URLhaus Database

You are currently viewing the URLhaus database entry for http://www.paulclammer.com/wp-admin/sjLCD/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307584
URL: http://www.paulclammer.com/wp-admin/sjLCD/
URL Status:Offline
Host: www.paulclammer.com
Date added:2020-02-04 08:27:03 UTC
Last online:2020-02-05 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-04 08:28:04 UTC to abuse{at}oneandone[dot]net)
Takedown time:1 day, 0 hours, 10 minutes Poor (down since 2020-02-05 08:38:55 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05INVOICE QT5894_92409388.docdoc 5b722d48257afc181ff557247576f41effaf72855ab262578b02cf1618e89ee3Virustotal results 26.23% Heodo
2020-02-05invoice-Z680_85991972.docdoc 883ccb008ab99500f06083ce5fffa69c29db0131240c30e3c04a159a08d175c9Virustotal results 33.33% Heodo
2020-02-05Inv JWG4631_89844556.docdoc d753eaf7b22aea01dd44dfba5b9fc26ebb5677f4a713b4afa69d8c34efe836f0Virustotal results 33.33% Heodo
2020-02-05INVOICE-R428_7418865.docdoc 251634753472a0f5fffce161c8c997b7ff91e76ec48b414e29737b4dc5b747e8Virustotal results 32.26% 
2020-02-05INVOICE-87_8449963.docdoc 33cc0ed116c8fd0f8a0ba59014bcf2a4a04a33356cca62ce27cbf6917ef1155fVirustotal results 42.86% 
2020-02-05INVOICE-YPQK40_6689420.docdoc 25d98e7b0341be2da85f8fbbe279863673a1b0744c9773c8f6bcaa0c0666c935Virustotal results 34.92% Heodo
2020-02-05Inv-O1412_923132.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04Inv_ZCV161_115342.docdoc c01faf044c1df797bde7ae50e931236add55e532401115f33435ad6802eeb184Virustotal results 33.87% Heodo
2020-02-04INVOICE 768_98895863.docdoc 6e6b6b51d4a9dd7f74e82c53490f95ead4a4d2a9a4adb06f1cbd991bc2b225a7Virustotal results 33.33% Heodo
2020-02-04invoice-F967_1988641.docdoc b36bb787097054921d1c91c8f9e839df7b8452550425a9f7df8bad8460bf085bVirustotal results 33.87% Heodo
2020-02-04INVOICE_K89_439762930.docdoc 9cf373c9a2dc126d14647d1c4f9bd6a554335f4f00f76b6ad0ce24dff7d1c054Virustotal results 33.87% Heodo
2020-02-04invoice_JKP28_88706040.docdoc 03657e4b0103d718978b4736846da1ebdd18f8ba892ff4709eabbae4d7f14c10Virustotal results 33.33% Heodo
2020-02-04Inv_UCHY380_681610563.docdoc 782ee01276002a63861c3f58a7b78787665649db336540048aabccb667e890dcVirustotal results 31.75% Heodo
2020-02-04Inv-76_329249956.docdoc 40c57139f9fe475f5e06542c48aac3476cd943f3530f73ef44a60db380bf9e04Virustotal results 38.10% Heodo
2020-02-04Inv WF9_789951329.docdoc 4f82639e01a29db574eb24d0c64e0446eec7f31119bc818b1b45e97a8ad50768Virustotal results 38.71% Heodo
2020-02-04INVOICE-BHL8936_2829073.docdoc 1173cf1516a39c758a543aa77e5efb97ae7c0405e4d4921939f774fe9a48be41Virustotal results 38.71% Heodo
2020-02-04invoice-U7555_016157678.docdoc 90c26b84456ef49591e93a848e25f662c833cfe38dd5576c91c6e1f1aa1518ebVirustotal results 38.10% Heodo
2020-02-04INVOICE-KRS1276_41298370.docdoc 32205c6e3940af055c6164bb249b544737778db9e0ee965daf226efedfe861d7Virustotal results 37.70% Heodo
2020-02-04Inv-EJ5_168129.docdoc c6f67345d51de31d968f542885d815a518e46ae16c2629694893cceceb18ff3cn/a Heodo
2020-02-04INVOICE 689_014001811.docdoc 83823f09462da02e461e5c8f663c0c2328a6a08bc1f1cff138d77055020c545fVirustotal results 35.48% 
2020-02-04invoice SQA303_1967734.docdoc afe31791fd85a56e44bdc5261af1e3c237392614029d439e9421a09d348bc389Virustotal results 34.92% 
2020-02-04invoice-BLC9921_9562147.docdoc 1b8a59f4d318378567b315680008eef2c0d1b976713902b43d63404b39e5e22fVirustotal results 35.48% Heodo
2020-02-04invoice-AU5_1613413.docdoc a49577b046e212d4060cdf4d911cefe39f32ed7d6dcc75d2b8913c82b7a124c0Virustotal results 33.33% Heodo