URLhaus Database

You are currently viewing the URLhaus database entry for http://mormedia.biz/colindepaula/wCYdEAG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427305
URL: http://mormedia.biz/colindepaula/wCYdEAG/
URL Status:Offline
Host: mormedia.biz
Date added:2020-08-07 17:21:13 UTC
Last online:2020-08-07 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002855335 created on 2020-08-07 17:22:05 UTC)
Takedown time:5 hours, 54 minutes Good (down since 2020-08-07 23:16:19 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07INVOICEC799700925.docdoc 346b0ed5db257c2bf541ae37f57e3971a19bc69310811cbe7fa037768f2136a1Virustotal results 38.33% Heodo
2020-08-07InvoiceZ9206511937.docdoc 522dfd2bd5983277254467284eb5cb1ae79a0957444adbd473462cfee3599c4dVirustotal results 37.70% Heodo
2020-08-07Inv-ZO0-82144671.docdoc dd693242b7c4ea00e3edc941a1b92d17d7effee6af390cd0abda5da40e5f4367n/a QuakBot
2020-08-07Invoice-319-2408040.docdoc 6d9ffb2447adb083ad20788cb467c96a7f91b27d9a5a9eb35a13e2471d909b32n/a QuakBot
2020-08-07invoice-PTZK03-768202.docdoc bb196956c5e57876daf8c64828c2b0cff8f83fc540f7ff492ecd7632f8a235dcVirustotal results 36.07% QuakBot
2020-08-07invoice-UUPB0-109753384.docdoc 66762226f0f7bab8acf658aaf69557223a227f9225671446d93e502b6d221fd0Virustotal results 30.65% QuakBot
2020-08-07INVOICE 7995 25335990.docdoc c255606c175748cae67207dd2ecfc3be6e215abe5fc235bf0f4e26771e0188f7Virustotal results 32.79% Heodo