URLhaus Database

You are currently viewing the URLhaus database entry for https://blogg-d.azurewebsites.net/8yyqma/tdICds/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308475
URL: https://blogg-d.azurewebsites.net/8yyqma/tdICds/
URL Status:Offline
Host: blogg-d.azurewebsites.net
Date added:2020-02-04 22:54:08 UTC
Last online:2020-02-19 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-04 22:56:03 UTC to abuse{at}microsoft[dot]com)
Takedown time:14 days, 13 hours, 27 minutes Bad (down since 2020-02-19 12:23:41 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06INVOICE_KB5_663816.docdoc cd94bedf130a17e90a8745d2c98b66c2f0c2255df9b65f040a7c6631cc8b2737Virustotal results 29.51% Heodo
2020-02-06INVOICE-WDXE5555_812813878.docdoc a91eba1db4ddcc5437aec16814c764bd4fb7d18f221f84031177016e8e52066aVirustotal results 29.51% 
2020-02-06invoice 52_841579.docdoc fbccd622c1dd3d84621bbdc63975f6a57fd06bb79c310e15b469beed436acb64n/a Heodo
2020-02-06Inv E98_756024.docdoc cf97fc92739f7d431c0d391d38dfe6096c9fb8689a40a8754a5bdcfba6f97fbbn/a 
2020-02-06invoice_GTXZ5892_2725735.docdoc 08a17a2ca774e5d63d00d6347ab8569354e6fc33b9e65cd55db64f088125e77fn/a Heodo
2020-02-06INVOICE F7361_82875542.docdoc a22067b37f97aa4ed866b27ae8891c6af526a3b0ef093d55e638577cf66567cbn/a 
2020-02-06INVOICE-KEMN775_74535062.docdoc 925ae322b24b7f2d6d39b258388984c572fb6e83dfa782e4895c576f26b76198Virustotal results 27.87% 
2020-02-06INVOICE-ZN5_5975021.docdoc c6a19d8526d12dc6f0c7c0510b8bb00a575ca52dad8d3aef5f4d90284a2d9877Virustotal results 25.00% Heodo
2020-02-06Inv-929_94048076.docdoc 73d5d0a00e3a8623803f215d801fb07104976f2f8da3f8185c1b0015b1c19ff6Virustotal results 26.23% Heodo
2020-02-06Inv PT5929_690035035.docdoc d8a98e712d6775091bbcdbe1e2b1ed30135d7fcb59a9ec4ce71bd80823438c5aVirustotal results 23.33% 
2020-02-06Inv_VFFJ4_793986923.docdoc 1ffc37048962c0a22202bc9de2da7dc6a958458986126b58248ab622cd695f7dVirustotal results 21.67% Heodo
2020-02-06invoice_EZ574_4116923.docdoc e2e9245eaaec1a1307df8261bd08e848ed4e0fa14b09ceaa2343646364a1f76fVirustotal results 21.67% Heodo
2020-02-06Invoice-OL68_221846289.docdoc 67617db60beb8c4cce54db289e3d3a8406049516de95ccc8940b0d1735caa144Virustotal results 20.97% Heodo
2020-02-06Inv C3214_020729157.docdoc fd7c8c6cf457d1d127ee24d40ea990ccae1f8f8e8c648e61c760124a04dd4941Virustotal results 22.95% Heodo
2020-02-06Invoice 66_9072289.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06Invoice-EGZI5716_6776124.docdoc 4a620a4453c5b138b1c90c5bb3db067135faef7ad7106666379edaa77f38ae06n/a Heodo
2020-02-06Inv_ZV52_28230612.docdoc 9eca08bea00fec73f8bdc769abf28f857d39de7d922c4d0dfd4017dc5981d2b0Virustotal results 33.33% Heodo
2020-02-06Inv-UBRT08_803033607.docdoc f64c7b18189347af96b402b6f3cb3294d4dbbc7cad63748805727ac4d2a83997Virustotal results 32.79% Heodo
2020-02-06INVOICE_4060_928989.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05Invoice WA0588_900900930.docdoc 23bfb58c53002a4c03a4931e057316564e8ccab64975f93e2d66ceca6c73f7afn/a Heodo
2020-02-05INVOICE P053_15206477.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05Invoice JJ7441_2228753.docdoc 2e6d60c0292605697751fd56084cb10b9ab90c135dd863bf3e428a185e050142n/a Heodo
2020-02-05Invoice-XPKK534_919011024.docdoc 6d5225b0982f192c99503ae1e58b74554f78452462dc9d2574aa266355967658Virustotal results 26.23% Heodo
2020-02-05Inv YKN81_493023868.docdoc a2de78a3a39c2c5d3d3c617de7f83a6ee2ba59eeb411de1095a208d4b21ecffen/a Heodo
2020-02-05Invoice-W33_613232.docdoc 8dc01e779aa14fa6b5e6df7f2cad4edbfa0f3cb078f9022861e1676032329056Virustotal results 26.67% Heodo
2020-02-05Inv-9941_299702.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05INVOICE Q0_05384811.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05INVOICE-UX1408_48686374.docdoc 927609b9f9efb576a2233015595d50cfecd6d736c6fda23e8742330c6051e64cVirustotal results 25.81% Heodo
2020-02-05invoice_HRX4_7677027.docdoc 3d86715a18dc19cdf1364d58ff7deee2c387cde502de5b43166a7c0d98b2a24an/a Heodo
2020-02-05Invoice-3_792020164.docdoc dc0402b2e8b444ac6695dd0686b697822b5c339fb556f63aaf4cb4dce9354572Virustotal results 27.12% Heodo
2020-02-05invoice-545_17303681.docdoc fa5927f2181dbeaef9cab75616169a02fe02b41df92e598cabad444619c3befcVirustotal results 26.23% Heodo
2020-02-05Inv-MS466_890058.docdoc 6e6b6b51d4a9dd7f74e82c53490f95ead4a4d2a9a4adb06f1cbd991bc2b225a7Virustotal results 33.33% Heodo
2020-02-05Invoice_PHN4287_895746.docdoc 471942cfd9aa93923bc0f054e64201217913ae24a3e192919207202918c628fcVirustotal results 32.26% Heodo
2020-02-05invoice_AAO73_296094.docdoc b9d42e016bb94271c9d10c7c68d438ead1f0078d3b0fe039da3166ed9f29432eVirustotal results 41.27% Heodo
2020-02-05invoice AAB1_8483144.docdoc d75ed2fd2d6309cc650cb4ba8181b95f1569241f0ec8fcfd8706b1ed4b5bf05bVirustotal results 35.48% Heodo
2020-02-05INVOICE_676_69895576.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04INVOICE-OOAW3_60633980.docdoc 53f5f987926ff0274559f310cd6f0893486a7b4107168dd570591b6b429fc2acn/a Heodo
2020-02-04INVOICE OM813_0811117.docdoc 4cdac2f4d63304355834be949d3daa22b6de9607436c0f5cbe758f86c05c5b72Virustotal results 33.33% Heodo