55:14 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-25EnExokTaLY.dlldll a9dd98f4b6fe0b997f8b3d50f1ca405f02583a02133874fe123eaea6c22dab00Virustotal results 58.57% Heodo
2021-01-20pWrq9q8O1KmT55g2luUHhmD.dlldll 06040e1406a3b99da60e639edcf14ddb1f3c812993b408a8164285f2a580caafVirustotal results 33.82%Heodo
2021-01-20TUAffAhOMWOHRma0IP3kZFj.dlldll fbdd4ded324ecceac6a3f334fb45c6459b013a5a38900cc8944aab90328749b5Virustotal results 44.93% Heodo
2021-01-2038ZpB8rHO5klWIFr2RMLJ.dlldll e55b3a586e07ac02042903f4e16b024e9e0ddb848fa0d16f818aec24ecf61489Virustotal results 41.79% Heodo
2021-01-20IPl8eXLja.dlldll 3cc579988d4f50ecdab2f0e6afe8f45c9e23fd646577e2ddee2619858ce20e1fn/a Heodo
2021-01-20qcrapacFBLH.dlldll abd05febdc5f8125440606791822037018fd541a7ac3944c92a186b620740a74n/a Heodo
2021-01-20Zx0G.dlldll 33f1ad31ed9751c5d6618fd9ceed79be1434003b3491fbb4ff9df829cf561436n/a Heodo
2021-01-20PsuLLyWdrSxf2rJx59n8C.dlldll 1966bb77634bbd4cec1176cb3366e597d4a2c26daf5f4eaf38e46fef92408ac5n/a Heodo
2021-01-20x4M0swObPsfZYeOWdpo.dlldll 956eee8ef21f0cc9b9205a7d3998feccd824df4421ba561d76c47a58768fc331Virustotal results 40.58% Heodo
2021-01-20mmRNvS4DSjFwbjsxIcmkkY.dlldll bd0c7e836bf434897704f3f20ad394ba86b4e91fba44c300f4a2ed0c0f24e7bfn/a Heodo
2021-01-20FqGGuD.dlldll 7cba224b04d2f909d3ae4cbed9b7c7e73cb622e00c0ec96ed116ff8aec590ce8n/a Heodo
2021-01-203kWxvEVTJxGT1.dlldll 0f954650e0ffe9bf791ad13865dabbe33ef6fb5cc777ec62a4516ad138e64e04Virustotal results 36.23% Heodo
2021-01-209qW.dlldll 572c6b8fd798bbbc5deda20eb4a6a965558af00c6c1e726a337c1f9aaea26051n/a Heodo
2021-01-20wxIah.dlldll bd866c66d70c29d21297dd5900f3e3391d836830a23873636cd97acf12ca1ee4Virustotal results 33.33% Heodo
2021-01-20NFTZGCHVlkL.dlldll fdb652cd83a4216bbef192ff2a7447016f546023b3f40da08f6b5cb1f071f319n/a Heodo
2021-01-20sZc9xIvodAmPxyiG.dlldll a727025299dc62c50b1245ccacbf42b1ab783fbc644930f750938cab3caeb6c8n/a Heodo
2021-01-20MLBYRMR.dlldll 639dbb77201ff8d30038fddc0b9c671e2947aa883a043447b8712ef684a2c879n/a Heodo