URLhaus Database

You are currently viewing the URLhaus database entry for http://0rdp.com/wp-content/INC/BFGTOC5X/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:184752
URL: http://0rdp.com/wp-content/INC/BFGTOC5X/
URL Status:Offline
Host: 0rdp.com
Date added:2019-04-25 15:33:02 UTC
Last online:2019-04-26 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-04-25 15:34:04 UTC to abuse{at}hetzner[dot]de)
Takedown time:18 hours, 42 minutes Good (down since 2019-04-26 10:16:41 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-26DOC_54535469961US_Apr_26_2019.docdoc 8052cbfa6f3348c2cbdcaf35a02d470947238347278421560a93400473a5e75aVirustotal results 31.15% Heodo
2019-04-26Document_016843890023US_Apr_26_2019.docdoc b6027234bbbfca5ce87c4757557f0a4a9ed2c54960d915eb215722fa703191f7n/a Heodo
2019-04-26LLC_0003396381US_Apr_26_2019.docdoc fd84376ecb2845381d03f46851fb6328f5c0f26c51fb515c74f21b2326031630n/a Heodo
2019-04-26SCAN_762727777854US_Apr_26_2019.docdoc d673444e2d8e9d1d919b1cefdeeb0dc783106192d1fd1fecb401df43134449e9n/a Heodo
2019-04-26DOC_53097477218US_Apr_26_2019.docdoc c22381c768d93356bda637be73a296a73f5b51756cff0c9d0eee0661e2e967a9n/a Heodo
2019-04-26SCAN_723304838286US_Apr_26_2019.docdoc 8065d2137332893c6e189b09a0e6b480e2f2955e827e0b67e4418e6a268da467Virustotal results 32.26% Heodo
2019-04-26DOC_429115921131US_Apr_26_2019.docdoc 00a73162489f59b1cc4fc07208676176c19eadbe5c4c0f16b0bd3f7c15a9a03aVirustotal results 31.67% Heodo
2019-04-26FILE_189384998399US_Apr_26_2019.docdoc 79aa4c12cd7acda388199e7e59ac3481b7e738ae2b3a43ac06bf08dd8f6b4419n/a Heodo
2019-04-26INC_15558509455US_Apr_26_2019.docdoc 1581b1babbda10ae6971f0e9ff822a65aa8bd4d98ea920dbeb9261e6e5f3939fVirustotal results 30.00% Heodo
2019-04-25FILE_150750876099US_Apr_26_2019.docdoc 828b7e9914f932108e52249577fa80987f20ebda94b8654fdc2964baa4d929a4Virustotal results 33.90% Heodo
2019-04-25SCAN_0240140141US_Apr_26_2019.docdoc 67d05dd367015c892e3f0f50e5737a5138f00f626a134a85f1c2a6496132e691Virustotal results 31.67%
2019-04-25FILE_59883988926US_Apr_26_2019.docdoc 2d4c029c63ed1ca1131a3ddda7fd4e66078676407a476a00ccd09d2a85c8079bn/a Heodo
2019-04-25DOC_290426601056US_Apr_26_2019.docdoc df0fb247a70c89c6562901405d16cc4d36f5052d95ecedc5b9ed5185a0125f91Virustotal results 27.42% Heodo
2019-04-25INC_1534542952US_Apr_25_2019.docdoc a11052d85933b9ebe77b92056e6efbd89393fecb51e3f0fd80a4cfa946cdb7d5Virustotal results 27.87% 
2019-04-25Document_5668853375US_Apr_25_2019.docdoc c10e6f58b4c3cef4ec5fc1bdb39d5d879c7a9c62e261bb47a74dff8c0d20118dVirustotal results 27.42% Heodo
2019-04-25SCAN_609857140052US_Apr_25_2019.docdoc 3a5f13bd1236171391ad45bf7369996f14b24bfcda152cada9bd04abd6351e6en/a Heodo
2019-04-25INC_900175214381US_Apr_25_2019.docdoc 3018734c8e915925793a54bfe29457bf245d9a58f3077d74ec22e2b04dcf9972n/a Heodo
2019-04-25INC_556729043853US_Apr_25_2019.zipzip 5f52608b29b8a8dd6056eef3edd71ec1c4fb181f9ea40bd7d74578e1feb92f85n/a 
2019-04-25Document_7947659675US_Apr_25_2019.zipzip e52745e59cce8dac1421ccdf10575967b964a7fa8fdc1fa218071ab8ed21af61n/a 
2019-04-25FILE_9037353764US_Apr_25_2019.docdoc b3e6382f49c7cd0ca3321c6bfa1b08e7b3ec57ca9cad5c29e7e37f0eccd210faVirustotal results 33.87% Heodo
2019-04-25DOC_111087264167US_Apr_25_2019.docdoc 9e506b942c42727c6a4c007ae5473c50a71f58ad78e8873588c3fd451ecd7da5Virustotal results 33.87% Heodo