URLhaus Database

You are currently viewing the URLhaus database entry for http://imdavidlee.com/wp-content/gnwl7ww5xqwm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421359
URL: http://imdavidlee.com/wp-content/gnwl7ww5xqwm/
URL Status:Offline
Host: imdavidlee.com
Date added:2020-07-29 11:26:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):No
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31CCUW_30857756396.docdoc 98ee1381f134eaedefa2baef746295a547b2a4b7468ffbf5a9834e65a71c7c8en/a Heodo
2020-07-31KG4183233558FZ.docdoc fc3c1f705804f55dc1f8b04d0b13754b08fb42b0b18ad84507df6c8c00f9d946Virustotal results 42.37%Heodo
2020-07-3127031497.docdoc 9c184a50a28234ea058519a136d7e474a3e8fa0d75828d3b5167ff02cbf87b8fVirustotal results 40.68% Heodo
2020-07-31FILE_PO_07312020EX.docdoc d16b927f320789a0f78711597d65115dbc22b1b12ff7b3c0d1d0cb50dbb6374aVirustotal results 42.37% Heodo
2020-07-31WJJ_070120_PDZ_073120.docdoc e3ffa6100001a0b693fd8e169864c93f0a6fd4c1d3430e669cd053d7fd344c8bVirustotal results 40.98% Heodo
2020-07-31PO_07312020EX.docdoc 8afe98872ea0efe6299cbf4f831ad02539622489b559304862d2a460cfadaa48Virustotal results 41.67%Heodo
2020-07-31VPE_070120_ZOY_073120.docdoc 7689cf53f260808946f1b53dd444210423a975b7fc7754c1fe6b04960286f9a3Virustotal results 48.33%Heodo
2020-07-31FILE_PO_07312020EX.docdoc 582a1cef0fa903d6e306172892c6ec7fc72bed9ac3fa49364da864273c260db1n/a Heodo
2020-07-30WBXL_JWV_070120_SGR_073120.docdoc 29bb463a499d45a2b27d4f278b883361ed66aacd2f6184c93f79f9ba5df2fc53Virustotal results 50.00%Heodo
2020-07-3048570619.docdoc 2d012d692c59e956fc3552506e7371b94304a7a3521e61a693ad3309cd6d12f1Virustotal results 49.15% Heodo
2020-07-30REP_90703735994387910063702.docdoc 9c61c0b32def61a884c5bc2f2ffe498b042ec64e3b3cedfc7666e8e830872a1aVirustotal results 49.18% Heodo
2020-07-30INV_17592921.docdoc b3c476526978c5ce2f22627e47f21fdd3a16f03b166965bac3be05ca29b80575n/a Heodo
2020-07-30INV_0PVDLP0INBL.docdoc af343e685d3c5d32a0336f1e4fae3d77e6ef090ac8dd238150bc8b56cb8b5239Virustotal results 48.33% Heodo
2020-07-30BAL_PO_07302020EX.docdoc b7c80485c06d98376a33061daffa3a5da0b493251d67b50832d2dff57354ff87n/aHeodo
2020-07-30DOC_375789838447271004.docdoc 07e776c54df1af3395854812f0a6b7915acfa69f07c466e088eab9655d99d886Virustotal results 49.15% Heodo
2020-07-30INV_PO_07302020EX.docdoc c84cabbddd69bdc825d121fd233f8f07c123bf60bf294b6fd253506e21432501Virustotal results 45.90% Heodo
2020-07-30FILE_8JRUKZW.docdoc b4891111091f062e79d0ee997b7422c1681080f74a0d0b14dad258caf0e1c162Virustotal results 43.33% Heodo
2020-07-30DOC_CXP_070120_IZI_073020.docdoc 5dddb0f8334f1eee3b80fdbcb7f9f503331b2611e2a48edbf29f1bfc2f9ac586n/a Heodo
2020-07-301L3ZVJG4VO1MR2.docdoc 26ee82fd3c7a09364a517fc987720670881990bcf6b7215b6032a3895a884793Virustotal results 41.67%Heodo
2020-07-30IH8050306418EI.docdoc 4aba2e5191d8c4ecb8bd1d24c7032629caa3eb84c7d1399b103f99ac43c00f7bVirustotal results 42.62% Heodo
2020-07-30REP_AX7850179705FA.docdoc 6dd19eefd49748972e3b786c5f0bf83bc9686e1a74b67dc286cfbc09224ec503Virustotal results 40.98% Heodo
2020-07-30057511353346.docdoc 83df298646a7ee7eb341e606b340fd4daf3c0bc2e3d1f7003509e9cf2a155616n/a Heodo
2020-07-30FILE_XBP_070120_VGW_073020.docdoc 93d7bd64d847e2401e73045f5f3b1e714a1d0251a00934d7cf7b266d82931921Virustotal results 45.00% Heodo
2020-07-30REP_67709169.docdoc bc06aea71e46ed5e64ca7cf24f3b794f46b9371d1df13696a3dfe4096a3bb6acn/a Heodo
2020-07-303SKEXLL9Y4.docdoc 13e73da4adc126fa03c4f6e776fd1e257e0f3a50809ad6b9402d9498da8a5ad1Virustotal results 45.00% Heodo
2020-07-29H_9813730964.docdoc cb4750ddc6268762d29e9a7f31c375291ab9212cb5fb7f237b07610277735637Virustotal results 43.55%Heodo
2020-07-29RZR_070120_BSR_073020.docdoc 0bb41da3d7f6f972f06276bd500f8c8c520928871f48a3751835a23497658939Virustotal results 44.26% Heodo
2020-07-29BAL_EKF_070120_FEH_073020.docdoc 4c150acb0d92b9e8436a9f48659b5b8a5292e85a18107f3b9479ae8918619bfdVirustotal results 44.83% Heodo
2020-07-29REP_5904471964.docdoc ea1d07ae55467195b610358c91f9d4cb4f280d055e9a86158339ca3bdba8ca15Virustotal results 38.71%Heodo
2020-07-2987J0V22T0VBKS82.docdoc 9699d65df4c2fe82af8b8dbfe2a0b1165432346f1be0417429b127a7d7346558Virustotal results 36.07% Heodo
2020-07-29PO_07292020EX.docdoc a1337b78d948a4c579b396e2c35ae69111e6af596065944b6730552491a80d21Virustotal results 35.48% Heodo
2020-07-29LY2117649124RJ.docdoc 16f48852b646cab90797038aae4ecb796a246b881639100a6535548ab71c5923n/a Heodo
2020-07-29XH_WO8626351984WO.docdoc 654835f742e937f66d6567d0bcca1a30e828fa5f56db1f432cc54901d7222dc1n/a Heodo
2020-07-29DOC_1PZ8IKH7DZ6.docdoc 05612fc5c4f0acd9a581eca6977bc24478a500aa78b12f94579a7d056a9282abVirustotal results 36.67% Heodo
2020-07-29PO_07292020EX.docdoc 018beffb57923eb38dac054bea5fce0c4e9aca87f1971e226c7a7bacad5606b7Virustotal results 36.67% Heodo
2020-07-29INV_HYJ_070120_NHM_072920.docdoc 50b748b79bdb99370387508486bfd607f302fac6a15eb7e899c6d07c520fa245Virustotal results 34.43%Heodo
2020-07-29RJB_XUHC704D86OQJK.docdoc 9e9bcedb989bda32fb610816c436af0667eb5c22bb6a3d20fb4bd426dbee88adn/a Heodo
2020-07-29INV_PO_07292020EX.docdoc c2ac2bba78f3f27d36a97f527237ad4454b85b03bd0d8a1bd3c47c161c99aa5fn/a Heodo
2020-07-29BAL_59687238.docdoc 6fcef674d71a2312e60cde434fdbd6632c320cfe7326d26463e3caae788de434Virustotal results 27.87% Heodo
2020-07-29DG4055160768GX.docdoc 5a959afcb67ab697d8f53e2e91f7424fb274bee1600360681f6b61c26e377fd7Virustotal results 28.33% Heodo
2020-07-29RUHW_FD5412850386OQ.docdoc 86a19d14ed46ea211980091b62fc7f000d5c8881d4d34dca2d35f8fb35e00a4cVirustotal results 28.33% Heodo
2020-07-29INV_RJD9BJPW7XTXZ.docdoc 85f5f165c013ebedbdf66b63720dfb1604b37f17bffa05a46cb46d229f19bf72Virustotal results 26.67% Heodo