URLhaus Database

You are currently viewing the URLhaus database entry for http://dyrmann.dk/wp/protected-zone/SeD7lx4gg-2PfDGH6zzOIYwg-profile/jUipQ-1fH07H13q6Iz0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417970
URL: http://dyrmann.dk/wp/protected-zone/SeD7lx4gg-2PfDGH6zzOIYwg-profile/jUipQ-1fH07H13q6Iz0/
URL Status:Offline
Host: dyrmann.dk
Date added:2020-07-22 18:59:33 UTC
Last online:2020-08-26 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-22 19:00:03 UTC to abuse{at}zitcom[dot]dk)
Takedown time:1 month, 4 days, 13 hours, 14 minutes Bad (down since 2020-08-26 08:14:44 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23list_32580.rtfdoc aec05999d3751d7cfd9ade2316388ee6da303748401fb7eada3edaf2b37a18a3Virustotal results 43.33%Heodo
2020-07-23Dat 20200723 9509.docdoc 907cdbd0036f8c72ef0830f26aee15b16f5498fe3fb88c9ac852fecebcfd2771Virustotal results 44.26% Heodo
2020-07-23File.docmdoc b27dff26a97f18384d8db6b7e5a3c5006d66ed61bba5313f802ebf96543c1c5eVirustotal results 44.26% Heodo
2020-07-23Mes-S24934.rtfdoc 5a2ebbb1273d774d883ccc80441f1c0a31352cca7114330d6272919625c803efVirustotal results 44.26% Heodo
2020-07-23DAT 28032.docdoc 1a49241764ba049de98c9d050dd57d0c9089402768b9a1206e09dedde0282d0bVirustotal results 44.26% Heodo
2020-07-23DAT 2020_07_23 343.docmdoc e73f1ef263f3c13e83599b2740bddf21cac0115e8a8da4a0c728e024efc669bfVirustotal results 44.26% Heodo
2020-07-23List_XJ584122.docmdoc 0f79dd6c7bd7490955e93399a3e660272c22f6f7f5e97a24ff33d1d1af714941Virustotal results 45.00% Heodo
2020-07-23Doc-2020_07_23-VD62244.docdoc 34184c5992ed62afbaee71a96232106fc41857b255341becc56b01722b343c3fn/a Heodo
2020-07-23list_20200723.docdoc 654e6bd6920ccd6177242d7e58e504e354a9e5fc0be08816ce3afaa64b0dee93Virustotal results 44.26% Heodo
2020-07-23MES_20200723_215571.rtfdoc 885dc147be1221ecee44115a61f7df1e11df4c2bfd930c5dc7e3c8ae1910d1d9n/a Heodo
2020-07-23LIST-2020_07_23-G57776.docmdoc c16f62ec18e9ca91236dfbab6da3e98fc15a8574e3c66dcb4c652ba820bac07fVirustotal results 45.00% Heodo
2020-07-23DAT 2020_07_23 8625.docdoc 57c916ce284fef78cf597e34daaba2cf0aeed7a30602b72dc93b8ec0a1aa8cc9Virustotal results 44.26% Heodo
2020-07-23ARC 20200723 AKF9428.rtfdoc 1b96d3881a05f141dca8c4cc847ff24cf5e03d3e37e67333351cf7cf4bb9e32aVirustotal results 44.26% Heodo
2020-07-23Dat_20200723_3240682.rtfdoc 4e765584956c4f9fe770cd92e1d32522023508d48ba53b6ce7ace6c04d4e8d83Virustotal results 43.33%Heodo
2020-07-23Dat 2020_07_23 9183.docmdoc cec6250fbf5fb227dd2bdf92b7031f41fa3d65fe1f1d5a441229c14913884ea0Virustotal results 43.33%Heodo
2020-07-23doc-20200723-G1475.docmdoc 3871eed6206b0a99254d0c9687c02a628857c89231e009285a476dacff80d98dVirustotal results 43.33% 
2020-07-23list 1945627.docdoc 769b01f8c9dd10732e0a5d287a38b2946260496bcb17be7319e7070e4f3a62b0n/aHeodo
2020-07-23File_2020_07_23_ZFY169803.docdoc 3f733796d3615608e933be5a6880061ec7fc506529e9ca3ad7c555fe460fb388Virustotal results 42.62% 
2020-07-22inf 365.docdoc ef64e139ac5120bcb2be7ca49559d2e39d9a00d5007ba03f7745618a805d08cbVirustotal results 40.00%