URLhaus Database

You are currently viewing the URLhaus database entry for https://theo.digital/wp-admin/Zyl2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972204
URL: https://theo.digital/wp-admin/Zyl2/
URL Status:Offline
Host: theo.digital
Date added:2021-01-20 11:08:03 UTC
Last online:2021-01-22 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-20 12:18:03 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:2 days, 0 hours, 38 minutes Poor (down since 2021-01-22 12:56:14 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-225YGHNgw99IrnU5u.dlldll f5a2ec7716664ae860577125e6e304b393e655a69cdd48c93387c0ec08cc98d5Virustotal results 39.29%Heodo
2021-01-22DPW8u9dT.dlldll 4f0aebbe2bd0308a5f20f96491a8c87875b2373da050bb36f8b9fc3200dc8215Virustotal results 30.43%Heodo
2021-01-20NN.dlldll 06040e1406a3b99da60e639edcf14ddb1f3c812993b408a8164285f2a580caafVirustotal results 33.82%Heodo
2021-01-2087le7o4Yv8ED7a0.dlldll 7d5b9a9c9b98606022d1d3b7d5347e13e637066b7688772c020d80651dce31c9Virustotal results 45.59% Heodo
2021-01-20VrZS0zzdk.dlldll d6857beb2b75128d4348167b167810c973555b0710b50b91491fde5d5fbbcf63Virustotal results 44.93% Heodo
2021-01-20mF0iuZQzY5pWkqZ.dlldll 85b75eaef88e6ca1b10933c249d2688a0fe08761c4bb0867a0a3ec3002fcdb28n/a Heodo
2021-01-205VntcLDMfbbNusG.dlldll 3f24cb44a5b2e31ebf60d444573b7cd99ffd9d7ca4cc7aba2f6ac8da71edfacaVirustotal results 42.03% Heodo
2021-01-20ssdYpwAJWF6q7rT3iKVFly.dlldll a1f03d553ad7b9e8e1577b7cf22a6df00074fb4b93da2dc6cc4ae2270bf8d3c4n/a Heodo
2021-01-20MJUctQcA.dlldll 3d48ebf77a294f194c3acb0e3ad1f19b5911277ce0ddf5f4cc9c20fc98384516Virustotal results 42.03% Heodo
2021-01-20QMb90tIis6.dlldll c3fd26dee384fa7ac72ecedaa026fc2dae0db229dc72067fddc4cd34b6cd962bn/a Heodo
2021-01-20JWcm5kVEJ.dlldll 9b36e035f9639a9a1a3ef31d04cd271b3e9065a3e32317d2ff27c5cc1eb31a69Virustotal results 42.03% Heodo
2021-01-2069.dlldll 920696fa6f20d96632e60e71b41ccb848abb9a1aac039e9f1beecb86b98e34f1n/a Heodo
2021-01-20aFHhapSOzel.dlldll ed71d83a8d4cfdb327231e52a00eca1f2db95527948f3d651eb495826d20352cn/a Heodo
2021-01-20SfocbZU0Llm5V6FDzYWBt.dlldll 11006e202824b0323640e0cc5c9b378e37f2329f0301f2fd8c9c6dbd2ef0c7ceVirustotal results 40.91% Heodo
2021-01-20MGQP9zEPcpyWRcJTyAN2Xxf.dlldll 369ca7d0842f1a10f10b4e92a26285c8d2d64169c889fa0211197d4800b57d85n/a Heodo
2021-01-20NHxJl0ZSdH.dlldll 0f1569686f13111d4da630257bd9c25a723b5c8e16bf1913578271a4c5326488Virustotal results 39.13% Heodo
2021-01-20A4Ko.dlldll 59c9704e561a5946c09ea023045be13269e6bfab243cecd0b9ef742bf612e1beVirustotal results 39.13% Heodo
2021-01-20X1E8eBb.dlldll b953887da7dd8c013ec68c3f4928f187e7fc1ad16a7dcb90ac5d6f22ad7dddcdn/a Heodo
2021-01-207ZdHuP19Hv2F.dlldll 6bb8599bea83c82a83b475a449077432ffad026c1686129c144c1f08c1473a34n/a Heodo
2021-01-20nM.dlldll 17103ea811cdd05813cc35f33254bd6a7190d637b0cf0dc0387da76977cbec22n/a Heodo
2021-01-201Iu1W9I.dlldll 43900db13c022505d76556ce0639652a86390b22c70741d7184b02ef15faad63n/a Heodo
2021-01-20FfGNa.dlldll dad31a7fc3f5d0d8c6c402961ffe786fe7159ec06834470a3ce2281ae9cfabc3Virustotal results 36.76% Heodo
2021-01-20KTGCC9WjfkO5B.dlldll e8dd90874406587e2fe0a993d18c3e5a93916dd80b9ffd68d0ab20ed97901f1dVirustotal results 33.33% Heodo
2021-01-20iGcHfWRCqiDkWGL.dlldll 1e08553391c478a26bff7a9b71bcb4af8bb2cc60cbd9c0927b58db3e43da1920n/a Heodo
2021-01-20YxqQ5js1VL6JCvM.dlldll 9711b632441ad739ac47ca123141e55155595b2cd8c08d758855cf5a24eac879Virustotal results 32.35% Heodo
2021-01-20Cttau7pkN.dlldll e80b8a5267d90e9db5ae60bb9a3e4b1e437ddf5b19e7c78e02f3364eca6d5cben/a Heodo