URLhaus Database

You are currently viewing the URLhaus database entry for http://axis-map.com/wp-admin/RGL440CNC/r2j3ky01ozlu/573113743626774500sei4uvc2z5f5p2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415294
URL: http://axis-map.com/wp-admin/RGL440CNC/r2j3ky01ozlu/573113743626774500sei4uvc2z5f5p2/
URL Status:Offline
Host: axis-map.com
Date added:2020-07-20 15:15:09 UTC
Last online:2020-07-21 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 15:16:02 UTC to abuse{at}ovh[dot]net)
Takedown time:17 hours, 35 minutes Good (down since 2020-07-21 08:51:41 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-2103922205.docdoc 59e827ab690ebe0398ef2409db0e89fd63ebe9c9a198ed0cd9febc218813f6a1Virustotal results 22.03% Heodo
2020-07-21M_PO_07212020EX.docdoc db38d38b8c391434f4ddb964a8737400a96eff22fa39ecfb74eabdc785bbfe30Virustotal results 22.03% Heodo
2020-07-21INV_FBZ8KUC3MHEC.docdoc 8b448dc2b315f49801c7b4d4b20a2d3163f9c9376a3c36dc4dc7a52513a101f0Virustotal results 22.95% 
2020-07-21FILE_01119748.docdoc 660ff4d3124a99db58894556a3461eda17393ca94c27e075185e72536eb6735en/a Heodo
2020-07-21INV_CK8353548802WC.docdoc fc2bb7719f33ff249113e3c05c4b2b6fdbc99190e250b3073295e271c553f0d0Virustotal results 32.26%Heodo
2020-07-21M_55L1NOLQ2N0.docdoc d604f20c04d25e448176ddfdf3e01865091590cdf5f2cd2c42eb9af7cf41c718Virustotal results 33.90% Heodo
2020-07-21F_67604779.docdoc 53b9a409018adc25ac26a608d9fae417659211d8754dbf7f07c3e4710a026774Virustotal results 32.79% 
2020-07-21BAQ_070120_ZDN_072120.docdoc f23c88283a5b29e45eb6658afb904be03923f73895e4f6b232f3e04e288bb715n/a 
2020-07-21O_0847497592752.docdoc 9312e2d0d00f48b53f5ce88ad3c874968ebb3c219e93cf1c5848021de545956aVirustotal results 31.67% 
2020-07-21EOL_454303427610512.docdoc 9e8362c34f689302d747bee833e604d4d7e10c7d519b401e9c9fe257bc241197Virustotal results 32.20% Heodo
2020-07-21L_DAT_070120_ZWY_072120.docdoc c9d9cfb4d6f95d66b6480f5dfb60edf7b0c4581895b68dbf25a830f9006b2d3bVirustotal results 31.67% 
2020-07-21INV_91731076.docdoc 98f9e3f351ef4ad0fa44e42564bff893ca18599495d514658ebc5bcc78534dd6Virustotal results 30.65% Heodo
2020-07-21FILE_J4WPGU7VAUDKEM7Q.docdoc d6c5ff0dea2cbabf074ec5c1f7ca759925d9f469a37d4265919edf2414c60d5bn/a 
2020-07-21REP_16588876.docdoc 6d7c0327ef758d90e34d8e64f95ea11431fc630f904b95f33141ced30a743dc1Virustotal results 31.15% 
2020-07-2124161425.docdoc 296943dcba8c391e81d42bf4b7887bd2929bfa9cb511d3e1a9056ca64013f00fn/a 
2020-07-21J_IP6972559758BE.docdoc 74fdca7126b9d049956422f500ca2a0257fb7956f385a45c6b5c36230fd3a2a5Virustotal results 28.33% 
2020-07-21DOC_88524052551984.docdoc 0d1316502220cb6dd888dfe5bf248b70b28dc8eb3518f1cf98737edd5b62aa74Virustotal results 28.33% Heodo
2020-07-21Y_7LGY1FCVG1W3UB.docdoc a7f4f8b9dddb70414bfdbbffd5c446c88b517c104a441be19151c8a711133686Virustotal results 27.42% 
2020-07-21Y_PO_07212020EX.docdoc 9f082f2eeb02660ab639991cade576f8a7f72990579ddb87315b51374e11fc18Virustotal results 27.87% Heodo
2020-07-21KWQ_070120_HZT_072120.docdoc cff09d732ea9fe1f128dc29bff9f5d5d8ff78ea22eadb52fa4b5b8d7c056928bVirustotal results 27.42% 
2020-07-20FILE_UQL_070120_TGG_072120.docdoc 1d9333d44f7442890d84cbc3972b9d00c93bf1556042f7b58c1386365eae3c76n/a 
2020-07-20INV_D8FZQLTE14ZBRF.docdoc 2a7edcd4009ca88459bd2ec64af866f700abb7acb68cc5b13a40315c51976df7Virustotal results 28.33% 
2020-07-20IPPG_NL0SWX6F.docdoc d94cea8ea634ed8d8de82348acb5c417260d48a0f2b559531624b67f776c660cn/a Heodo
2020-07-2074417532.docdoc db25e5d9d7e9141385c443268866698c14432d243af5aee0906b93bf713ff820Virustotal results 29.03% Heodo
2020-07-20REP_PO_07212020EX.docdoc fc5b7108a0eaca8bbecdbea0d3405756a6cdb3dc9911363730b275e1e29acc4fn/a Heodo
2020-07-20BE8751117124HT.docdoc 4ec7f2a0359b740dbbc849705f2856818bccc8fafa5a2237fd79640e61423255n/a 
2020-07-20REP_77083584.docdoc a6ce3b9c522d36ac4e91cf8e2cf1581bc9d7e6548f1e66ff998e11662f6894cbn/aHeodo
2020-07-20REP_WE4481423320BG.docdoc 148aa06dceabdc99c7588bd48277867f3d0528fcf04463562707fd66f953045dVirustotal results 27.42% ZLoader
2020-07-20DOC_BAQ_070120_GEZ_072120.docdoc 7b6a3b4d5f51807fa19a536a4a2400dd3279b75a75ba37423ab27c6937aee30fVirustotal results 27.87% Heodo
2020-07-20H_POBLAO1403GQUUJ9.docdoc cfb6588d9181a97aa1f93b2b9f8af82134836e916938a80a217cd03fe4294811n/a Heodo
2020-07-20REP_XYI_070120_IBF_072120.docdoc 401dadd7c1211dae181b8767949d274790aa4fb72e78a3d57ae92ac2cf925da8Virustotal results 27.87% 
2020-07-20BAL_RE7264473440DS.docdoc 8163146178e6d55057843fa5f0da1b851d049bf802aea69b44aaec7352be33d4n/a Heodo
2020-07-2091854825.docdoc 33c897cc3c1d11687231644af13032e24358c594f4b484a7040a3eeecfae7145Virustotal results 27.87% 
2020-07-20A_F85WS32V1UQIVLE.docdoc 4fdba539896383e37ec2383fb569df4f17395dd40115ba8caba62127b7ebe949Virustotal results 28.33% Heodo
2020-07-20WPG_070120_FRW_072020.docdoc a00bd0c41a60173a7d02bec198e21b3be8ce018289a2120a48b3cea32160de78Virustotal results 27.42% Heodo
2020-07-20INV_85824883.docdoc 265c8a20b2d97de3e6464bbc718b00cb55562ca2512c7ca4f8fd6034613fff53Virustotal results 24.19% 
2020-07-20WSEY_UFT104X.docdoc 021aa9ae780b058779de8a93eb224c78e1d856ebd0bf6a3de8810e1b20e88f7fVirustotal results 26.23% Heodo
2020-07-20DOC_PO_07202020EX.docdoc f479686dfc59c7e2cf8607ef958b067288d47d2de6a92db1b0c1268b9862f42bn/a 
2020-07-20REP_887318420487.docdoc 69167697c3c077b3ca6449ae55750d1712c20bc33196537fdbbe05e463aab195Virustotal results 27.42% 
2020-07-20OESL_06291719.docdoc 1e146c18d65265b27e23f9ee84a8f1d20c046aa76c30ed386710a10cb0da2960Virustotal results 27.87% 
2020-07-20INV_PO_07202020EX.docdoc 9ea223e9251e17c155c00e320f9f1008c6872573da7a16d524213225ebec9addVirustotal results 25.81% Heodo
2020-07-20IVNR_ZN7N3CQY.docdoc 4d4dde2b4708fc336d7f1450e624c14cb25a836d5081855b17a1166a8b1b2521Virustotal results 26.67% Heodo
2020-07-20DOC_RQ4250115285ZQ.docdoc 16a986a19d026da35781703a1baa7901b7c796b6a56c4cb47d21b741c9b47291Virustotal results 25.81% Heodo
2020-07-20INV_PO_07202020EX.docdoc dfd60a37d9d7dc24e9302548219fc2547abf5a5cf7a6f4df5812bd4c737c7f69Virustotal results 25.81% Heodo
2020-07-20INV_80542517.docdoc 6184126e3453b754392ed6f6123957890870d807b6f67d16cac4116de881e3bcn/a Heodo
2020-07-20INV_PO_07202020EX.docdoc 0fee9dff045cb53ab19cad51113a8af4f6b38c19b46c50150f606626fd1a42c9Virustotal results 25.81% Heodo
2020-07-20FILE_EXB33OU5U7M9.docdoc fdc3a5d1febd58ec001ec2e119bc2756b8518c289478484bae758ac45c964e59Virustotal results 24.19% 
2020-07-20REP_PO_07202020EX.docdoc 15fe975d4b69b43d4f2a72a301e2eb1beb12fb709d0cf36259e10950b30d0fa6Virustotal results 25.00% 
2020-07-20LKX_070120_NSO_072020.docdoc 932c549927ea5c0ce827253fcb26978c1361cfbee3495d9dde5130ba190dd3b5Virustotal results 24.19% 
2020-07-20FT1498612544YL.docdoc 9916b4a492b19650f59d73747d3b28cd2e996ea9e6ea86675534a17b52c01bb9n/a 
2020-07-20DOC_NJO_070120_EUG_072020.docdoc 80b106f0a5ee76807f30854146ca7ec399ba3a278a7d7b2dabfb22df35ffaafdVirustotal results 24.59% Heodo
2020-07-20D_367246030753824726450.docdoc e569138cd126927c018ddb4ac81d548fed36c44bbb98b507180ddbfe8c5e84b6Virustotal results 24.19% Heodo