URLhaus Database

You are currently viewing the URLhaus database entry for http://xn----btbmbi1bg.xn--p1ai/wp-content/personal-zone/guarded-area/4944062669-Ubdcc1C3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303632
URL: http://xn----btbmbi1bg.xn--p1ai/wp-content/personal-zone/guarded-area/4944062669-Ubdcc1C3/
URL Status:Offline
Host: пож-без.рф
Date added:2020-01-31 04:01:05 UTC
Last online:2020-02-06 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-31 04:02:02 UTC to abusencc{at}interserver[dot]net)
Takedown time:6 days, 2 hours, 4 minutes Bad (down since 2020-02-06 06:06:15 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-02Arc_2020_01_31_QA283647.docdoc b8f61b7051e5cb28a6f514db68d873b863f74324defa9d63a2ee00cbed32c509Virustotal results 33.33% Heodo
2020-01-31LIST 2020_01_31 R674017.docdoc 31ad07da3bccaaebc18676212e40fcd30a280ae55fd101eb55e89302c9532580Virustotal results 26.98% Heodo
2020-01-31Arc 20200131 EN871.docdoc 7b8b820eea5aaf7759404bcf53ca9979080ea061ab4523593b1f5e2e8db6f5ccVirustotal results 25.00% Heodo
2020-01-31FILE_92181.docdoc 98d4100547490c9809f92a82a3afc57c4927ce1e84664bad304d005b9754a02fVirustotal results 20.63% Heodo
2020-01-31INF-505893.docdoc 91275159f80eeb0eff909660f56290704daffd027e4b5725ef33573c925488a4Virustotal results 20.31% Heodo
2020-01-31List KX300.docdoc e7863425cfe23c40a2c40e179c1bd67eba047602a382158bb9458b1f52cbeec4Virustotal results 20.97% Heodo
2020-01-31Doc 2020_01_31.docdoc 9fb0a6fe332aeb878af094ebb838b45e25773204f45c299a2c31fa1070c7d80bn/a Heodo
2020-01-31REP.docdoc 9ab30abebfdb3619b5253d44a3e4b928ad5d7ae3a1af4c5634f3b1faa7e675a2Virustotal results 20.31% Heodo
2020-01-31FILE 20200131 XGR156399.docdoc 1927c895365ce9eb0b850ccab2180fd7d46e42b647113981b953bd353c6edad6Virustotal results 20.31% Heodo
2020-01-31mes_20200131_XS812.docdoc 3ad1ce31e5fd92383ef10bfd1ef62d5163e305c89f3b23ec9a266a18cd8a0fdan/a Heodo
2020-01-31mes J381.docdoc 3cc04f77aac8a4cda9d58d7ac08cc46443898774556b200a1fe78f26fcd46be8n/a Heodo
2020-01-31doc-HAK110.docdoc a5a1cad504ed2881f3206bcc602f7e379d15cd59082cac926f2fd286257ca9can/a Heodo
2020-01-31file_20200131_N844.docdoc db5ec50aa0307b01efda63c0c839ca56003ecb0cf9e97153c79a15f8c7954de7n/a Heodo
2020-01-31DAT_2020_01_31.docdoc 994ab85c2ed2004c1ac4b7eb7b3300ed9453ac6f02787c92e226c3cfb19cc939Virustotal results 38.10% Heodo