URLhaus Database

You are currently viewing the URLhaus database entry for http://paramount.edu/JU-4843734/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3161
URL: http://paramount.edu/JU-4843734/
URL Status:Offline
Host: paramount.edu
Date added:2018-04-06 05:49:26 UTC
Last online:2018-09-08 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: cocaman
Abuse complaint sent (?): Yes (2018-06-11 10:47:53 UTC to abuse{at}newtekone[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-04-18CG-89888608580.docdoc ea036a4e07795cc164463e195031d10c130a6ee7176aee37002890c913c1f5dcVirustotal results 61.02% Heodo
2018-04-07ZZK-9559792867858.docdoc ea036a4e07795cc164463e195031d10c130a6ee7176aee37002890c913c1f5dcVirustotal results 17.54% Heodo
2018-04-06VDL-580994427508765.docdoc 14b5e36e66e149a4c2abe4c4d6a9d0c5f02155b4f47778fb228f2c325dd8e3a2Virustotal results 10.71% Heodo
2018-04-06CMM-5449701981223.docdoc de045d1fc27006c6afff001d766604b47bc934da697cd01413cf6eba505382e0Virustotal results 11.86% Heodo
2018-04-06BD-823615479818.docdoc b17d906024b15f1e0998c7eae0adc8afb537bd6b21fbd757369312a681cbfc23Virustotal results 8.62% Heodo
2018-04-06OL-63697815427325.docdoc 3fa491121719371e32e5bc30bad48ba40966df9288c37e3c6ca379a09ee4a3c0Virustotal results 17.24% Heodo