URLhaus Database

You are currently viewing the URLhaus database entry for http://jthlzphth.ga/wp-content/IuTE-joJB_CLz-lh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:166492
URL: http://jthlzphth.ga/wp-content/IuTE-joJB_CLz-lh/
URL Status:Offline
Host: jthlzphth.ga
Date added:2019-03-26 17:55:04 UTC
Last online:2019-03-27 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-26 17:56:03 UTC to abuse{at}cloudflare[dot]com)
Takedown time:10 hours, 29 minutes Good (down since 2019-03-27 04:25:44 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-272019_03___US___ACC2529021135___2655827535.docdoc bf3ac1d80daaf533b3af1f1c3b030803791374ac22ad5d4530d8c5b8b3a6c5c8n/a Heodo
2019-03-272019_03___US___MLIRX5553314304883166073___4152874045.docdoc 4f910d9c86a9f647fc2c9ee8018925b2c7bc974cab6331e252d5d17485ec1e06Virustotal results 37.93% Heodo
2019-03-272019_03___US___X84465644358___982226535043277.docdoc 4a2de059b24cde110ce822adef190218a365e9b41f0a96b06d5e45e6642faa23n/a Heodo
2019-03-262019_03___US___ACC781623279346486806___799142735.docdoc 6dc961267d310273be9c3755f9ddb21914619fa0b78a47f5a22594284a0e39cfVirustotal results 37.93% Heodo
2019-03-262019_03___US___G6373526567838___006146816244489.docdoc 12801117100fff39edbbc870c6a21e4f180a7dabb92168a0ebfc0abdb2617f72Virustotal results 36.84% Heodo
2019-03-262019_03___US___68324641632___027881860239.docdoc 00792cc131f75e7f87f2c033780021fbec3eb2092d8bb7e6e9cf0ce9269eeef9Virustotal results 37.70% Heodo
2019-03-262019_03___US___ABN655943479389411___40483309693581.docdoc 78ad7fface477d0c80f8e451aaed8f325ea725dceb195d522daccfe1b8a5ec98Virustotal results 35.09% Heodo
2019-03-262019_03___US___INSTR4343919128259912383___1325381613068079.docdoc cbf9cd66ccb6e969c0ad9878fd01a8122c73c7af7bac9a4518d9e26a38260e6aVirustotal results 35.59% Heodo
2019-03-262019_03___US___25955392767139___646129342111296.docdoc 07c63e38cb12e5e8e259602a0a04acb44cc372c7d09acd675b395be858adc06cVirustotal results 36.67% Heodo
2019-03-262019_03___US___ACC944975978022415___4145065883273354995.docdoc f2a3fb74265fe14d74cdcfcbc96e59b58037e4de0a288a0253be7bf593359fe2Virustotal results 35.59% Heodo
2019-03-2662905017603536115.zipzip 74209c0e4fb7bf725c9fb555b5139693ead45cba5628bf66ac3a343588c31438n/a 
2019-03-26ACC8336868182540592439.jsjs 77dc0d7396d3ce236d9833c2c2ed1cb9236540cdd02e4f8f1e6c7f14392167can/a Heodo
2019-03-26US1919965309652088180.zipzip 9e75b15d655bd5741ac039f0f8584c28cae61bd20b5ae933df5f0aff1755b6f8n/a 
2019-03-26INSTR966241816807.zipzip b5a20b10c408febbaa3e05a4fb0ea241a56382a7a1645bbe20862471d8d98465Virustotal results 17.54% 
2019-03-26GSKZ6827037030967196548.zipzip 0a6bef642ed51495da42f9ad1c197d832e34ce86c2b7ff7a84ae9e92524f3986n/a 
2019-03-26INSTR7300637888.zipzip 8115813459a1ab2a664f8871d01022519568cf1b8a73d7b88bbc4637c1eec428Virustotal results 17.54% 
2019-03-26747563673.zipzip a88e86c2232f64ef24c37e2d336d52c996755bf486b799904601031a564e8320n/a