URLhaus Database

You are currently viewing the URLhaus database entry for https://testmp.dune.ru/wp-content/45477300-62539359/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1977467
URL: https://testmp.dune.ru/wp-content/45477300-62539359/?i=1
URL Status:Offline
Host: testmp.dune.ru
Date added:2022-01-14 22:35:05 UTC
Last online:2022-02-16 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-14 22:36:11 UTC to abuse{at}rt[dot]ru)
Takedown time:1 month, 2 days, 18 hours, 21 minutes Bad (down since 2022-02-16 16:58:03 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-15l7247.xlsmxlsm b8121edc6cc2e93b9a7832beca7e11a32f3c0b8214816c8276a2d2eeec251050n/a Heodo
2022-01-15I_23902.xlsmxlsm 1f2fb274efe18ae6707db44fd5e92e99c9da494530658002e2443435536ad260n/a Heodo
2022-01-1592235364_10625.xlsmxlsm f58905138f947e83a11dabe1d0fcacd0f6b6390a4b2c968f6de1e7f388ff5f1en/a Heodo
2022-01-15zxyaott_0006708.xlsmxlsm df3d1c9f634b214294ffb42adacb58b20d8aa9f35da387af12be4ef35556a1eaVirustotal results 36.51% Heodo
2022-01-15201621_931969.xlsmxlsm f843518359dd39cc1adc8c717ca65addcc0803b0130440152c1a23923820ac9an/a Heodo
2022-01-14793656_216923.xlsmxlsm c7f2afe51337a22d7458aad225f6c867436b3c51c0897ddd6815294d8731353aVirustotal results 37.70% Heodo
2022-01-1439146_42826.xlsmxlsm 2c1629903649cbcf3b885c468c648e7b9caad9bce1bad13edf832b78d8e98d96n/aHeodo
2022-01-14914798611462125.xlsmxlsm d2569a5701a8fc23468530b950ed661832ef6d909e2a1a921da07a879135f612n/a Heodo
2022-01-14978073414732.xlsmxlsm 269e9c81c482255515158bebf6c871afb18b879ac13cfcd7e9a22a6e6476423fn/a Heodo
2022-01-1445477300-62539359.xlsmxlsm 490a022e265d8e49a264e991a18c7cf5e9ac696b7904bca3c765370e5d4fa1cdn/a Heodo