URLhaus Database

You are currently viewing the URLhaus database entry for http://bambathamobileloans.co.za/cgi-bin/X/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972522
URL: http://bambathamobileloans.co.za/cgi-bin/X/
URL Status:Offline
Host: bambathamobileloans.co.za
Date added:2021-01-20 17:49:07 UTC
Last online:2021-01-24 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-20 17:50:07 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:3 days, 12 hours, 31 minutes Bad (down since 2021-01-24 06:22:05 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-20XIbS6T9mjmt.dlldll 03ff40768f2c5dfb8c60c977b173ab72abc0932ccd13d139115bf7f0ddcdb323Virustotal results 31.88%Heodo
2021-01-20KKJAdMjqIqHcGWxo1m.dlldll 7072ef571dde71561419877d4ab14d97136c059ffa69bf289cf253efa06723bbn/a Heodo
2021-01-20BPmrUF.dlldll 1086ea49af6bad26c6bb2720cc6baad1fd8264c643444118790f4c3d1eca5eben/a Heodo
2021-01-20ohCU0r4bYkl4K.dlldll 3710b548e10e1ca1a5648a0a2df7b9620ed8bb5ef61ca1ce2b2d4b9d9547a871Virustotal results 44.93% Heodo
2021-01-20U6bZO2MFIVKzP.dlldll 74679b915a9a7f011bca955ee58935af85f2502095336845f67a38f9db9c2a44n/a Heodo
2021-01-20ThQF5laoh.dlldll 6cbf4e69bf6c2a02be477a75eaa4dbf6717ac0a5a6f8388a328980a367cd4c7dn/a Heodo
2021-01-20fpoVHF1OruacCjeFD.dlldll 3a580559a9d7972bf1fcda68e05c50c8723c8e7a8e4e720e468b5273b23e34adn/a Heodo
2021-01-20g2QOBsnZNj5rf0.dlldll 6e1bd07a726e55944eea239668249c03c0423e549c53f655d16c92e1728116bbn/a Heodo
2021-01-20k4xUfTwB199ohKT9oH.dlldll ae5d3379b6ebb3b587385475e9712f03bb4624df9ac7864cc4b8c7ba8b45da38n/a Heodo
2021-01-20wlJT4obKxqGH.dlldll 0d70da1ebd4131691f55ea43b0debc9bc4981c324ff382721500f70050b5262dn/a Heodo
2021-01-20wfISugHd6DeocQQVR.dlldll d8cb5bb4a366b6e40a9a315e22827e297de9811f74838d781af8045175ae6961n/a Heodo
2021-01-20KYP.dlldll cba9181638c4941392d14263b58855743eba5c73471ab79821890afc96d4d9c8Virustotal results 43.94% Heodo
2021-01-20M9AAUwe.dlldll 999423dbc9ce1fabe62c9a28a0ffc5e2ec88a981d43d1b3b27206289c97a1ec5n/a Heodo
2021-01-20rK2KO9E1eqtci.dlldll 862ea7f1392d0f756ec3ad0e75d5ba0508960b5cb9c3d1509ad200a7a5189091Virustotal results 32.81% Heodo
2021-01-20nhnqjL.dlldll d72fae43fb4c0088d3aca9db3f4450b0f0a8e3368b2f0527aad364b9efc13f23n/a Heodo
2021-01-20GGTSQSMxoXpo.dlldll a375dccf8bae1650588f5501fcb409b51589bf2bd806c78fd28e37bfcbcbb2c5n/a Heodo
2021-01-20T9kzAC4hNh0.dlldll 109ef806734c5c3c5a13cb3f03badfb7ffedd06837a5fdc756840a230b404b24Virustotal results 40.58% Heodo
2021-01-209OlpSxoli.dlldll 073fb1d49910c03c3dcd519d5ab0b4be8a8c2bb00822fc7a92d05d22d9815b73n/a Heodo
2021-01-20e09.dlldll 65c80b8c1d96eb54c20f38fa4a0827f8e1f7bfcbe70671aafd338863e5ca01a7n/a Heodo