URLhaus Database

You are currently viewing the URLhaus database entry for https://www.thebermanlaw.group/wp-content/FILE/ULUy9Vz5NkKK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:187490
URL: https://www.thebermanlaw.group/wp-content/FILE/ULUy9Vz5NkKK/
URL Status:Offline
Host: www.thebermanlaw.group
Date added:2019-04-29 20:24:05 UTC
Last online:2019-05-05 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-29 20:24:07 UTC to abuse{at}siteground[dot]com)
Takedown time:5 days, 22 hours, 17 minutes Bad (down since 2019-05-05 18:41:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-01LLC_40938989224US_May_01_2019.docdoc 571210656adbfe8cde574bb15f96232169cdfb487f4597ce1a4532c7a0258f46Virustotal results 32.79% Heodo
2019-05-01FILE_527031738742US_May_01_2019.docdoc 404f20fabcaf9c4c086a38eb1cb139e49e2e08d6249ef41b88d7eb2c0e628bbcVirustotal results 33.33% Heodo
2019-05-01SCAN_554416962409US_May_01_2019.docdoc fa4963b59046a924250a2c0d7599ae98fec4d4d0ba1cdf8de575a7438c570563Virustotal results 32.79% Heodo
2019-05-01Document_2030327299US_May_01_2019.docdoc 60fef10a83e873748b44cf932f3e0fa0a0d891f414e591696daeefc00f0d01c9Virustotal results 31.67% Heodo
2019-05-01DOC_035734123539US_May_01_2019.docdoc 854cdddb19feff91dc4b4fba1ec91452c996a460cd5bd9ea2ff6e88f8c20f66cVirustotal results 31.15% Heodo
2019-05-01Document_022267805929US_May_01_2019.docdoc 2ade167cc02b318750feb789c0476581e4f2e0864c3a51fd65bd74c25534a74eVirustotal results 33.33% Heodo
2019-05-01LLC_421202232928US_May_01_2019.docdoc e8c5d544a7c4f929fc3c3422dc0dfd03d2e3ab6ff8e4153f5ea104d35d1b82ceVirustotal results 25.00% Heodo
2019-05-01SCAN_2415974455US_May_01_2019.docdoc 68e686c3f2b87d3169766ffe4bba021a8acd7648ca38c6c75be829a864558ecbVirustotal results 26.23% 
2019-05-01SCAN_18701039255US_May_01_2019.docdoc 42981d37b50801d5cdc23d5d9f0a1e0e20f3787e24c4d20f606d2250ce5bf804Virustotal results 26.67% Heodo
2019-05-01LLC_402796165965US_May_01_2019.docdoc db1c99298b5e34e6f10a5e054febbbbb8ebf940b4cacdcd1b1f4bf542d7da41dn/a Heodo
2019-05-01DOC_27346942325US_May_01_2019.zipzip 233f85cc131727592099fda98fa480783c747eafe8c896498d739f3947a8e713n/a 
2019-05-01INC_29022504898US_May_01_2019.zipzip 1f8aa66766a389ecb517b8df7e2078aeb112f082244f89dca24cc007578b8c5en/a 
2019-05-01FILE_617627904698US_May_01_2019.zipzip 7a999f6456005a2970dd64ac143a0081376425a85876370e5cb49311fbbbdcbfn/a 
2019-05-01INC_605656851206US_May_01_2019.zipzip 90ab9bf4051088d53a6755bedc66a44dc39a92be24a28e3efda654eaf3164714n/a 
2019-05-01SCAN_14398667231US_May_01_2019.zipzip f106a5a3a067abb514397a1d88d766ca674b68177fe31b4d7853f54061dbb378n/a 
2019-05-01INC_02385669307US_May_01_2019.zipzip 6f023d4946c0cfb7a4fe58f55aa0a76a86977c506141e0d9af6c01899e545e26n/a 
2019-05-01Document_2864193019US_May_01_2019.zipzip 6cea47c8adbf14c5cbfc8f5e296ef4b6d1cef7529c0db652549778e4364635d5n/a 
2019-05-01Document_639898096087US_May_01_2019.zipzip f13673ca215d4ca2091e4479f1a0097c31fe9314917e3b73140c06e6d2e7b8aan/a 
2019-05-01FILE_082968404278US_May_01_2019.zipzip 88209b354ed769c6319b558d3d19187b7d91c01561b4b6405a1d10d8bdcf19d1n/a 
2019-05-01LLC_521862195748US_May_01_2019.zipzip 617b056c650c8993dc39b2f33ee0e0f8f46ee2ae9147401da882cb2991f912cdn/a 
2019-05-01LLC_98746961966US_May_01_2019.zipzip f29dcfbab1b7af6b3f063c09cb20352a9e579dceb7aab38ad63997dda045d49cn/a 
2019-05-01INC_82034647583US_May_01_2019.zipzip e12acc8cf3555118ea72c95748153b7f479531abb1bba282ce1aabe6ce52ef7cn/a 
2019-05-01DOC_262253865241US_May_01_2019.zipzip 1ab5657c441f794aedcf5bca8d5c6b1e2b0834c3b808231bd7bb77ef2cc3de00n/a 
2019-05-01LLC_99524726562US_May_01_2019.zipzip 5bdc8502704fda72d2b768a5298ee075906955870f299c0e40baa923086d88d7n/a 
2019-05-01INC_01256083595US_May_01_2019.zipzip 0bb846361bcca070c1fe081382ed65d38418b96ef5b22ea3fa7c7786930a0d9cn/a 
2019-05-01DOC_8401447616US_May_01_2019.zipzip be9ec96b5db3d51aace59262d714abe71a6047f88ab61c75193fdd2aa936a074n/a 
2019-05-01Document_6181532991US_May_01_2019.zipzip 19908dbc6546439cbfff27c969b6249bf620ef1729d8619b3ffe98b5845c07b0n/a 
2019-05-01LLC_11931992719US_May_01_2019.zipzip d0c0ae0dc2f44261c4212667ed74e010bd8b9c0f5bb15fc57a97935465520bd2n/a 
2019-05-01SCAN_77580595489US_May_01_2019.zipzip 43563fb068c5c762246903bae4942a79424d4977adc6b526c474abc2371328c5n/a 
2019-05-01INC_2808761445US_May_01_2019.zipzip 64f5fa34635aaa6c981ff02eb17839d3593ccdefd297f5e926bf6780753a370en/a 
2019-04-30INC_84476148012US_May_01_2019.zipzip 34f204248d72f9a9ba5e6576b349b266b8c6119f35b634665965239973551739n/a 
2019-04-30SCAN_055834479905US_May_01_2019.zipzip 53ae0d9dbe4f0b201c9151860ff9c18354341bb627d56e6b403f5c35733253aen/a 
2019-04-30Document_34047587345US_May_01_2019.zipzip fd0ef8e1ff6295b343deab68ce644c81af27867872de441dc853f995c31d5dffn/a 
2019-04-30INC_89819746455US_May_01_2019.zipzip 2f3c7fdd5e8b2e6e55e50700ac2d0cb5fec12bdd49dcdc59b6569264fec9a659n/a 
2019-04-30INC_3058213085US_May_01_2019.zipzip 827850f47adf2f89a7c07d437e334248080471e6ce80b3db00a4c15ea64f5870n/a 
2019-04-30Document_3756111849US_Apr_30_2019.zipzip 4978f742016a6083c59c1763682b9075dad46dd9c772bbde175efd0b61dd322fn/a 
2019-04-30LLC_30535635349US_Apr_30_2019.zipzip 636f5ca6c3ba021416d11f388b734c15578c65091f1396149a0e31d165c91bdcn/a 
2019-04-30LLC_426284017380US_Apr_30_2019.zipzip a52fef100dabcf39e497a716662ad5c71fbcaada9923f9ad0cad0c40467a130an/a 
2019-04-30Document_5263797991US_Apr_30_2019.docdoc 034d793e2d7928a31f3a2d405552c9288aa51d9fb212759573cb300f5538e92eVirustotal results 48.33% 
2019-04-30DOC_127848030688US_Apr_30_2019.docdoc d6b27400c5f0886cc2c21da11cacf302aa85e1b457a6f49ed8119b573fcb5558Virustotal results 47.54% Heodo
2019-04-30DOC_876121102128US_Apr_30_2019.docdoc 42a04a35e214a16dcf1a928a99faa2648c7a34562eead18fa516512fcfa784baVirustotal results 47.54% Heodo
2019-04-30INC_9881138900US_Apr_30_2019.zipzip 18cc51d61fca2a775504f1f587fb8bf354a50c93aa3f8dbca0f0fca063c53218n/a 
2019-04-30SCAN_12513918088US_Apr_30_2019.zipzip d9ec9547d07e181ed1663bca73028fdba4aeb8c116af2ebff31a66b0550e9cd3n/a 
2019-04-30SCAN_175280866385US_Apr_30_2019.docdoc 73b99eff123644a39dff492f32d56732e9e091e57474f4e6ff9389b002c1c695Virustotal results 45.76% Heodo
2019-04-30Document_78025136409US_Apr_30_2019.docdoc 4ea21ebe4deb18442e48c50e5df59871fe759b0bc7d77d9e642fb4c2d8d075c3Virustotal results 40.98% Heodo
2019-04-30Document_23917709334US_Apr_30_2019.docdoc c1149fafd459848007beb7b03aa37238890baa832f9a6da66148f7fd53ae2cc4Virustotal results 38.33% Heodo
2019-04-30LLC_73980785943US_Apr_30_2019.docdoc f399fb7c51afe772dfeaeb3bcd6e3d314556b9823612e79fabc1526b9c388efdVirustotal results 38.60% Heodo
2019-04-30SCAN_7488915103US_Apr_30_2019.docdoc 88fb11f83cfe717bc701477ce352734e64288099a09ef72bfdeda4dbac3d03c0Virustotal results 37.10% Heodo
2019-04-30LLC_607166549204US_Apr_30_2019.docdoc 17b7ee868deb1727ad76e550adc36d7961fc7680118038ab2911427184306a48Virustotal results 37.10% Heodo
2019-04-30SCAN_6338345262US_Apr_30_2019.docdoc 9e910794abbe1c197fda10c892da9d8912a81d887bf8092e68571dc863ac89a7Virustotal results 31.67% Heodo
2019-04-30FILE_241728835124US_Apr_30_2019.docdoc 0697a18483c60f3f703c0d498ba0d1288918ad7261101c942e33799eaaa1beb9Virustotal results 32.79% Heodo
2019-04-30Document_1014271796US_Apr_30_2019.zipzip 39b3e7341ee435953ea710a4a75725b43b07aa3df5cb946ea972412e9f5ef014n/a 
2019-04-30SCAN_9036245323US_Apr_30_2019.zipzip 1c66e786dc8b6f35aa43bd9a8489a0d149e56548f51e626ae5af9bf49bf06e23n/a 
2019-04-30DOC_78181889640US_Apr_30_2019.zipzip 8583812d711c873346a107b229939b9da831683a1579cb4621ccf0ee2fb910a2n/a 
2019-04-30LLC_140585975708US_Apr_30_2019.zipzip b80ceb65b5f777a4fba989517cd2ad7165da86a355c74b4ed5d8695e459c9e9bn/a 
2019-04-30INC_471279132800US_Apr_30_2019.zipzip b1fa60724a499c1bfe63b96ed2ef5394b6ad837e3f2d52ada415afb7a2753580n/a 
2019-04-30DOC_1189253016US_Apr_30_2019.zipzip d4c945862e78ce6bd0be673ab8cb054f6349f9bdfb2428da1c3f17a6153ecc52n/a 
2019-04-30Document_917689215819US_Apr_30_2019.zipzip 365d6546649c34f783fec00a6f8099855c4dc264e51a8aefe1531f8f02f8e584n/a 
2019-04-30SCAN_6419065335US_Apr_30_2019.zipzip e7b43626f4302e6f161614a239b527818734e9dce518d4deb5c34e922df6d899n/a 
2019-04-30INC_02713256141US_Apr_30_2019.zipzip 678b7cafd27cfc7cbbbe715ab9d88f0fc3037f84237fe6f01fdd9f806b5224d2n/a 
2019-04-30Document_626441497232US_Apr_30_2019.zipzip 002027e1de246a210e8f785404baba0b330ca2955d9ef6baf27fffa5d0c2c044n/a 
2019-04-30Document_096627038402US_Apr_30_2019.zipzip 4d6ea9adb4f358e9045cabfc71c95316e77e6648750ff7fd7e9c979e6c01028en/a 
2019-04-30DOC_37055051959US_Apr_30_2019.zipzip e4f6c188376b6f69c93e505e946da75ca2e8fc4c84c25a814eb1f18738677316n/a 
2019-04-30LLC_79225108049US_Apr_30_2019.zipzip 8eeaad0cb04d84b934bdd2bef5824e6138ab32a30e2e26346cca1d1d9c390768n/a 
2019-04-30FILE_030191870230US_Apr_30_2019.zipzip 6e06dfbd5569003a80dc43a275109257c73bda2b775868041cc0af14578b037dn/a 
2019-04-30INC_757732744516US_Apr_30_2019.zipzip 906a8cdd93491a51862d39a33f78da4d9360a92d39c4827d852a2e2429c235f7Virustotal results 18.64% 
2019-04-29LLC_15475119652US_Apr_30_2019.zipzip 204c01ce944ca182c4ace649befd3fa93023e555c12888185677ddf27f33a2f2n/a 
2019-04-29FILE_831224286514US_Apr_30_2019.zipzip de03ad5d8690a250bf0b1eca49b9f4314c6e50b94faa45cc687754d59cb0efb2n/a 
2019-04-29SCAN_1489430329US_Apr_30_2019.zipzip 352cb29dcb81e3048545601d7efd5ec7d9ffd75b85c15f639fb7af559ff32e65n/a 
2019-04-29FILE_4605035861US_Apr_30_2019.zipzip e663d1fc31d81ff53f5c0de2b26b5ece99f4a1663f5fc051babdb48d9cfd5fc9n/a 
2019-04-29DOC_757549297157US_Apr_29_2019.zipzip b2cd479e3411cf440f09b8d5f0018f247fdd8aa37e1c19f05f302b1574cc6c55n/a 
2019-04-29SCAN_33876135224US_Apr_29_2019.zipzip eb39df09dcd4bc59863af84fe3e54de83a548da2e4301d7375575358be4067f6n/a