URLhaus Database

You are currently viewing the URLhaus database entry for http://cometarabian.com/wp-includes/zFY6U/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972346
URL: http://cometarabian.com/wp-includes/zFY6U/
URL Status:Offline
Host: cometarabian.com
Date added:2021-01-20 13:30:08 UTC
Last online:2021-01-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-20 13:32:29 UTC to abuse{at}privatesystems[dot]net)
Takedown time:19 hours, 39 minutes Good (down since 2021-01-21 09:12:25 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-207prrTs.dlldll 06040e1406a3b99da60e639edcf14ddb1f3c812993b408a8164285f2a580caafVirustotal results 33.82%Heodo
2021-01-20lZkk.dlldll 984dc72fd26fb8597ead0173f0301ba3bd72e75288d49842958f311aa2f22644n/a Heodo
2021-01-20jyysOYDSKABnUk8HfdlXfd0.dlldll e96f1fe5ab23f84731db56d406b09f59898fb32720a3a3eb693bde171f7ae7bbn/a Heodo
2021-01-20L0Vt8acs.dlldll b27a56df6fa5cfe33c97b219a0519bacfccb1f82b2fdfe2b6d966db5b9b34f20n/a Heodo
2021-01-20YLabeQLtrUymqLuYv9G3gu.dlldll 6989215c7dd1df2cbae89c4d0fd9f997938c20dd001268d5d6ac0a33c62a3cc3Virustotal results 43.48% Heodo
2021-01-20mve7sxW.dlldll f8a3acaac2498c2e9650cc005669f277a47374474aef2ea6da09153cc6399c16n/a Heodo
2021-01-20xn04.dlldll d9d88e1dda8ae5a22670fff63c98dd7c3e707211a3043a0f14093a09c3419877Virustotal results 42.42% Heodo
2021-01-20JGo3hfytjDkua5uIpe.dlldll f7bb90d27fb0806db44f278ce623e7b8793e8ec7c1e482b5cacfe703d3362acan/a Heodo
2021-01-20WWc.dlldll 59df7964d15248e4e362e48a45dc98990c23bd264690ca05eb6df7ea24c16de9Virustotal results 41.18% Heodo
2021-01-20M3.dlldll fb1cc2a09c087e253e0ab6d01606da46f7a96212077be3b9a211124b9fceff82n/a Heodo
2021-01-20PrAhcyVLQPZYbQWRuEnV.dlldll 524affc9d6726135832050090eb396cf660d2ec97f51a40a896c8df205f45fbbVirustotal results 40.58% Heodo
2021-01-20JQkA0L3bqmofNK.dlldll fe32a73c7c8d8f42912bcea45570edefe541f701c4ebb247b12592b53ff366a7n/a Heodo
2021-01-20445azrWMK6zhzc.dlldll e70f31be2b969803644a0711d3aa1e2726428514e9c376ba5f4d476584615d2bVirustotal results 39.13% Heodo
2021-01-20VP67zMbPFvUek.dlldll 4f28c63f32666bd6acc010f9e9dcb197d6fb866966235cf3aa43906b3368ac84n/a Heodo
2021-01-20DBpXXE6W.dlldll 9fc57c607585532593786cb652acead2832ef232a7c8b64bc6b3f3d950bc61c6n/a Heodo
2021-01-206SA3RoPeQLlwgJ0l92lRs.dlldll 4582fc89f73cb6117db162742aad1268a8d642299091af9ff4aa5dba7765e704Virustotal results 39.13% Heodo
2021-01-209v6hfEm2N.dlldll 1dfa78aab177a1c57c7c3066574333a495f5b5a8c95d31099f3b63e306938ab3n/a Heodo
2021-01-20FXnj.dlldll 7acd0a1e4c0ce5ac13e0e12803e02264626da8117a685683bb9b2d5420b89eb2n/a Heodo
2021-01-20zM5PsN6FFUMnLlIPgskM1m.dlldll 4c7fc5bf8457230a1ce7dcf821eab7370bd745aa3d8d969f7f4396d68992df5aVirustotal results 36.76% Heodo
2021-01-20ZC64MRfgEqS.dlldll 1a12a8644dfca3dd1a355b36863cf640484f7afe7b1edd2d027a44d070c77b6aVirustotal results 36.23% Heodo
2021-01-20X3imssynw.dlldll ab84fdc892482ee90b9a448beb2b9028b6793b7ff7602ccdfebe5fb1e03b3125Virustotal results 36.23% Heodo
2021-01-20Ax4uzznwfuUuF1eirCbX.dlldll f6bdf5ff6b3dc93a54fecf57a3e54b83e24aa7fff8267d0fb7ab18891ff54950n/a Heodo
2021-01-20BV8l19QaZtzfraC2NogcF.dlldll 0e554cb3ea5b7ba2a880d08fb6646e81fe3aacc44ee224a7f0e5fe4ac10fac98Virustotal results 35.29% Heodo
2021-01-20Xk0v99xpCb0wfGupCCYN.dlldll 90d3dc1d752dcb2a4a67b19f73fb09956a0ffb97cc0f0671f1452b959635d65bn/a Heodo
2021-01-20tyRe.dlldll 490cf85f9f0c2f6f21c72437dc50a5a548d50ca1506d8a520f9f25c994591154n/a Heodo
2021-01-20bAFEN.dlldll 3a0c28624283d66f1ec9a35e6078662359b043cd653b6920a1c19b3d17d625fan/a Heodo
2021-01-20BnXF7PXx8Zit9aX.dlldll 60dceff5ce148186b210fc41e7a1c4d8575ef39784f8a9d1379dd6fe1519d5c0n/a Heodo
2021-01-20iVtPb.dlldll f433448349fc25303866042ea74d5edaf1d0fe49fe62ac9c669aa4b5cacbbf9bn/a Heodo
2021-01-2093rg0344XD4wCMOJ.dlldll 4a640ba13353b2bafe65b9a2b098b8841cf9c9aa84a4073661f65c2d4befbe0en/a Heodo