URLhaus Database

You are currently viewing the URLhaus database entry for http://sd-1130049-h00002.ferozo.net/wp-includes/JmOU9rpjaYV6yR7z0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123441
URL: http://sd-1130049-h00002.ferozo.net/wp-includes/JmOU9rpjaYV6yR7z0/
URL Status:Offline
Host: sd-1130049-h00002.ferozo.net
Date added:2022-03-30 23:51:06 UTC
Last online:2022-04-04 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 23:52:07 UTC to abuse{at}hostmar[dot]com,abuse{at}dattatec[dot]com,pablo[dot]pepe{at}adinet[dot]com[dot]uy)
Takedown time:4 days, 19 hours, 10 minutes Bad (down since 2022-04-04 19:03:02 UTC)
Tags:emotet link epoch4 heodo link xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01ZJC-561208372037781.xlsmxlsm 01c0169c20d6d3f1ef670cb180a6bba00773b10470c460b5c140e414492da173Virustotal results 39.68% Heodo
2022-04-01PKC-3169581261.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01KUR-14704476073858.xlsmxlsm 033009536542621d4d21d3368787a56ecdf807bccc352f8014ebf00a5a57c6f6n/a Heodo
2022-04-01WSS-782564764050.xlsmxlsm c171d718d9aecb5ad1e27309660f8da7a568f9798e03d4c6683d7825b5a122c9Virustotal results 43.55% Heodo
2022-04-01AO-791174963.xlsmxlsm 5144b4176d2f9e56ad483565884642378be09039de1f2a353cb355c00dfa1894n/aHeodo
2022-04-01XU-4218415787.xlsmxlsm ea8981ffdb13c6d1dd874a5a86e7079bb053c862a92849bc571846a6762dc7d4n/a Heodo
2022-04-01FTC-1743815.xlsmxlsm 73dc0a16c8430b50b28054c9e0b1e54cc8174554e7b63b4e2fa4be17c3cac1d6n/a Heodo
2022-04-01HWK-77342631878287.xlsmxlsm e487c02def7287335acf2278332f27a4a585960d8ba68a14c0b8370535440c3cn/a Heodo
2022-04-01DYD-81507594.xlsmxlsm dec78675ed65ce3c282f1d9d3e4a1da9209c833b7aca7b14647e1a944b002400n/a Heodo
2022-03-31BLW-89970972.xlsmxlsm 7b5aca9a82485f669d10db3cd974bd416d8c41f460a1cc9e81eb7a5ec0eb1574Virustotal results 36.51% Heodo
2022-03-31BKT-5125978791711.xlsmxlsm e4a6b88e713470e3d31c81c890d21472b60eb097b915f29ff70c688bf397df8bn/a Heodo
2022-03-31QI-362531250.xlsmxlsm c7f63ce6becdd48402150d223d11b5fb003ec48c57f2d856c8d979e5b3da4254n/a Heodo
2022-03-31YRN-8377683.xlsmxlsm 8d56be834c0179e7c6eb48e5182c8a9478aa5afd0c88e1c54592d9b01ed11fe2n/a Heodo
2022-03-31EM-82707810.xlsmxlsm 441ae7dcf7d20f39dce4201542202d7c62c067457d1476c2bda9c819979879ebVirustotal results 40.98% Heodo
2022-03-31ATO-787883623599.xlsmxlsm 0baff6c11648937580735dcff8208034790a0e1ee649431e79b2b6221d825c40Virustotal results 44.26% Heodo
2022-03-31MT-584326360066.xlsmxlsm 522056ad088097c5c827ddabc4a8e7ad95b16563043dcfde8aa2fc4b0df81a1fVirustotal results 41.94% Heodo
2022-03-31JP-538807258633973.xlsmxlsm 2fa93c2dfef003816d473094a03ffe57ed6fd6cbbd21f22831af88634fc3287dn/a Heodo
2022-03-31PB-029555389926015.xlsmxlsm 48f3f48c930933448b555efe67aa364e098504f2273ec2a4792803cb4a21b8bdVirustotal results 40.98% Heodo
2022-03-31DWL-566024127817.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31DY-358393616.xlsmxlsm f6d9028f6903f57570a969a97a510120fa11d93ce778cfeac61862c36d6b6bd2Virustotal results 40.98% Heodo
2022-03-31JWM-5058408.xlsmxlsm 63ba5c63fa8f569c1870ab57faeeec2933a7bdb28c90458f6c5373f1a71dcef4Virustotal results 36.51% Heodo
2022-03-31TG-84485832356050.xlsmxlsm 2e1db4578a7534abbaeb0e65b01b0da5024a9e27d99c3a9b29b03cca35b3a096n/a Heodo
2022-03-31GTH-34628069920111.xlsmxlsm 5285de9e0e5323564d48a5d9fc627190ed9bae90f9c0e818958768b0d7c856b1Virustotal results 36.51% Heodo
2022-03-31VO-6653639685.xlsmxlsm 65b87a95369159fb3d54556f3f316f9e13eadd8b95e9e13f6a8d9cc79f43a8e6Virustotal results 40.68% Heodo
2022-03-31OG-29202255754.xlsmxlsm f869263419a75a1350a78400b9e3dd186488c7c76d299e7984af7e5e0c91d75dVirustotal results 37.10% Heodo
2022-03-31QRM-2659659719310.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31YWC-159744552429392.xlsmxlsm db67f0509c5f982c9eb1fab5a17d14ea07d5a1e13b2f5ee3b35ccf93700588e4n/a Heodo
2022-03-30VOR-3668953415936.xlsmxlsm 8eb161bd22ea52d987b19953ebebe364df8a0779ed9f42ad96c6dec32f8cce52Virustotal results 36.51% Heodo