URLhaus Database

You are currently viewing the URLhaus database entry for http://iconhealth.in/wp-content/payment/1iyxp5y3r2v/9pr27060433012321d5s4sqbymb8h/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:416900
URL: http://iconhealth.in/wp-content/payment/1iyxp5y3r2v/9pr27060433012321d5s4sqbymb8h/
URL Status:Offline
Host: iconhealth.in
Date added:2020-07-21 21:43:44 UTC
Last online:2020-07-30 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-21 22:46:02 UTC to abuse{at}godaddy[dot]com)
Takedown time:8 days, 19 hours, 3 minutes Bad (down since 2020-07-30 17:49:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-2828568318218809919293.docdoc 5f2520828449385a186054f9fd1888a69f6d808ee764bb50c387821529d0fdc0Virustotal results 60.00%Heodo
2020-07-22PGX_070120_OZP_072320.docdoc d50d98dcc8b7043cb5c38c3de36a2ad62b293704e3cf23b0cd7450174df53feeVirustotal results 40.68% Heodo
2020-07-22K_1120195708930565826658.docdoc d6dda19b45b3e10925dfcab7b4c0060f7cc816d29ccfa5b68e8f45bd7c69192bVirustotal results 37.10% Heodo
2020-07-22REP_37022313741842928.docdoc 1cc88188b7c5862b588b0e9eb1b26ba3f672648e3a7ce82453e02ee1a59e1dfeVirustotal results 37.70% Heodo
2020-07-229734198596.docdoc fe236d1160de3bfa6f16325da55c3b58e62bb19f27f67a942f2b9ca9580e9043Virustotal results 36.07% Heodo
2020-07-21REP_PO_07222020EX.docdoc bc7398dd8ac94a9ff8ca7a93f0755681ec84ca7fd05058ddc053cd16e1b3f4e3Virustotal results 26.23% Heodo