URLhaus Database

You are currently viewing the URLhaus database entry for https://gmthearingsolution.com/cgi-bin/lrZkqL/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972179
URL: https://gmthearingsolution.com/cgi-bin/lrZkqL/
URL Status:Offline
Host: gmthearingsolution.com
Date added:2021-01-20 10:02:05 UTC
Last online:2021-01-21 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-20 10:04:05 UTC to abuse{at}godaddy[dot]com,abuse{at}heg-us[dot]com)
Takedown time:15 hours, 55 minutes Good (down since 2021-01-21 01:59:25 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-20kgGip.dlldll 03ff40768f2c5dfb8c60c977b173ab72abc0932ccd13d139115bf7f0ddcdb323Virustotal results 31.88%Heodo
2021-01-20DwPybq68Z4i5l0XuY.dlldll dd1962726cf51783b6e14f6f6be0c271da21b40f7d1ad99bdc1a2f3de05e627cVirustotal results 44.93% Heodo
2021-01-20rNBI5ZC3xkzGOJovDEg.dlldll 48c5d93e8274183e33d4515062e19fb1c14db791c4a6b4049e790be85214cd1dn/a Heodo
2021-01-20Q6bStVZeW.dlldll 7978925aa5ce37a7691a207d29b8037d3cb2811cccdceb58558e1b2f63ae5d12Virustotal results 42.03% Heodo
2021-01-20iyfaCol.dlldll 8debeb31058251846cb2a390b0a52c776dfa3354d9827ee0b85d5ad26b3dd217n/a Heodo
2021-01-20rxCJldKtqUB.dlldll 61155de37f371bff0bef39296e837b017ce15cf6ced3476a4559ba41b1eba7een/a Heodo
2021-01-20hgYi7C6mjDb2.dlldll f889fae430ec6558daa28b324a02da043b0970aafe89196e136b2eb087339d55Virustotal results 41.79% Heodo
2021-01-20gT3OguGr.dlldll 2d197e9fe3823432fab5705054eec20373ea275c10a127b0cb091144e834c97cVirustotal results 42.65% Heodo
2021-01-20r.dlldll c7784b4bdb5d9e0cc3f926e7b2d286656189fa2956d653f165cda17752870481Virustotal results 40.58% Heodo
2021-01-20pjIp1wBBFxWTaWtiC.dlldll a350da7a09937a89a819dca92c4d2f810d329e8cb231e77cd4d2bce95576318aVirustotal results 39.71% Heodo
2021-01-2088V4eqSutdXutf.dlldll 156f723962b2571c1b079d727bdd2a33949e86b2b6a92defcd5ac09f99affef7n/a Heodo
2021-01-20mJSJfhfvjqbNPK.dlldll e50f9381899bb70a493e5c8ed0a9418bddf8cf053e3813b776d6e831d8f32b46n/a Heodo
2021-01-202R2NCrnROQaBbE0Ur.dlldll 67d45db5ed8dfa00ca6fae092d14ff1ccd925d86ea9247e7a92bfddccef68391n/a Heodo
2021-01-20mDvZZ.dlldll 8a22c147d7b07ddabd272681491c29ebf8b607d90ef54269c821631e191d94b4n/a Heodo
2021-01-20Q9ZHqSWWfyMqn3bjgxx.dlldll a632323021f98d667be75115739fcd49fdf237fc1734c957dc024623356ed719n/a Heodo
2021-01-20as8.dlldll c5475b132303544ddb8095d49036fb8e28ef4985e462fdd280e8cc60b18fb453Virustotal results 37.68% Heodo
2021-01-20CD249oaD.dlldll 2f62a22a53e1595f130507247f2415fb10bc3a07f6b0db3a4541a0566be650bcn/a Heodo
2021-01-20dD5ee45X0V1BJ.dlldll d0766f070ac22c2b69242999f0456f0d8fe420b82ed48b52c05fe4585c6bf895n/a Heodo
2021-01-20w01olWMB8LHyX.dlldll 088cc21f292a3647c4a929a2bbfc54805b27d683bedbc49a309ccb713fddd95dVirustotal results 37.68% Heodo
2021-01-20i2q4wozNkBMypA.dlldll 07a4b4677655c8928cdda0cc17c7df47696939db19baf93c5a903079d051d328n/a Heodo
2021-01-20gIAYAYzzy2M.dlldll d959f843aa7f145a087c539c5d5d624cc96022720794b185fb99ec51a9e2673dn/a Heodo
2021-01-20KapnVtU1BNpkWWa.dlldll d8c81f35acdf493f88a708662d3a7609e7e468c45c35e53160756aac33375816n/a Heodo
2021-01-20Bdr0je8.dlldll 292b856335161eb24b1bc571e46a1c1240d7cce83bae63ce1a56b4f4b4449d70Virustotal results 36.76% Heodo
2021-01-20zuM4z89K.dlldll 5073861b196a3e51b9b602648329dd4cf85afeea15becc49df4d260b9feed271n/a Heodo
2021-01-20oYt.dlldll 7e5054ae78092c57f1e9db7110c4f4edc120db9cab641d31ba254c27e6ae8840n/a Heodo
2021-01-20e3GA1A78JsY.dlldll 97e2d5d1c7eb8a25929c79869e8323ef6040fe293c0749aae2d8c03918a5ab41n/a Heodo
2021-01-20IgXq.dlldll 52651bf319dbd95912fa467e9b52bbf2650b1c7f64c2b9db0da8a7f5bd2cc4e2Virustotal results 34.78% Heodo
2021-01-20VyIiOwJ.dlldll ab8b8739aa7ac9bf0f356617a36959e566f46aba0c31660017ce9b3f228ad025n/a Heodo
2021-01-20hX0oGDV1.dlldll 9db80b29d7224b5c8f48c23179c8ecb01662d618c876c3bcb0f96863f4146c66n/a Heodo
2021-01-202wz5IhJifn2S581E.dlldll 2e9afc2b311bf28d8fcc2747ddb6bd51809383f8585ddc7843c68931dafe1047n/a Heodo
2021-01-20Xudg9.dlldll 7d9ffb5823da279b5d2b88ce64d1a3c5f56567a6ecb8f153f15eb9dfc085828fVirustotal results 33.33% Heodo
2021-01-20QZcb9cBS3upw.dlldll 91832c6c6d12e5e17b39e9beda88f5177864eccc5011acc3590b5f78d0b04718n/a Heodo
2021-01-20ianZ6QZS.dlldll c5c8b12f9bb34ac0b922f590b46d235c5e4848e40b8f48181d79b2e600d4c9d0n/a Heodo
2021-01-20RZYp.dlldll ff15ef568971c5be6c1adbae491944e440afcb3a454fe00a8c7066c5f88570d4n/a Heodo
2021-01-20J5KFfx1wS.dlldll 6024afb625a008083f84e145df363c26b419497c6e603e5b3f270af6b35a299cn/a Heodo
2021-01-20WYMNDQcHl33.dlldll d12fd02ba23d876478109d1de45562f6307cdd3debbe1faa4e5aed73794cb06en/a Heodo
2021-01-20DuZnbDFF.dlldll d2c6c7cb7c25777bc791b8847ce2a522561ee4c6c1adee54634a6ffe75a41195n/a Heodo
2021-01-20Fh9iQLhu9u4FCAkAAW.dlldll b526336d0acac6df8b7b08fd2d16354e044c1a607a44f26dd51a25d83324da4eVirustotal results 33.33% Heodo
2021-01-20P3f0A6esDwYXWBL.dlldll b8d6063c1f23e8c154db9aeb74c2e5fdc3f536f956a2aac9d9fdc9f0ab7dc496n/a Heodo
2021-01-20Zwp3NFjQvihIu0YtFA.dlldll 0a12150b7df4b6c526641da9c8449aafbc490b0a0913bddaa769129980c9ace4n/aHeodo