URLhaus Database

You are currently viewing the URLhaus database entry for https://doktortj.com/content_files/a6Fjp2SIn9UcCrBcZZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2125399
URL: https://doktortj.com/content_files/a6Fjp2SIn9UcCrBcZZ/
URL Status:Offline
Host: doktortj.com
Date added:2022-03-31 19:42:05 UTC
Last online:2022-04-05 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-31 19:43:06 UTC to abuse{at}idnic[dot]net)
Takedown time:4 days, 5 hours, 21 minutes Bad (down since 2022-04-05 01:04:53 UTC)
Tags:emotet link epoch4 heodo link xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01HC-581066248496.xlsmxlsm 7e16b96f674b1b3fa812fb1720851a37cb88e781ae92220bb858320fbe62c331Virustotal results 39.68% Heodo
2022-04-01QOB-8539392.xlsmxlsm 12defc6352bb846667f7048ac22b5ba0a7bededbfdc06aba79c5629671d59f33Virustotal results 44.44% Heodo
2022-04-01XW-81452953.xlsmxlsm f732de85cedc648c0aa6fe976bc90b56fbbd78c9458986d67c94873a64ca035an/a Heodo
2022-04-01MC-8779671.xlsmxlsm 0eef88b56a2aefc11d6c2fcc94f775230aeb9afbbcef74adad0e2e2c409151e5n/a Heodo
2022-04-01IK-036658995833824.xlsmxlsm f8f5316e59f479286d96010874074660c5afe3ddbbf1bb382c468904b9667595n/a Heodo
2022-04-01FY-273561228103633.xlsmxlsm 4d52dfe6d7f72aada80362bf080ef49a439b176e7c488de69e8d6cc39feefb9cVirustotal results 48.39% Heodo
2022-04-01IAT-115548704.xlsmxlsm 2b24ae43b66b722398ecdce2eda45ce724f63487f3059dffa976479d26a9f3b7n/a Heodo
2022-04-01LJN-1283975834513.xlsmxlsm 61635512bee4cff899365f4b237bb10933734ba71146cc0cd7f7692508f2b26bn/a Heodo
2022-04-01QUQ-5354428.xlsmxlsm 4e6c2dd2bb0183aa17caa2084632719d1b9d42cae3e0c96f6770b216822b8d01Virustotal results 46.77% Heodo
2022-04-01ABL-549793558707.xlsmxlsm 2c4b41fdeef820de3df320cf56f01c1fd68bc513eab0a09ce944de90245da0ebn/a Heodo
2022-04-01SZF-3817287646.xlsmxlsm 73dc0a16c8430b50b28054c9e0b1e54cc8174554e7b63b4e2fa4be17c3cac1d6Virustotal results 40.32% Heodo
2022-04-01WW-0535268.xlsmxlsm 2a6631c9dcb2385c65248a43d84d9d2063d4c0bec3ef9325c437a5ee31ef4dd6Virustotal results 39.68% Heodo
2022-04-01NM-520359083.xlsmxlsm 033009536542621d4d21d3368787a56ecdf807bccc352f8014ebf00a5a57c6f6n/a Heodo
2022-04-01PD-2285325218.xlsmxlsm b67f378396a813307cf0d9d7c4f272be83010272fcfa9af1791b517cf4f1ba05n/a Heodo
2022-04-01EQ-30205954518741.xlsmxlsm a4653047d35b63e4cfb6020be4149b484aa5e68354d53a9da860dcc3cdeef038n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01YRC-74645141309.xlsmxlsm 7865998de760d97246decb7fc619579d9389e6c2cdf72097738e48a74a0bafe2n/a Heodo
2022-04-01QA-8069906106187.xlsmxlsm 55af29e8285944f573d931d856bd099dac92ab1868000f8346d13a0bce7f1e3dn/a Heodo
2022-03-31YPU-95667205229034.xlsmxlsm 3cea415c72cf99f730ca00ed40940ba35c82dd2582786d91fb329459f88328efn/a Heodo
2022-03-31XK-760400062.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31NV-155937607.xlsmxlsm f4e10c5743205f55ce4eca43f3741f71ecfdca9391ae883123c3372d5daae4b1n/aHeodo
2022-03-31LNC-1345501063503.xlsmxlsm 441ae7dcf7d20f39dce4201542202d7c62c067457d1476c2bda9c819979879ebVirustotal results 40.98% Heodo
2022-03-31ED-2932395128354.xlsmxlsm 886b5540d8a7234ca4d384341ef859f08d555dcf16aeb021075140bb81459b9an/a Heodo
2022-03-31JW-140892357264.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27n/a Heodo