🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for https://bitextreme.com.my/wp-admin/5qBFWwuVA-Lg6u1LlQEsH2j3B-resource/guarded-cloud/xehuw2-41z1521/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:271274
URL: https://bitextreme.com.my/wp-admin/5qBFWwuVA-Lg6u1LlQEsH2j3B-resource/guarded-cloud/xehuw2-41z1521/
URL Status:Offline
Host: bitextreme.com.my
Date added:2019-12-18 04:21:48 UTC
Last online:2019-12-22 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-18 04:22:10 UTC to abuse{at}digitalocean[dot]com)
Takedown time:3 days, 23 hours, 11 minutes Bad (down since 2019-12-22 03:34:00 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20adjusted_doc-18670864.docdoc 50ef9a5f6ef2cd9539a0b58a8f8af3fba684f119fe6ded32b0ec2867bf727498Virustotal results 32.79% Heodo
2019-12-20duplicate_12202019.docdoc 27b25b36f565ebe1b9fa0450584e3e8326ee1e48bb32bc9618e2f87dfbcc63b0Virustotal results 32.20% Heodo
2019-12-20new_original_12202019.docdoc 9c8a67a4cca28b33344ba9e2bfdf954e7b3de20c7e7df17d0bc9940c94a6a898Virustotal results 32.79% Heodo
2019-12-19payment-K288909-6976795078.docdoc ef2f6014b9f926466073f7e036544e5188ac00b96f5f321e12c8daece16e3b94Virustotal results 32.79% Heodo
2019-12-19ChristmaseCard.docdoc c9830c742b6d63ed05a6a06724a96918b32f5bd2a3a7632ed6866508970b3510Virustotal results 33.90% Heodo
2019-12-19Christmas_greeting_card.docdoc d394ed6a30ff8bd2c2812675561d9662c72ea9d8c987dd329046f0ecfdeb9177Virustotal results 32.76% Heodo
2019-12-19Christmas_ecard.docdoc 38228d35350b8cc46377671e6c82da104d71567808173fd99063d63b506488eaVirustotal results 30.51% Heodo
2019-12-19greeting_card.docdoc 1e1aca50c65bc43be764fd92ca9b520348c710fbf834ff62ab8d6d1198d3a1faVirustotal results 24.19% Heodo
2019-12-19Christmas-eCard.docdoc 77d6e16bfe0c08553094c4d421b8fbe2e19da685a837ec432e153c31376fc803Virustotal results 24.14% Heodo
2019-12-19file-wown87k14r5pw.docdoc 27820b2e783ff5a9817650a7f8a04b23a41db0d06c86748ef6a1c4a1fdf9f43eVirustotal results 22.95% Heodo
2019-12-196oouks.docdoc e75e3aebe863fbe42808fecadb2cefe8ef18d23891d13b6b970f21ef8489a238Virustotal results 19.67% Heodo
2019-12-19PART-5slu4no85wtlw8.docdoc 61fe55be0a1c2a52426f90abfa9778eef565c849a24ae59e31c6c8ba403462e8Virustotal results 21.67% Heodo
2019-12-19S580559_95446759434.docdoc 4b96abf7da27bf640a179aca09786968bcce28787e7551ab431bbe77d144a212Virustotal results 21.31% Heodo
2019-12-19Doc_w0wpqm6oo0.docdoc e5874d28102cb0c9b354502a98d8b1c8d982346ad1b8463988833a104bca5b51Virustotal results 24.59% Heodo
2019-12-1912192019.docdoc 5167cc18fa6f09d6f20b7eb6cdcf237800ed1e86862a053fe72b0a936ecbed8bVirustotal results 22.95% 
2019-12-1985727411477.docdoc f4f8b44946546436bc0416b3020ed6dc278c7dd8a18db0a8a9b904de6e2f6640Virustotal results 23.21% Heodo
2019-12-19copy H4144365519.docdoc 139113f465022b7336c3cfa9e2ea54952d56825d295a0ff62dd3e8cc09483d24Virustotal results 21.31% 
2019-12-19COPY_MH447803300775.docdoc 8a375c796318cfaf7c7ac3c524f9c401ded50195b94059176d97992ec3832da2Virustotal results 21.31% 
2019-12-197813296.docdoc 51e2372fa861af972c7f0b7735c82cf27679b45c951a5e59242c550b95be3b1bVirustotal results 21.31% Heodo
2019-12-19rep 2323119864.docdoc 46e6df81e9899f2d35c7f62fb707f6ef9e909ea682b7e62d4afd3e0ff0b9076aVirustotal results 30.65% 
2019-12-19UNTITLED k4to4v0wwv5s9.docdoc 572bc2b161d30a630cb05d333098de35fcf29bcf4744b6af84196990fdbeb3b0Virustotal results 24.59% Heodo
2019-12-19REP vouk1s18noqtwm.docdoc 39c1d85d9122a432fc48e0162b6720734ab8b31d97fad0dcac4d0d6f6517b6a5Virustotal results 24.59% Heodo
2019-12-18doc 5450.docdoc 07ab35a0d78f11f8ea58be35156645e2e83acb0a13e1500f6928143220857c26Virustotal results 24.19% Heodo
2019-12-1812_18_2019 60025091253.docdoc 866e994983ede51d25e1d15f589f8f3e853388f0d7813de5d0641ada4a168a31Virustotal results 26.23% Heodo
2019-12-18info_w3856qkv981l.docdoc 3be9f66ef6e3feb291bca66c44fd8651d392ab19807b9bce1a7fad00d4a518a6Virustotal results 25.00% 
2019-12-18Untitled-file-Q8U3638.docdoc 6998c2f955541d5a517fd68d96604f2ea2efa83d0d1c0a04fa3d09c629bf3e18Virustotal results 24.59% Heodo
2019-12-18scan QP9215.docdoc 540a539653c7a75ee7d4574be240c9619d114d91e73a16c0eb7ff8044b46ca5dVirustotal results 20.97% Heodo
2019-12-18part_N31914.docdoc 7d4dccc23bf9da5fbb6f74c516115a47ab6812b79175db351f6a331dee5c9691Virustotal results 24.59% Heodo
2019-12-18VER 9p9mum9r8p7ls65.docdoc 854d5fd9c1117d7589ba87ffbe6e0016902612837bbd0975a230a5fbb65457f3Virustotal results 24.19% Heodo
2019-12-18ZC162456_44578478.docdoc b940831dd5e63865c557cf3eeeebf1a5b859df61b2b463df2c7aedef04f8ad72Virustotal results 22.95% Heodo
2019-12-18DF106982827 5999872.docdoc a5c388ebbee623f26938d67427170bb063976b1dd0524f6ea18b402809afed4cVirustotal results 21.67% Heodo
2019-12-1812182019.docdoc 438bd7e0c1a2112525ce750cda357b571958c739448d3da46dda55f0ca8e375dVirustotal results 20.34% Heodo
2019-12-18doc_luut694s19q.docdoc a9b41646ad51dd5bc762a07a0efce3c6f5d6f372281699b1ba4747ad29e74c9fn/a Heodo
2019-12-18doc_WC717329436541.docdoc 561126bfb39ff16fe82c097bf9150a1e4b4f4e5674359c8c07bd900befb3378cVirustotal results 45.16% 
2019-12-18copy 3181098.docdoc 9d7854178437a26f14d851e786d68dcdfa005d2010b175103ccf8e1eb106b141Virustotal results 45.90% Heodo