URLhaus Database

You are currently viewing the URLhaus database entry for http://devc.121mk.com/wp-content/PARMRGlRJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:298692
URL: http://devc.121mk.com/wp-content/PARMRGlRJ/
URL Status:Offline
Host: devc.121mk.com
Date added:2020-01-27 09:44:05 UTC
Last online:2020-02-02 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-27 09:46:02 UTC to abuse{at}cubenode[dot]net)
Takedown time:5 days, 22 hours, 59 minutes Bad (down since 2020-02-02 08:45:50 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29Invoice-H33_3534796.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29invoice 7_624576938.docdoc e32cca6446f2ddd8430400b16fc171ab3163cf8222669d7d9144e9c85904d5f5Virustotal results 46.88% Heodo
2020-01-29Invoice-TJI54_176577607.docdoc ce585ca3bbc24cf3e93360b57e2f8f9574cd89823963cd35ae08bb6a252d682fVirustotal results 46.88% Heodo
2020-01-29INVOICE-HUFX0_809887.docdoc 0a84308348fee6bbfe64a9ef23bb9c32cb319bcdf5cf78ddfda4a83dadea4b8eVirustotal results 45.31% Heodo
2020-01-29Inv_257_008220890.docdoc 32753598f94412fe3dc382dc12dcf2edf7881d9f07814c82aeec36481b9362b5Virustotal results 46.03% Heodo
2020-01-29Inv-NKWF39_791049280.docdoc ea3a0a223474592635d1fb7a0731dd28a96381ad2562e3e064f70e2d4830c39dVirustotal results 49.18% Heodo
2020-01-29Inv_CEMW156_0906166.docdoc 849aedf219a4f6ab15e2c5c653a8bbd6fce909c51d2e95984bf6241f6b939e89Virustotal results 48.39% Heodo
2020-01-29Invoice-GE99_2817995.docdoc 1fe8cea2fabc31ad37931e33bdba652c012489533daa90a699e3aee3b8d75b91Virustotal results 49.18% Heodo
2020-01-29Inv-31_04328948.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42Virustotal results 43.55% Heodo
2020-01-28Invoice-3180_999013.docdoc 1f826649cf4d7894c52b645fe736ff139ff80f0e72ebad38385e8882bc545ca8n/a Heodo
2020-01-28INVOICE-FH1088_691988195.docdoc 0617b35ff84886cd395bbf20745f3b82a830d97b07b0085b0f4aa056bcd57cd9Virustotal results 42.19% Heodo
2020-01-28invoice-C437_522586.docdoc 9dbf7690bf328942e99f61b0eae8db502e74c272b7499da4342e6ee7d915bda2Virustotal results 40.32% Heodo
2020-01-28invoice-2360_1982873.docdoc f635c4a870ec9061d6d0d75ad2909b9c7ebe4f21dda6a4c359211fe146df925aVirustotal results 32.26% Heodo
2020-01-28Invoice-502_4922893.docdoc e6551fa9814756f1d99f86fe2713d695e930e5930e397affed4aa07d4ea63ba6Virustotal results 29.69% 
2020-01-28Invoice-64_012727.docdoc 92c3a1a03abdc8976c1b9e1b200a2b08e114d2e6dfa54566f81f16a2671e9735Virustotal results 25.40% Heodo
2020-01-28Invoice_NB2_5100098.docdoc ff71f06910cdebceb665fef3861262fbabd9f92ebd7285926a1b3d4ed3a7c166Virustotal results 26.67% Heodo
2020-01-28Inv_PLHI37_04356206.docdoc a7cd0e0d4371256091f7a81ff6100974822424c0c06e2dd5e07956b1ab62c19eVirustotal results 24.19% Heodo
2020-01-28Invoice-VAAN5966_026414.docdoc 160fe2d4287a96770020461a685816eb0d9ba8b3a3275b86f708784b778f380eVirustotal results 22.58% 
2020-01-28Inv-N4036_024734639.docdoc a6b9f25b3f632a071e548d1e092d8557eedd074094e5e1a2dd684a724fb07fe6Virustotal results 26.98% Heodo
2020-01-28Invoice-W446_13777954.docdoc 32a27468a4355d462e5de6e29290189f023ad6b51836d3134dcb19a74f615f51Virustotal results 25.81% Heodo
2020-01-28INVOICE-NA877_900818.docdoc fcdf9154d769d5e1f3935355b39b57010d978fd2dc9ad24a1df12131f7d34155Virustotal results 26.56% Heodo
2020-01-28INVOICE-F46_01628418.docdoc 42cf3dc2c05800ee63913c2437b824f17dc2999d761edc2c318a7b94fd9ac4a4Virustotal results 22.22% Heodo
2020-01-28Invoice-K6_00533576.docdoc 0f30073111c54d8f89bd3d4c031b77db7d32447f0bee27914ac94ffedc2baef1Virustotal results 23.81% Heodo
2020-01-28Invoice-TZC5267_575236293.docdoc 37f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbVirustotal results 40.32% Heodo
2020-01-28Inv-68_6494447.docdoc 6f7ef2942319a8f55b338d43ac0717e2999baaf867ba160e6cdc15c85b47a4e1Virustotal results 34.43% Heodo
2020-01-28Inv-597_396380412.docdoc 4732690cf746cecd8bd49d095d5514cf185703860490402cc2a5cfbb9e3fadf1Virustotal results 32.26% 
2020-01-27Inv_P95_0519998.docdoc 11c1f2089f30fba10c0d8e7a46d5b5a163acc645ae1ac899f9c1da16fd34d5cdVirustotal results 31.67% Heodo
2020-01-27INVOICE-874_0717308.docdoc cf6fc0c9b296a21a605c029d19eab5d466b785cdc4efb16d18963b598f82ccden/a Heodo
2020-01-27invoice-RLG58_877030565.docdoc b8234c3a29dfe136921812c6011604fac4f3860df104d73b44365fd690d34e17n/a 
2020-01-27Inv-TW3527_559258.docdoc 844e6dce32ab6c95097c5fd947761f9c4c47cd4a18f6f88e94b906eec219b073Virustotal results 21.31% Heodo
2020-01-27Inv-5_763287279.docdoc b08e839fcaa91713751d0ce0fa1ed4f8bdd81ab3803347177886cfc3095440a1Virustotal results 25.40% 
2020-01-27invoice-AD7751_30630347.docdoc ff41ca3c8f2ec42a86f291c2cd1c4b023767b2b41782d20933cc96071bfb168aVirustotal results 25.81% Heodo
2020-01-27Inv-TJR2_99687758.docdoc dfaa827439562eeff34e4ee725e9e1d19ecab21556134361ab102dbb7f41afceVirustotal results 22.58% Heodo
2020-01-27INVOICE_D093_939398.docdoc 0c487e050a7045c40d0a9350685d4b0a63b663c390707a09ebf770ae3a7703d2Virustotal results 25.40% Heodo
2020-01-27INVOICE_30_586251578.docdoc 6cddcfd58c789c8db9ae41d6a91bf3070fa44d597a43db9d3726e6b7bf56a93cVirustotal results 26.98% Heodo
2020-01-27Invoice-RMJ199_505649.docdoc ace8618da66520684eb96d22854978008a5246ec4f1ec58246fe95c99911c5daVirustotal results 22.95% 
2020-01-27Invoice-Z253_334182.docdoc e026510aaee7aa7ee132803cced039b9c93cafad3c767969cbe1373b346c1c48Virustotal results 26.98% Heodo
2020-01-27Invoice_222_8443568.docdoc e6b9b81ce547eec06c402e08fd665a7426c66e956a6f2cc5ed510072bdbb4433n/a Heodo
2020-01-27invoice_89_4686260.docdoc e8884f9a8ae1250edb8efd989f18ad27241735365d3a116519251b6aa3f86358Virustotal results 24.59% Heodo
2020-01-27INVOICE-636_826841616.docdoc 79863d7ceed0d6607a97d4a22918af499c9f49944eb7b69ec07132601038490bVirustotal results 22.95%