URLhaus Database

You are currently viewing the URLhaus database entry for http://immediax.com/CGI/personal-module/verified-space/M2iwrAA-i88ugeu2f1z9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:423120
URL: http://immediax.com/CGI/personal-module/verified-space/M2iwrAA-i88ugeu2f1z9/
URL Status:Offline
Host: immediax.com
Date added:2020-07-31 23:14:04 UTC
Last online:2020-08-03 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-31 23:16:03 UTC to abuse{at}liquidweb[dot]com)
Takedown time:2 days, 16 hours, 7 minutes Poor (down since 2020-08-03 15:23:19 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01Doc 2020_08_01 92516.docdoc 92a8c9729a35ef4fbe97b8b931ac2ba3284ff4c1aaaab30eadbe36ad12c75465Virustotal results 47.46%Heodo
2020-08-01Mes 20200801 42684.docdoc 68d03e74f29b8ab84731be7d1d202d1234196be51e50924a161404b942aabdf4Virustotal results 48.33% Heodo
2020-08-01FILE-D932048.docdoc 170792807608455432c626fa966cb339667a2dd902f641b8073dd44bb86d64e4n/a Heodo
2020-08-01LIST-2020_08_01-HPQ501117.docdoc a680dee80d1c2e20335b72e1ab12908d3d79228c4be39a045dbcf6bff5c2f2can/a Heodo
2020-08-01Rep EF123.docdoc a75172196a20458cf0816b02008b28c9517d5b671b1a72235e200231cb02c694n/a Heodo
2020-08-01ARC-20200801.docdoc b022041c3866fa72e9822bbd3eb197dfe6d228453a0261f39be63a3d2b47f9cfVirustotal results 50.00% Heodo
2020-08-01REP-20200801-640.docdoc b516a3797050f6ac640f573248069d74c0a95c2f96e09f7c8f960d02edb53117Virustotal results 49.18% Heodo
2020-08-01mes-HZ13109.docdoc 73b934062bb8c8721173ac73c39f36f73eaf2b1236fd8ae3a0284cb972fbcbc5Virustotal results 47.54% Heodo
2020-08-01Dat_20200801_BZU630.docdoc dd7b7de461d1bb98f753cab9f3d748f28f34c6919770f2c279541724298390a8Virustotal results 49.18% Heodo
2020-08-01Inf_20200801_M644.docdoc 8d88b8b69a328ea24a481452ebbd0b239ebcb55d271c85b2bc1e99d4edb8b709Virustotal results 50.00% Heodo
2020-08-01Arc-20200801-7123.docdoc 8c17593a656e91dd4f497ede251ae65edcf1b44f79bafaf31cb1c270131d7245Virustotal results 48.39% Heodo
2020-08-01REP_5137761.docdoc 39ae9baef305618855896b8d6b700d61ab6421310721e1cd074efee397b46b2cVirustotal results 49.18% Heodo
2020-08-01Inf-20200801-ZMA45047.docdoc df2dc0151e9893df9a0b5fc037b8857125e0e013db773886f7714baaac50f250Virustotal results 50.82% Heodo
2020-07-31REP_44408.docdoc d237fa25ba4fb8cc8b5aa3c9a5edc6b8f2dc2c5ca92a707e20b1a6fa58e658fdVirustotal results 49.15% Heodo
2020-07-31list_MOA758425.docdoc 3d5959acbd3858cb4d5ceaf822493ee9d0b2250bb989193f8fbbc64db8570dcbVirustotal results 47.54% Heodo
2020-07-31dat 2020_08_01.docdoc 8698a975eeefa70a6e8eac20e57be07dbed23f59301a735a72892edcfdc62d26Virustotal results 49.18% Heodo