URLhaus Database

You are currently viewing the URLhaus database entry for https://www.progymrd.com/b0f45aec027284c2ee5cd3940b040b12/atNAetJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287384
URL: https://www.progymrd.com/b0f45aec027284c2ee5cd3940b040b12/atNAetJ/
URL Status:Offline
Host: www.progymrd.com
Date added:2020-01-13 20:45:37 UTC
Last online:2020-01-21 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002242896 created on 2020-01-13 20:46:05 UTC)
Takedown time:8 days, 0 hours, 2 minutes Bad (down since 2020-01-21 20:48:43 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-15invoice-RN65_9794.docdoc 7a1bb65a845c067f7a327d08097b85e17646c11d6f7b226176e89d16474d54b4Virustotal results 36.07% Heodo
2020-01-15Inv EI223_66.docdoc ced74a717f09aa4ee30f883e7140c28a91a1911384510acf14127ecd77ae577cVirustotal results 35.48% Heodo
2020-01-15invoice-BPM826_13730.docdoc 1a86b0027ed894d1cdf56b5880263c545a5fced00774690756a6c3c0a86cb013Virustotal results 29.51% Heodo
2020-01-15INVOICE-EC709_991.docdoc c878d796e888019c69ef646177d2687214c5bbc0a0d47d80b575bd156668f5ebVirustotal results 22.50% Heodo
2020-01-15Invoice_S12_8927.docdoc 010d4daa4dffe83b54b6d3f489493476cf3de236ff55914f90d2750df262e52dVirustotal results 24.19% Heodo
2020-01-15invoice SH84_47850.docdoc 78a310a044510fc979e903828bdc3831844a04b5c01b34397e52e3bd62c96674Virustotal results 20.97% 
2020-01-15Inv_AFD409_20705.docdoc 312ee8dc3ed3f60c8e3c5bc0fdb8fcd5c74b9ebf691b873b18461421280bd04bVirustotal results 21.31% Heodo
2020-01-15Inv K16_135.docdoc b7d6a9d883ceb3098ae6e82cb15a930133fd838486587f4f1fee1145cfc87b3eVirustotal results 22.95% 
2020-01-15Inv-RJ473_664.docdoc 6223fba003639527f555cc2407a49f113dc4b915ab798b630fa7ab7e28dac94fVirustotal results 18.03% Heodo
2020-01-15Invoice-XCY39_3061.docdoc 0be95290124a09aa4fb39e3c9069ee6c8078349d8fedc5694c2bf8e6291b4839n/a Heodo
2020-01-15Invoice-IK685_625.docdoc 8286cb8a72b77a5dacae5e1e4d7cf07916449ea76edbb706d7be01b6282b4968Virustotal results 17.74% Heodo
2020-01-14INVOICE_CIO700_3299.docdoc c912fbd5e3979ce3299c6cab4db775c4d86fcd1c779d4c2b402931f558484d99Virustotal results 16.67% Heodo
2020-01-14Invoice-FJH070_85578.docdoc e78d9c58e591afb77d784cf72f005f0a03662ebf8a8480a76ff8b960004bda6eVirustotal results 18.64% Heodo
2020-01-14Invoice-W637_911.docdoc 574b2bb421e5876d279f08a21722a49102902d0a532730dc18a0051a9b53067fVirustotal results 18.03% Heodo
2020-01-14Inv-W32_6787.docdoc 166bbaedc5517c3d760fd2c906f300c7ba083535fd72f852c9f2e13691183f1aVirustotal results 16.13% Heodo
2020-01-14Inv-NK40_19750.docdoc ac22656075380fa9c45ac9f52abd162c09cfa2af5a7b7cc2e671f194ddbfaf5dn/a Heodo
2020-01-14Inv-W317_42.docdoc 75eb88048fa201b46d96cca9fa12f4b4917232c3d963596554a6970d007a639eVirustotal results 13.33% Heodo
2020-01-14INVOICE_DD009_210.docdoc 04899f2e89a00a9e6b019c7af86a24dd72d98328c91a7ba3a1a4e99d59f41e85Virustotal results 12.90% Heodo
2020-01-14invoice_S08_2070.docdoc c9e03d9b15a357f412a9ea5302fa6183e4f06d8ace5d5b43dd1cb67d11e0146dVirustotal results 13.11% Heodo
2020-01-14INVOICE-QXY15_04.docdoc d50fb4d2b5aeca55182160f95f244527af5d00d92c8e760906394e338cfbe992n/a Heodo
2020-01-14Inv KL34_0229.docdoc c6060900e3b43701a22cfe16c2259647be6b08b8a90e145aa99e89c19d568ac0Virustotal results 15.00% Heodo
2020-01-14Invoice M137_8560.docdoc 67f8c63d4fa5c53c9fff164f962b16abe128d2b038e10f5bcacafa2e446788ffVirustotal results 21.31% Heodo
2020-01-14Inv-R649_478.docdoc 61ef44b898c732da0b07cc34493e971778b8835edd28386161473dd228025581Virustotal results 18.33% Heodo
2020-01-14Invoice_QC68_62246.docdoc 680d885e100dd48bf1af8ca6818fbf9b94cb5c78d80da12a4e3c6a5f6fffc951n/a 
2020-01-14INVOICE GPY473_169.docdoc fae7e292b443e97b48949f711e94e1ee3c23e5e01cdcb3d890bb6c20d459d756Virustotal results 38.71% Heodo
2020-01-14INVOICE XQN137_1284.docdoc cf670c15f960413e27bc98672efa1e7014f58c8f4bbc6423425f626e884ef523Virustotal results 36.67% Heodo
2020-01-14invoice-UXI21_5423.docdoc 798e9969ecb0e43bfaa34fca93c9dc6719bd3ac63068fcb7fb676afcbfd1c3d9Virustotal results 44.83% Heodo
2020-01-14invoice YIW26_0441.docdoc bbec91babc2513939b05530c6c50549b7d096c7bbd57e557b07d145f9d2c66e8Virustotal results 26.23% 
2020-01-14Inv EJ19_27.docdoc 18b7a070ad16b8cfff48c011226af98c8df66202cf67b83d9229cad680bd053eVirustotal results 25.81% Heodo
2020-01-13Invoice-F97_119.docdoc 4aefe00954db74f1af15ce84c91567c239d1081b3c8bd1b08477da705db7a5f9Virustotal results 38.71% Heodo
2020-01-13INVOICE-X18_5297.docdoc 0cc8aa9425011bd359ce2f1c6436de0f9c496296266a11741a4898687aea2fbdVirustotal results 35.48% Heodo
2020-01-13INVOICE STD78_29101.docdoc 273658cb6f95ae9ec4c1697e2e3552a9fd5e85996691be591edd20beb0897359Virustotal results 31.58% Heodo
2020-01-13Invoice NG04_36.docdoc ea4b88bf559b80ac8e9ddd60bcd0a1d97c422f0c84eae0661606eec3d4dfecean/a Heodo