URLhaus Database

You are currently viewing the URLhaus database entry for http://bimland.info/wp-includes/bpj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:267320
URL: http://bimland.info/wp-includes/bpj/
URL Status:Offline
Host: bimland.info
Date added:2019-12-11 22:23:05 UTC
Last online:2019-12-13 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-11 22:24:02 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 day, 18 hours, 53 minutes Poor (down since 2019-12-13 17:17:11 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-13Inv-MWV93_6430.docdoc dbb364e4577a66d4f381e4af2498d6372d376b268133c958207fcd3f351951bdVirustotal results 31.15% Heodo
2019-12-13invoice-WT579_326.docdoc 7f350e0bb84750815d9982ccb48286d2d3b454d9952b076d306876879f8a058dVirustotal results 27.87% 
2019-12-13invoice-GP49_76575.docdoc dea12bbe4b2c5989fce96f1544844b590f45e02b6cce5ddb771a9a5b3eb9f8b1Virustotal results 26.23% Heodo
2019-12-13Invoice OI49_23.docdoc 1d9d018983c19aba80412aef9e7c2d0f7e71c28ae8770d785819ef49fb467c5aVirustotal results 26.23% Heodo
2019-12-13Invoice QOI338_215.docdoc 6a5b5173bbee3ac445651227d6d24e875e04bb93eb1c0a60b5711ded512195f0Virustotal results 26.23% 
2019-12-13Invoice-HB859_99612.docdoc fbe0ec1ec4b33074fcb351e2f371bfc8c7b194c8f7a2fd9b4f70944117a4d034Virustotal results 24.56% Heodo
2019-12-13Inv P95_69625.docdoc 07eb1f103c1fce37edabd5f8e89d0b23230c1e4726aaf7efb8359b790da97a1eVirustotal results 24.59% 
2019-12-13Invoice_OQ851_239.docdoc 7eef3e40c5fe9e85bad4b2299a8ba6c37727189761a0ff114307b5b50952b508Virustotal results 41.67% 
2019-12-13Invoice_S032_69240.docdoc e4a4f352053438a256858f74b0c81b171da65542435b6ef0aea4c12b36022606Virustotal results 35.00% Heodo
2019-12-13INVOICE_P189_37825.docdoc 5f6ba823787afb7e2f9788859061479479075de0f6a120b7521ad11e22003b6aVirustotal results 34.43% 
2019-12-13Inv_OPJ58_5431.docdoc 78512311878dc5953e0e21ca16ed7248ac613e81a73ac6a65ff47e7daee04d0cVirustotal results 35.00% 
2019-12-13Inv-EPY938_8678.docdoc 16a152d62c22e97695d546db457c563ee707a1720e2484aefca89c4ea444f756Virustotal results 34.43% 
2019-12-12INVOICE LP57_673.docdoc f8c126652a855a24d3e388407d94b80344e1b774f5f2a7a292af380aaf6eb8f1Virustotal results 34.43% 
2019-12-12invoice_X337_52844.docdoc 89891bb4f7c8613e62b60638e41a82d4fe0589af2be2884ffa84eb7d8102337bVirustotal results 34.43% 
2019-12-12Inv-O000_621.docdoc 5ab572b3e3a96baf28b4a1ac9473f4f864814fe34b6ad9c0f659503ce3c5d99dVirustotal results 35.59% 
2019-12-12Invoice-O937_82.docdoc c7329a0847be6a4d32fb3cd13a9e24ec6e54c7946c5ffd111939b5567275e92aVirustotal results 32.79% Heodo
2019-12-12Invoice T72_43246.docdoc f59f977d3187101bfbfe78bc48663ed97e0764674f803e9ad5af7607661ac4e5Virustotal results 33.33% Heodo
2019-12-12Inv-G87_402.docdoc d81a284ae7d3b942ef02659ca2f90b8017e30730fdf79ba7408704b1d07e6546Virustotal results 39.34% Heodo
2019-12-12invoice_Y53_54685.docdoc 8766efc88b7e69bd335ce0607a459ebef87acad1fb3941526085853212b56ca7n/a Heodo
2019-12-12INVOICE K876_43.docdoc c065308bae2e29a077afed2d64f29ea013ac3697b251f1a9e0cc4b8072234f71n/a 
2019-12-12Invoice-JTD325_32790.docdoc 5df1f1341851c837a5892bd964c406fe101dd9154c3b5c1df36eb95372c604e0Virustotal results 30.51% Heodo
2019-12-12Inv-XE57_0131.docdoc 8ec626cb5d05c16b41312eb6967a5b541891ecbd185bd088415fff9689af2973n/a 
2019-12-12Invoice_G830_92.docdoc b235bf9aeaa3cd3418f2f1f3769f99b65e465915cd872b5860d833e456668c8cn/a 
2019-12-12invoice_VX841_145.docdoc 00dd9a987f526a8a477a329bd805ce33c63bac6e56ffc032f4abd4d08896029bn/a Heodo
2019-12-12invoice-F52_177.docdoc c765ecf47cc4ba7c01f89d2a7349570cd9ffe689498c807227fadcc78f291da2Virustotal results 40.98% Heodo
2019-12-12invoice ZW659_52.docdoc 699dfaa6f502bc577250c8307983c757cec5bc1a0f672621e92cb60b1a07ef02n/a 
2019-12-11Inv-N99_40386.docdoc 812e0b4cf9e67544fd7b338d45b8739096c49778e2eb338b560c50883ea8f6b2n/a 
2019-12-11Inv_SNX95_5767.docdoc ca86140dd6fc523d776b6b4fac20df57ebe0cf289b76b57185b8cd5813f8dfc8Virustotal results 40.98% Heodo