URLhaus Database

You are currently viewing the URLhaus database entry for http://www.pcsaha.com/wp-content/fG1tM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:973970
URL: http://www.pcsaha.com/wp-content/fG1tM/
URL Status:Offline
Host: www.pcsaha.com
Date added:2021-01-22 10:46:05 UTC
Last online:2021-10-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-10-18 21:23:03 UTC to abuse{at}hetzner[dot]com)
Takedown time:8 months, 29 days, 11 hours, 3 minutes Bad (down since 2021-10-18 21:51:56 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-18pNNVltJY8QP0F43nHu.dlldll 1b00a1bc8f31181444401e5fbeeda262710528a55a652573ecc8684020ef43e4Virustotal results 78.57% 
2021-01-22Wgzt3own54Gg.dlldll e08424829ee4e951109a6fb0cb7f23686f6775a6f59b9871ef40a3e22cc41b8cn/a Heodo
2021-01-222biKR9e32snR2r6vwWEo.dlldll 4e4f7895c5bb7bc3e1f189857368f039ee5e5f8559dbc6a858ff5699032a15e4n/a Heodo
2021-01-22I6NTdHvKz.dlldll 22b7cec3b1d99a80a3af1f3f21bf1f2e28feff124d913e68b46a0c19d5b1e117n/a Heodo
2021-01-225k2Rm7r.dlldll 20322c9d17e45e9f7078d8b4ceea0f841c1f82df4eb2e0e3287089eb73a92f94n/a Heodo
2021-01-22QXA.dlldll 1873d6e885a7cb5cccab330c2ed57413818b97c42c0aca384d8162c6ffe55039n/a Heodo
2021-01-22PjZr1vREmzBN0S7mGD.dlldll 68e1c2002bc1e77503ee34e0bd8f2d97354a17e33efec419ee0594d3d69400d2n/a Heodo
2021-01-22LvmFhUZsJ9w65QE.dlldll f5a2ec7716664ae860577125e6e304b393e655a69cdd48c93387c0ec08cc98d5Virustotal results 31.34%Heodo