URLhaus Database

You are currently viewing the URLhaus database entry for https://elsadinc.com/wp-content/B/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:973845
URL: https://elsadinc.com/wp-content/B/
URL Status:Offline
Host: elsadinc.com
Date added:2021-01-22 09:11:04 UTC
Last online:2021-01-22 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?):mail Yes (Ticket DCU003271363 created on 2021-01-22 09:12:06 UTC)
Takedown time:11 hours, 22 minutes Good (down since 2021-01-22 20:34:51 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-22ynkZQFiUJJL.dlldll 7fc95528fdfe7e17578f023c5eff5766ed9463d20293c5814a5f49e05cbe4832n/a Heodo
2021-01-226vzuGOl.dlldll 5bdcab566326c2280cdd65a8f084993cd886fef245cf78d080d9cf9cae5b1e13n/a Heodo
2021-01-22CnLG2l4OXW6PXCmREM.dlldll 746b99af6accaeea76760ba6ae27d36d32a04f4e19b1b98a491e1fe4d5670ee2Virustotal results 34.78% Heodo
2021-01-22eTQp1V0ICNzstK6Zvjz.dlldll 7ddedfb973b815f3b97ebe58fed41b070b20670b4ab4997830e31b2f43d5ab9bn/a Heodo
2021-01-2287NgA.dlldll b307d62333559e1296134c255a2639ff9b7788f9d09a60f7a88c426809a89cd7Virustotal results 33.82% Heodo
2021-01-224rsbpbTTh24uZRjH4jl.dlldll 0639eed3355991cc4d6c31f7fec1f8a06e9fbfd4aefb3faea09c4e609f19e885Virustotal results 33.82% Heodo
2021-01-22r.dlldll dac9cad1597616c8f244c1acb5c84f209d984a52856b10bf3f980840c850adb1n/a Heodo
2021-01-22ypxU0UX.dlldll e747d0d409fece3661a1615c6f160dffeac6ccd636c7856c6c89107027fe0cdan/a Heodo
2021-01-226DBynLq3NjKKIYpBUQl.dlldll 85c585f97545d83bf397a48bb2b31230d0ab6c6c6071231d4447243488ca9d0dVirustotal results 33.33% Heodo
2021-01-22jHEqrnpfptFtwAaaHI.dlldll c8b82cd21d292239aaeb7ba4bde061afce6f74cc01462c634159a84b44fa7558n/a Heodo
2021-01-22zJ9EW7fDzyaX2d.dlldll c6ddb69722684c95075e9d0d98e0927aea8d7ecafc967f0d1cbdba604cfcd052Virustotal results 35.71% Heodo
2021-01-22sswbFBmlrRcry9zyMT3Uf.dlldll db51ac5588858e5473431d7eea0d5f754f53e3bd461f6044b825754a45620f0bn/a Heodo
2021-01-22n/aunknown f15f6e28115833121a6360a78b3f2475107d23e462ec7897e2907b0fe5428321n/a 
2021-01-22apfOYWBz8j.dlldll b0f66b3ad029bf748995c58a847d04c8422bed60b76605198988d67f4945c01cn/a Heodo
2021-01-22hcNd6EehNcN.dlldll 70324ee1a4279cd074eb6057720cb0aa5ff4968055ffbac2e885d247f9280e09n/a Heodo
2021-01-22dhhEAPAzkQZGmYa.dlldll 0144ced73c6e569dcdb09f96346999a95c1618fdee9a2a3b8b294b75339c8717Virustotal results 32.35% Heodo
2021-01-22q5C4HoK2l6yGb.dlldll 8a87e9ca0011dced9b29abff8ffa438815ed675b7c9fcef3e546109a08f2ab45Virustotal results 29.85%Heodo