URLhaus Database

You are currently viewing the URLhaus database entry for http://bethagroup.com.au/wp-admin/4126445-72SMD3Z1kG6-array/verified-kbxvgkvk-ub5m61njwm/2fwrw03dhg1-vtx0y7sztv50zw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:418598
URL: http://bethagroup.com.au/wp-admin/4126445-72SMD3Z1kG6-array/verified-kbxvgkvk-ub5m61njwm/2fwrw03dhg1-vtx0y7sztv50zw/
URL Status:Offline
Host: bethagroup.com.au
Date added:2020-07-23 19:34:06 UTC
Last online:2020-07-23 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-23 19:36:03 UTC to abuse{at}hostus[dot]us)
Takedown time:1 hour, 14 minutes Good (down since 2020-07-23 20:50:08 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23rep.rtfdoc a1f0ab7b2cfa90851ab4d5139530011fa45b20ea0afd3a0016108322064bf8f7n/a 
2020-07-23dat-2020_07_23-CQ5656.rtfdoc 7764a03225d3545d1a6268181d677c37e573e5b483c33e134940e0cc20842d83Virustotal results 41.94% 
2020-07-23list_20200723_G3524.docdoc ff12248384396a8a2e48e16a4f407d77a8c5aa86ec9553cb8703c95e4ff126e1Virustotal results 42.62% 
2020-07-23REP_2020_07_23_HWE973.docmdoc e3bb137dddfd1d26c99cb38a85455f361e12b41c869bc50c95485fd16c4a48f9n/a 
2020-07-23DAT_T92962.rtfdoc b59ca21fe76f630465d33889ebeaf9b77b2ff06169b221afe1708f78d8b8e9d7n/a 
2020-07-23DAT-20200723-Z964539.rtfdoc 1db7cbb2fec4bfbc297348c7bbde6517a777ff80c43d8ab97da85a99d4726a2bVirustotal results 42.62% Heodo