URLhaus Database

You are currently viewing the URLhaus database entry for http://vataas.com/3325390551/5W/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972521
URL: http://vataas.com/3325390551/5W/
URL Status:Offline
Host: vataas.com
Date added:2021-01-20 17:49:05 UTC
Last online:2021-01-22 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?):mail Yes (Ticket DCU003266195 created on 2021-01-20 17:50:06 UTC)
Takedown time:1 day, 22 hours, 54 minutes Poor (down since 2021-01-22 16:45:02 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-20edJerrcHqc8.dlldll 03ff40768f2c5dfb8c60c977b173ab72abc0932ccd13d139115bf7f0ddcdb323Virustotal results 31.88%Heodo
2021-01-20ofNEyBkthyC.dlldll c3154b10051241ee792f5f2e1bc442884e0535478b945c5480d6c61ecdda1ffbn/a Heodo
2021-01-20gcEFSP5oyCjnukLJWPu.dlldll 5376254c0d6fc591c26d9f94743d83cea7dc849d5bf0682ca6c06b6510da94baVirustotal results 45.59% Heodo
2021-01-20B4xyFj.dlldll df45fc02db4df1625bbb8f611edeed20539133738674261e42b4eb491def4c29Virustotal results 44.93% Heodo
2021-01-20VNp4bYvI8TwxFHa.dlldll 215a5e76ca03a5c3b0349890a254993df81bebb6f90c49e6506de28346cad74fn/a Heodo
2021-01-20zesBhyyIPwMbxXGks.dlldll aba340a4d86bf6732e0793bcc452cc77bb786c26e284da179045014a3430baf4n/a Heodo
2021-01-20Uz4Y9Wj677YDL.dlldll 30f8c26b86a3e63ff08c732621899cf627f455570c9ee7f318456579a619d33dVirustotal results 42.03% Heodo
2021-01-20ryrTKo0Ls1VTM.dlldll 32eaf3f23e3187b0cda281266a81280907436c2c139e52cb67415ad2238193d6Virustotal results 40.58% Heodo
2021-01-20OOWeRHgnuHKFTCWL.dlldll 487956f87c17ef25e290f1bbaa92025bf1df180453ddcd33d0dff299b65107e1n/a Heodo
2021-01-20BqWN8WP.dlldll 7b8d2bb04cc6efd4066926601f94b754dbdd76a71896ac9735749fdf433d040an/a Heodo
2021-01-205NaawSc8.dlldll b8607cff20c3f11ae23bfaa62add41fcf56b5239c964abbb532cc4c7a2cb5d7fn/a Heodo
2021-01-20GLtluMw.dlldll 44ecc97e5373025748f3e7b44c4a92dd0f362eee84107eb9b4f456da27105426Virustotal results 42.03% Heodo
2021-01-202Y5b2gh53.dlldll 7f790a2e4e2f1ab86309890987a5607f7e04d7e54ad44b417a596ed4a3f85a02n/a Heodo
2021-01-20MRC3FNCDDMObUqlNqK.dlldll 58449c7137407f00ac0a114abf59d43f19629838ba693c7624b54fb35698c1ccVirustotal results 40.00% Heodo
2021-01-20wHIE9D.dlldll 51127ecfdbf6fd763a19cf06f54c90e5c6acbee90328ba6345c8b54a316b95c9n/a Heodo
2021-01-20fC.dlldll a922b27eda11f1afb5481996bd7340c9b960428fbc51ddbc5336262b0354e34an/a Heodo
2021-01-20AKWfYU4uLjTAxYg5N.dlldll e20ae4cf83514f49289c93adac769ae8a2b8e547a12834cb5d5d7e1950da3cd8n/a Heodo
2021-01-204IOFz3wYZCWgxc.dlldll 71c13d82f7ea668e479a0a2f06209682a3715865a5339e44aa813c607e954003n/a Heodo
2021-01-20RRETw.dlldll 87e1df269fe5a32d2850cb3760ead25c201b9eac5d446173bb131023a2e69e2bn/a Heodo