URLhaus Database

You are currently viewing the URLhaus database entry for http://www.wedif.com/wp-includes/641103991036/6zq71964877680747aj2viz2qlcgikqz2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421343
URL: http://www.wedif.com/wp-includes/641103991036/6zq71964877680747aj2viz2qlcgikqz2/
URL Status:Offline
Host: www.wedif.com
Date added:2020-07-29 10:42:31 UTC
Last online:2020-07-31 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 10:44:04 UTC to irt{at}nic[dot]or[dot]kr)
Takedown time:1 day, 13 hours, 30 minutes Poor (down since 2020-07-31 00:14:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30INV_PO_07312020EX.docdoc 29bb463a499d45a2b27d4f278b883361ed66aacd2f6184c93f79f9ba5df2fc53Virustotal results 50.00%Heodo
2020-07-30REP_PO_07312020EX.docdoc c36f82ea105cba4a44f73acab1118437af3aab1d9a0f306fad8180ed6fb20205n/a Heodo
2020-07-30M9WRRHB10T3B.docdoc 7c27fc12153685ebfa853201b4b71b6183b994f0bee705daf6d52db0f1062747Virustotal results 50.00% Heodo
2020-07-30DOC_HMI_070120_DHN_073120.docdoc 2479f0c202e0b1e1af6e349625250c5e8433d8c2971ba1cb5325402e1ca70e54Virustotal results 48.33% Heodo
2020-07-30HM0315272048SX.docdoc c9d8e0575231ffd0d53eb2e66416caa812343e14a5197e01bfa0391c0fbfe458Virustotal results 50.00% Heodo
2020-07-30DOC_NMBR0FSYWO04S9.docdoc e2bd4b9161beac093fc18bd29e08e53a735f5853f1d683b11848c73f919ef3b9n/a Heodo
2020-07-30UQ9575009135YY.docdoc 50237ce7bab432ebc9fdb9c0b9b8764d40d62f59367f6c32fd67cdbd428a7ca9n/aHeodo
2020-07-30X_T4BTK9A3KNIL.docdoc b428976d96415b32efb7157b375160dd676b448e1566fad5dd8da634fac3cc64n/a Heodo
2020-07-30FILE_PO_07302020EX.docdoc f8e63fad886d5ab2d244f39608a7cd53f7bd5a5ab283d1e5aa64774633cb79c1Virustotal results 48.33% Heodo
2020-07-30INV_JPY39EQCU.docdoc f3ceae5781ace1e523935bb48baaf6484791c5cde8e95f8ce6db69f31b2917a4n/a Heodo
2020-07-30DOC_19835818.docdoc b3c476526978c5ce2f22627e47f21fdd3a16f03b166965bac3be05ca29b80575n/a Heodo
2020-07-30I_W7A6EKK3ZM.docdoc e36e626e95cc4e2feb34bfba30b423f08786bde39a1ddda5fa65ce1abc18bdb7n/a Heodo
2020-07-30ZERLMQ65HERKXPJ4.docdoc 6bb1593ac7b893c0564d6a29fcbc566db5a0cf5e8a4c0c19dab1866d91a041a9Virustotal results 48.33% Heodo
2020-07-30DOC_PO_07302020EX.docdoc 9a039540a5c66db061b1a3fb4f0e45324d5f2b48cedc6c1bf88e4b8f1b887302Virustotal results 45.76% Heodo
2020-07-30BAL_87322065.docdoc 3ec0cda0966fdfac5059b61d8b718eb7dc9e4454c370aa8260f34a3c759d43c2Virustotal results 48.33%Heodo
2020-07-30DOC_B2QE3MRHFRH76BWR.docdoc b7c80485c06d98376a33061daffa3a5da0b493251d67b50832d2dff57354ff87n/aHeodo
2020-07-30REP_YX3547825534HA.docdoc 07e776c54df1af3395854812f0a6b7915acfa69f07c466e088eab9655d99d886Virustotal results 49.15% Heodo
2020-07-30REP_4ISG7CURTEWV9.docdoc bae631a4bcfb6f64cb01a26d307ddcfa85d0d63f8765a7020242e2e5b7ba979eVirustotal results 45.00% Heodo
2020-07-30INV_40980394.docdoc fc71240699d99fe12f5253034d018233aca29f28291d562f41f75444f6ece914Virustotal results 45.00% Heodo
2020-07-3091565987.docdoc fbde268bb3b1960b075be4472b42270bebc9726fd35c46d5ccdc91c2eaffe665Virustotal results 46.67%Heodo
2020-07-30REP_09536753.docdoc 1d8d8efde60da9a7ef7e927d2ea168b44ae1c9e70b543f692cd98d6dba98f99dVirustotal results 45.00% Heodo
2020-07-30EQYA_ZR24AXCLL.docdoc 644ecceefd25470a4909b40c0d4c590ef6f5df9613ed3ed3703d2795a21930f3Virustotal results 45.76% Heodo
2020-07-30REP_123925849.docdoc c8af9424ff1c3e407411aadbf072dd116adc72bbc718c6742a8dc4a116c6d934Virustotal results 43.33% Heodo
2020-07-30NEM_PO_07302020EX.docdoc 18190f715f0c05ac6e28e0fa78c58fe7a1f6a0733be72ea6494e4340611c2194Virustotal results 40.00%Heodo
2020-07-30OUF70LNWQKG.docdoc 7f808ac67ce1cd2c1e08a46de2537e6471f4ae05aaf7f61d3d21091745adad9aVirustotal results 42.62% Heodo
2020-07-3074806686055369206604920.docdoc bdd27214237a8d3cb0df1c5a91967fb3d767427fe0eea2f8cfcb62357eb7490aVirustotal results 40.98%Heodo
2020-07-3097956943.docdoc ccffd1057a0198494234050b71333c4cb0411d6c9fb3fdb730043076797c6fbcVirustotal results 40.98% Heodo
2020-07-30PO_07302020EX.docdoc 9753345689b4a9807df97ef55a6f73ae295aa23114df7727952483430b6ad127n/a Heodo
2020-07-3023414178.docdoc 07e19f3c256981e488d086f48552ee93a5b7d9148744edc670f477090ecfd5fcn/aHeodo
2020-07-30KM3EJSMZ.docdoc f69221bcda2041011a5346b30da22aac2af5ed52c961455f6529339faa519dbcVirustotal results 40.98% Heodo
2020-07-30FILE_0KPCK58JU1BPFS6B.docdoc 4aba2e5191d8c4ecb8bd1d24c7032629caa3eb84c7d1399b103f99ac43c00f7bn/a Heodo
2020-07-30FILE_268408097.docdoc 2fa814dd0c5fd6baf41a1dff861eee948734721c6155c4812ca40945d7432a07Virustotal results 42.62%Heodo
2020-07-30DOC_EYM_070120_FKQ_073020.docdoc fd2c870bab01edcb6af885cc070a9ededf595bb1b3613b83fb9313a3caf5e014Virustotal results 40.98% Heodo
2020-07-30DOC_DID_070120_GRI_073020.docdoc e65bf031ca1679654f9dc89f8d43700e1f7275c339d42af6a4949ac6c09e164an/a Heodo
2020-07-30FILE_PO_07302020EX.docdoc 9b9201d1a6812f56bfae2ab23b43743860110bf3e299305d69c02d83577be9dbVirustotal results 46.67% Heodo
2020-07-30BAL_1QZKELNLYN674.docdoc 4e037190e0798dbb95a301951d9cefeb18b9f7c0d901052a67f3180236b72bb5n/a Heodo
2020-07-30PO_07302020EX.docdoc d834f17cd0c738eb95638a398e34040960ee1780aa6daa9c730d7d0188421681n/a Heodo
2020-07-30I_UEG_070120_ZVX_073020.docdoc 4cdedce9eaa2192b68d57d5362319c339f9efb5bb60d063a11500053b0a6dc2eVirustotal results 45.90% Heodo
2020-07-30INV_UCI_070120_GXQ_073020.docdoc a3e3e8da6025ad93ee1a84c515fe80351cc08ea4a60620f29b4cd6cc65b5387fn/a Heodo
2020-07-3058765917.docdoc 0f2ecdddfab774804433ce0b9a13b08e5d8ac3af412c34b2aa0c071ac230cab6Virustotal results 46.67% Heodo
2020-07-30XHT_070120_VDS_073020.docdoc e6658dff38b4a88f8d04cdb4f0e14bd6247e293b3249d10e195679438b9c4070Virustotal results 45.90% Heodo
2020-07-30PO_07302020EX.docdoc 47e3d76a19b9abda5ec59103b5cca5343e385cc0275a9fd5ac33d72783df7414n/a Heodo
2020-07-3016168595.docdoc 9aac93599eba869798e80c3d41e24b6f2baf93e55f4069eb74aaaac4f8b71a6fn/a Heodo
2020-07-30INV_LPZ1B0OBP.docdoc 2dfa11471ca3770cd8081933b8a4923f9596207beb3ecfb545a53a560d0221d3Virustotal results 45.90% Heodo
2020-07-30PRCE_PO_07302020EX.docdoc 1b92a9e2189e1b1570803509487d4403924054cea97919e4055becadf52a9b5an/a Heodo
2020-07-30REP_686547750.docdoc 8ef7719b6b5ea2d908bae174825539df09cc69ba74d699bac5a761711183a608n/a Heodo
2020-07-30PO_07302020EX.docdoc 4294b85b71c2cb58c3fc676a5c6fc1a5302b96fa35300a4982ff55394923eb4dn/a Heodo
2020-07-30INV_DG0536836239BD.docdoc 3d4c586c90603af996e127bcb99453ddf407b359560a3d2f08ec16e451f498e2Virustotal results 45.16% Heodo
2020-07-30FILE_SBQRETEFHNFUO.docdoc 84390b0c62fe199c631eafe739946719ae42dbac314d5e64d66023449ef31d56Virustotal results 45.90% Heodo
2020-07-30OR_CJ7474755520OW.docdoc 7bd515184dd9fd061f1626220ff1cca98d3a58d71361419d9bdcf53fcba329bcn/a Heodo
2020-07-30BAL_IRU_070120_QYX_073020.docdoc 28eb3047fa38f2e2070584d2220a5850c31525317b2fb592dbeaeb6144fa307aVirustotal results 45.90% Heodo
2020-07-30FILE_MPK056XFO62.docdoc 5cce66eb35c678e6e308f4710a3504c100f81bf8744939f8ba6021f4ecf69c71Virustotal results 46.67% Heodo
2020-07-30BAL_PO_07302020EX.docdoc ffcf999bd4956069ace23c70a4cdf979f7dc75fc959dd578b96db3207fdd1ff6Virustotal results 44.26% Heodo
2020-07-30BAL_PO_07302020EX.docdoc aedcc1a32e55afbbd9b9b4def9f545e76adb5f9b0df0313da66a6e648d43f460Virustotal results 44.26% Heodo
2020-07-30PO_07302020EX.docdoc 4300cf17a027ac75b787c42acdb0e19e2b952e682b9c28a831de36087a43a603Virustotal results 44.26% Heodo
2020-07-30Q_0YNMC522D3ODCM.docdoc 7b12e1367d2a858964b39836839735c8b68e56fb91c1995440f30972860c8c66Virustotal results 44.26% Heodo
2020-07-30BAL_06313473.docdoc 704af909402caeff30d6ed6d6f47b5f0acb7e12008448c8a043f5a7d2aa08932Virustotal results 43.55% Heodo
2020-07-30INV_70686003.docdoc babf9bbe00be892ecb7b1d8774cc33a3bae77c5b3d414f640c3f136365acea11n/a Heodo
2020-07-30BAL_XVY4FKSG2E.docdoc 7b459b39196f8a02d1d76081fd57227679c791e3cefa667a2264e36cb79230aaVirustotal results 45.00% Heodo
2020-07-30C_PO_07302020EX.docdoc d3925d4dce34de594b7873b36880de7be2b8cf95a583665c91ab3c660f18d292n/a Heodo
2020-07-29PO_07302020EX.docdoc df0fd9aeb27800d1d055526f68c68130262c8c15596eaa5077cf3a067e810d76n/a Heodo
2020-07-29FAT_070120_KJV_073020.docdoc ef354afa479fb3c2a19622cee6c8b67e9b54ff16871ace2f97bf8cf992883da6Virustotal results 44.26% Heodo
2020-07-29BAL_40535687.docdoc 0bb41da3d7f6f972f06276bd500f8c8c520928871f48a3751835a23497658939Virustotal results 44.26% Heodo
2020-07-29P_WCB_070120_WOR_073020.docdoc 247650d657b93cdc868b938cf09c549175ede9f04050b49bf731bf4187040030Virustotal results 44.26% Heodo
2020-07-29INV_437672079792394695521110.docdoc a4c0992c92db3e0c5c314930e66582a8544194b5ba6bd3870de21b986ee1ccc3Virustotal results 39.34% Heodo
2020-07-29PO_07302020EX.docdoc c8587832af2d0ae412cb347a9a17c03c7e9c13139b338cf3091ea4fbc376d320n/a Heodo
2020-07-29DOC_97348001.docdoc 85586aed0ec99352b1a7641827523f66047222df673d56eaef2318e8cfe5d325Virustotal results 36.07%Heodo
2020-07-29BAL_255336729301332.docdoc a1337b78d948a4c579b396e2c35ae69111e6af596065944b6730552491a80d21Virustotal results 35.48% Heodo
2020-07-2943823897.docdoc 2182766a9cefb688b5c1a002a1e951cfb08c4619f814c1c5f5a56dfdc60710a3Virustotal results 36.07% Heodo
2020-07-29Z_40339823.docdoc 509e5ceff7eb6060dcdfecb46ff0cc25302b21a0086e73f472d6a87e5a30b26dVirustotal results 34.43%Heodo
2020-07-29SRV_XZY_070120_RUV_072920.docdoc 05612fc5c4f0acd9a581eca6977bc24478a500aa78b12f94579a7d056a9282abVirustotal results 36.67% Heodo
2020-07-2901324138.docdoc 018beffb57923eb38dac054bea5fce0c4e9aca87f1971e226c7a7bacad5606b7Virustotal results 36.67% Heodo
2020-07-29BAL_PO_07292020EX.docdoc 61be402d01ef60907ecb10271e98676d6e061ed6ddc0e7d6909589ffd22eef0fVirustotal results 35.00% Heodo
2020-07-29BAL_00921889520.docdoc f1175d64cfa9bd48060ca1c9a55ffbc0ea4e9c9f11f776735540a5df0cbf998en/a Heodo
2020-07-29INV_PO_07292020EX.docdoc 7cc0e0d42675739a03ee7a45f6f70ba77f5586f1757dca8f793b25daf607f7e5Virustotal results 36.07% Heodo
2020-07-29KG8226390977DP.docdoc 9ca463088f63078936689452eb9fbbf48f0c4e7efaa553174c1990d90f5e8530n/a Heodo
2020-07-29L_64425169.docdoc b3ba7eba2631c4a7d69a068f7273be62e8435ef7b8564aeb7270fed27f11981aVirustotal results 33.87% Heodo
2020-07-299WWVVFDU.docdoc c53e4356e0a876f07a7b63c9c93e8e198f72a37a5dd754cf3f8060369b2ea9f9Virustotal results 33.87% Heodo
2020-07-29REP_LK2575332597XY.docdoc 727f2b57969b68dc6e79c694c096bf3420cc788db33ec0f47193d70ce11fb20fVirustotal results 34.43% Heodo
2020-07-29BAL_PO_07292020EX.docdoc 2726f3839cf1006321efbabff9c5f63a660e6a9f854a27a0d4ac5d505aae31fcn/aHeodo
2020-07-29INV_41254373.docdoc 3d0f47c47fbc6cfee2fb276f433b21cca723df51f5c2a24b876cef35c936e81eVirustotal results 34.43% Heodo
2020-07-29FILE_5418964497142179935073742.docdoc 6fbae9bccf7687065cab8a4f08d6b3698f4d8224cf72ca4eb10032c0178766adn/a Heodo
2020-07-29SIH_070120_VLP_072920.docdoc 2b446f962d60ae78cb353c325d1371e6526cb8315092524b2709b9c2eeae6753n/a Heodo
2020-07-29DOC_KTC9ZPG.docdoc 4a406747cc4af71f72229df7ddbd5c6858984101d67e93ab864273cdff151823n/a Heodo
2020-07-29DOC_70908421.docdoc c2ac2bba78f3f27d36a97f527237ad4454b85b03bd0d8a1bd3c47c161c99aa5fn/a Heodo
2020-07-2930387334786897697383.docdoc 551a8dde631d3e53e4ccbec22c88ff151b1ae950686fe687b93d2886a94d841en/a Heodo
2020-07-29BAL_OO7195561817JZ.docdoc 9c24d6fd85470958aea67d26f6293c5d8cb091ccac7299fcc6c243ff90382cben/a Heodo
2020-07-29DOC_OTIX7U46Q9.docdoc 4046d4baed8c5cbed9936f09919edd39c697922a01e56617feeba4e5957164d9n/a Heodo
2020-07-29LUOX_PO_07292020EX.docdoc 3681daa87fcd7273080d8c9943be0e8f549075f23e2ceef7e89875649ad5a0efVirustotal results 27.87%Heodo
2020-07-29DOC_PO_07292020EX.docdoc ea0c4bf37a77d48ec55e6fd331d26c6efd0c643194ff2c6919b8f975f0562e7dn/a Heodo
2020-07-29BAL_IG8723825626GM.docdoc e5f86234f39d86f44946089d600b3d4244a9e7f9700d6d0e167c8b8821b22e05n/a Heodo
2020-07-29REP_YHX_070120_YNQ_072920.docdoc 6fcef674d71a2312e60cde434fdbd6632c320cfe7326d26463e3caae788de434n/a Heodo
2020-07-2926262369.docdoc c614c297be69c8380b5bdac5f95ce873d587242578aa7f330f71e10bc2af0e81Virustotal results 27.87% Heodo
2020-07-29FILE_853899305517739853.docdoc f2079fe72b86eddb5c15d9b80c2cc59076a08c0fbbacc4663d5573f5fe40e88dVirustotal results 28.81% Heodo
2020-07-29BAL_21838377.docdoc 4d4716ffbc0025ce6b471022511dc08d0b712ecf347b502ba4c6f734b72242a3n/a Heodo
2020-07-29E_PKI_070120_SHE_072920.docdoc 1257945161cce1eb5a26d2ae6cd6d914e96eb7e505d3f37a281f2d091e2a7a32Virustotal results 28.33% Heodo
2020-07-29DOC_PO_07292020EX.docdoc dbd8762c7d8b9348a509e890f68a6c74aa1f60d81f6acad63ad3b56dd3337e8aVirustotal results 27.87% Heodo