URLhaus Database

You are currently viewing the URLhaus database entry for http://app.trafficivy.com/wp-content/zopdvm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300871
URL: http://app.trafficivy.com/wp-content/zopdvm/
URL Status:Offline
Host: app.trafficivy.com
Date added:2020-01-29 06:16:05 UTC
Last online:2020-02-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 06:18:02 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:13 days, 1 hours, 9 minutes Bad (down since 2020-02-11 07:27:21 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31Invoice FLH1_33110794.docdoc 7520f696c405469515a806385d54d83b2861501687a91bb899a29bd3bdf664ffVirustotal results 34.92% 
2020-01-31INVOICE-KWC786_455071631.docdoc 943444f98f1bb22118cddf2198722733aa216ad0aa313ece459ae6e268a9e2c0Virustotal results 35.48% Heodo
2020-01-31INVOICE_CHGC379_792021.docdoc 813226187f75c12909c10d00dfafe96c916ad768979a68def760048753fdea9eVirustotal results 34.38% 
2020-01-31Inv-LJWY76_1863317.docdoc 797c8a01976f70efa8f735c4a8f0d80a805578978d7f025c204d3e99a1a67d29Virustotal results 33.33% Heodo
2020-01-31INVOICE-ASYV597_346801616.docdoc 9931f06412385e83080f75415b9fba75bafafe36cb481e478b635d4dca29d0f3Virustotal results 33.33% 
2020-01-31Inv_L2212_825532378.docdoc 8dece0d2130198c1d3acb7688f96392e3ded40745d7d8f7c01f03337209801f9Virustotal results 34.38% Downloader.Upatre
2020-01-31Inv 735_697012885.docdoc ae370246a5b55b8f9dc4d3d0d7041d03f466f3d4260bf0beb48ff4dfa85a5b11Virustotal results 34.92% Heodo
2020-01-30INVOICE GI913_985899469.docdoc c7970448dd12285750ec5d562765c8f494b15914f9699cc95a46f4b249f5f370Virustotal results 35.09% Heodo
2020-01-30INVOICE-KJ073_6067651.docdoc 7d6d03203cda13942959101d4487c86fa9d270163e2d4800debe50da466398a0Virustotal results 34.38% Heodo
2020-01-30Inv-QY860_00664360.docdoc 9e5e33a967ae502e2a528fd31502336cc68f2deff565b4760bc2eee148ae87f7Virustotal results 35.48% 
2020-01-30invoice_ZY56_21510859.docdoc 0cd2361c959ed9e7e67f305e10241dac8c04cf6aa8816a02fa0ecd57f3b8e66eVirustotal results 35.00% 
2020-01-30invoice 0909_786690623.docdoc 9d23b6da889229ad96e4d4ac90dd6c382fca9006273b8de6254bd3fe1415f403n/a Heodo
2020-01-30INVOICE-CI742_0712252.docdoc 17a7596a2561b8ff8cc3bf7daffec3ebf35525aa363d4659cb420d42f4af92f3Virustotal results 38.10% Heodo
2020-01-30INVOICE_B8932_00330111.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30Invoice WS693_411695.docdoc f274292ec06934b8c2417a6103a2558010703119785efb96e2443e57f4e1c658Virustotal results 34.38% Heodo
2020-01-30INVOICE_Z31_5343585.docdoc 9440498706f2d925d78ed85c677ee615fe3fdf05c7188cf59cadf543e59e0c32Virustotal results 32.81% Heodo
2020-01-30Invoice VFK6_9096207.docdoc e88c11fe26e7cad165df54049eeb12ea47f3cbb684fb6f8a5235d4a379e646ddVirustotal results 31.75% Heodo
2020-01-29invoice-W6944_173974451.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29Invoice-VZ90_417737.docdoc e14bd51bea91be160aefdfd75c853ce85ef348e87400f0d1e14b64c7d46eb748Virustotal results 33.87% Heodo
2020-01-29invoice-RN0_92027949.docdoc 829a7809009f98e48474acb1055638a301574dc66340f546a4f96029e8a6cb9aVirustotal results 29.03% Heodo
2020-01-29Inv_A5_293655710.docdoc 0e7d6a780c7dedc2d2625158cde219a2df7eb7b37a509c810644085e1781eb12Virustotal results 29.69% Heodo
2020-01-29Invoice DTMT675_098683500.docdoc 7bfcb28623bb456b78495610797c508f2f0d900d9f5917557ef2e021b03f4349Virustotal results 27.42% Heodo
2020-01-29INVOICE_GZLR26_561526191.docdoc 3025dd0f7c5bcce361eb76f350f7313e70bb8d2b908d2edf67b9494b934c8f7fVirustotal results 26.98% Heodo
2020-01-29invoice-9_548829.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 26.23% 
2020-01-29invoice-XQYE7_81174898.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29Invoice_PCS64_4155966.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29invoice 013_61376857.docdoc e8f8cbc324e2601a0d32232c887aa398adfc45984b6a254666b95a1c00ef496aVirustotal results 30.00% Heodo
2020-01-29Invoice_HFV89_152609743.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice-5926_4814317.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-29Inv-XR1418_69584081.docdoc 1c3532d143212078e204d0f81a782deacd58e8f0e7253472e0509491fd1e5201Virustotal results 46.77% Heodo