URLhaus Database

You are currently viewing the URLhaus database entry for http://superkusch.fun/wp-includes/BmdQXkMg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428490
URL: http://superkusch.fun/wp-includes/BmdQXkMg/
URL Status:Offline
Host: superkusch.fun
Date added:2020-08-10 16:42:02 UTC
Last online:2020-08-15 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-10 16:44:03 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:5 days, 4 hours, 2 minutes Bad (down since 2020-08-15 20:46:15 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12INVOICE-ME77-793992162.docdoc 8d34f5b572ac9a28d49a7939341b0c401c39000c57f782b4aa3c38982d6d32f7Virustotal results 28.33%Heodo
2020-08-12invoice BT5887 890766438.docdoc 5ae4f0020d095228ab72c9e222d2b4b98c8cf44fb068ecdf2f43ce0f12b9104aVirustotal results 28.33%Heodo
2020-08-12INVOICEBJZD118704677067.docdoc 28af5978f878de657395657384a4ed7a7c0d19fc418f06628d0213309c3c17ddVirustotal results 28.07%Heodo
2020-08-12invoice_4_853801.docdoc a0cc5c1b5719f2747bf50cf50c3c6416863a25fd52bfd960cb679beef7e6b2fcVirustotal results 28.33%Heodo
2020-08-12invoice-PLM590-7841012.docdoc 280a50d04d643f96dc80e164116696ae77cf1e300a8b123d73f49078f304b9d4Virustotal results 29.31%Heodo
2020-08-12invoice_3849_4256722.docdoc 32750365d68890d9071db244c4b3534a22dc90130e47ca9dfb21d81277678528Virustotal results 28.33%Heodo
2020-08-12INVOICERJQG570154466.docdoc 6c818eb9af4ba3479156ffdddedf9e68f03dcc98579d8a7df9cdac88c483335dVirustotal results 25.00%Heodo
2020-08-12INVOICELCIG085851190.docdoc cf65449b4b23f2991372657bdc810fda45d90cb45b5866061bfa0172f01b692aVirustotal results 54.24%Heodo
2020-08-12Inv-BFH78-148841749.docdoc 2f20ed3e86d25bee2fc86cfef8577a1392ff6573b368c48c7611b7215f15323eVirustotal results 53.33%Heodo
2020-08-12invoice GDD9 2544506.docdoc c594321ad25c0a0e2cbd28d850bd14056f97b05472ef3fc60aeaf17e43cc95c0Virustotal results 51.67%Heodo
2020-08-12Inv-NVO016-177555.docdoc a2b1d13fc111d276dc837aa2c6e155e9aa2944ec66d9133932b1f183cbecad32Virustotal results 52.46%Heodo
2020-08-12INVOICEPSZA9646823.docdoc de3e75a70100e3ecf0015c869943c8c67ec15e70f7105d34fd9452677b60e0ffVirustotal results 51.67%Heodo
2020-08-12invoice1121760.docdoc f187d66fdb939f8dba5144cee441601671652077d4b7f795a6d0a5ce18e0fc50Virustotal results 51.67%Heodo
2020-08-12invoiceDJM6767064081.docdoc 8008c78224947ab2255baafb8665c8c62668d7551e3d33d2df81126400cba80an/aHeodo
2020-08-12Invoice PF73 267642370.docdoc c57f8830d597b05f0dbf9031092be52ed1ce11f9f75f530bfd698f46f624901aVirustotal results 52.54%Heodo
2020-08-12invoiceV7438758100425.docdoc 252a44229413353042efc9846e4521a6c230832832d0d7efd0bb8b2677026afbVirustotal results 53.45%Heodo
2020-08-12Inv-802-21692293.docdoc 6e9b1ad824b0bc35792a2ec92fabb0456af70c654e99e5f6d0067903f3c771ceVirustotal results 52.54%Heodo
2020-08-12INVOICE_ZL063_027243614.docdoc c9a3637927d6c089d282b7e5f89be7e0269eb7fd1e823cefe8844e25153f2cd2Virustotal results 51.72%Heodo
2020-08-11invoice546605273.docdoc ac1bd9010c2ce0ab643beaa92a00c1d342b013f58e2099bc3c85e584b8a92107Virustotal results 50.00%Heodo
2020-08-11invoice_6114_75943636.docdoc cbf6ee8e987a618ed4bbc8efb689fab62d912808ce3d959106e7697637d3a217Virustotal results 50.82%Heodo
2020-08-11INVOICE-UPDO32-4964355.docdoc 4e7dada550866484045928cef6fdd4d7ccb5d19d79febe490ed7da33d3491b01Virustotal results 50.85%Heodo
2020-08-11invoiceC907619020205.docdoc ba9a8497f8d62ce6e51e23f89f045998e57f187f7b8b9ff3168e5289d1758e80Virustotal results 50.00%Heodo
2020-08-11invoice OR1 251009.docdoc baa7ec55d76e7be67f654211832accb7b7352442fefbadd3a4047e63adcc24c1Virustotal results 50.82%Heodo
2020-08-11Inv-MTAK4-305497.docdoc c45b228e93af0e566d2bd17f6a59f923a95517fb7eab92217995375cba5ed65cVirustotal results 49.15%Heodo
2020-08-11Inv-K19-9846030.docdoc a333fa244b433049bb35cd2d2b8a2ee2c904a26033a1f55f967159b4db8e49baVirustotal results 47.54%Heodo
2020-08-11Inv-KVH51-27327549.docdoc 50ec0f5012c83993533de48a638157f8879561483c54242f0c74cc2c57ce3917Virustotal results 46.67%Heodo
2020-08-11InvoiceFO67232100592.docdoc afae9a58f094ad2820f5d92fbf12b243f4f7db992916f2e6893329b9db28ccc2Virustotal results 45.76%Heodo
2020-08-11Inv6371596501.docdoc 293f306523c6435dd07806dffacf1aaf3b4afa145384326acc152e1862286c94Virustotal results 38.33%Heodo
2020-08-11INVOICE-LYWH51-76016195.docdoc ede2cc2f4a614a18e35882b7e97c84dd7af65a7473b27ff28fab5de1fa31b080Virustotal results 38.33%Heodo
2020-08-11Invoice_HHE0_2633135.docdoc dac8e0e3216153525553b0acfd49fa1e9378c161e33bdf00399148901b499dd7Virustotal results 37.70%Heodo
2020-08-11INVOICE 030 977026.docdoc 9a4c9e66ce9ef47c504d569042c60e503eae3ce56861bd849f9f4af50c41cb17Virustotal results 36.67%Heodo
2020-08-11Inv 7713 747950718.docdoc 81a81cd7bd810ce513cc65228f2046fdaa21f79402d31a76221873894c844982n/aHeodo
2020-08-11INVOICEBD87688235.docdoc 1eb595533c1188468da26f2d8efdec446f0b7d1e1eb1faafaf7969193d8d82d7Virustotal results 37.29%Heodo
2020-08-11Invoice ZG3122 28233373.docdoc 14852f4514aeb650a12d6f5b8b1f48f5d0a3de8b270e5f8e52326ffd0d55134eVirustotal results 35.59%Heodo
2020-08-11INVOICE YSL529 125487789.docdoc a99784861e65c2f8547c5cfa6e13dab394daeb62e238aa9f4cfbe80619e744d1n/aHeodo
2020-08-11INVOICE CP165 748406.docdoc 4ed6407bac7a7d0e0122dd585bd1479764cebff3701d3e6bce6f59fd8698378cVirustotal results 31.15%Heodo
2020-08-11INVOICE GL0872 9285605.docdoc 519dfcfc8df38f6cbe0e60280784fe52817df6a4d22343ae006687f6f5595296Virustotal results 29.51%Heodo
2020-08-11Inv557744656.docdoc 891ecc5448ab8c4386d4b35c929d92dfdb0a929f452fc34cbe848dd4839bf3den/aHeodo
2020-08-11InvoiceFGFA76633737.docdoc 02e7adbd6348d10f9ea3a353c5a32b022e35bec8c9c0aff0605675d44aaabcb1n/aHeodo
2020-08-11Inv-1023-503164.docdoc 521ce598b022564001f8325d028beb08bd8ee8ce7fb2ca81422ae6e70ee7bd8eVirustotal results 27.59%Heodo
2020-08-11INVOICE-DCH7-484236.docdoc 7a95c345a8439026794c587553c122019925fe3072d0902ae4411458c2d68ad8Virustotal results 26.32%Heodo
2020-08-11invoice-XC9-293661.docdoc 744f82770d4c090be9a6bd6e9d2ab09a760ae5cdc58ba11385871d2660555586Virustotal results 27.12%Heodo
2020-08-11INVOICE_P728_879989138.docdoc b16e37a0663d4850eea084147f345f8ed5f0771b13cb970e6073598106508476Virustotal results 26.23%Heodo
2020-08-11Inv-LP7944-837198.docdoc b97f21c9d86c3f8c4a66a3e12e9a89c5d9f0bb23fc7b90a95618bc0faef06250Virustotal results 26.67%Heodo
2020-08-11invoice-FCJ3490-8225018.docdoc 25e187d3fbbb75a088371fa39be0269a26df239b04c3cdd4e6e37dc76eedfcb7Virustotal results 23.73%Heodo
2020-08-11Inv-JK588-96750239.docdoc 6bc1e3ac932ab1cbc6359f9bf1af246523f8fa7050160994440732dd1a41281dVirustotal results 25.42%Heodo
2020-08-11invoice-QWBK8-4888901.docdoc 0c5ff699c5ce1207a99bf313c0671b6feddabdccbfbf212a8ff166ba4c658a59Virustotal results 22.95%Heodo
2020-08-11Invoice HBH7328 43241620.docdoc 233870a634ccdf96fdda69a701b37127e715c783be8864a56bf8a4ac81223f8cVirustotal results 24.59%Heodo
2020-08-11Invoice PS05 593263.docdoc b62a1e1adccc08cc8064309a5d7feb151348e3b1de2175cff71db2b252db5336Virustotal results 24.59%Heodo
2020-08-11Inv X870 8895587.docdoc 9f5254aadc7a867d60371d269a9dc5700029302284d6d0e9b152fa0d5b27c67eVirustotal results 25.42%Heodo
2020-08-11INVOICE-JVQU438-061269415.docdoc 539b9b6a1a67270d4042d4a27e6c105ab464ca4a6bde8bc31a6cc617867c6dbbVirustotal results 24.59%Heodo
2020-08-11Invoice TV196 4360874.docdoc 920f950bc61e9c48ea08d7d68d5b1d5f8a96a323a027f67380f61b63004a2048Virustotal results 43.10%Heodo
2020-08-11INVOICE EBRF57 953118.docdoc 3d67e2d51250c36cc9e982d2c244daddef2075c3776d37bb1d56e09186b2ebb7Virustotal results 43.55% Heodo
2020-08-11invoice-XJX3464-423728.docdoc 8ae38417b073e0d10ce8af04602bbb886fe6a48206d5f9a1d23e6ad1cd8e2964Virustotal results 44.83% Heodo
2020-08-11invoice_NTAQ6314_12182960.docdoc d9d5afd0f83aa28a06f4a1b5dc642926301d0b9bb7cd9dc22dc75ef49fafa296Virustotal results 45.00% Heodo
2020-08-11invoice_TAVU20_99232711.docdoc 00c79cf67a9dad04c8c95c56c0ee755066e266c384f38f106cbcee90931e6cc7Virustotal results 44.26% Heodo
2020-08-11Invoice_LGRD7_503036.docdoc df9751edb6d3f6da4e475cc3b05844cb0833623d6e9f3d268a38611dd8bd15a3Virustotal results 42.11% Heodo
2020-08-11INVOICE-QI99-25541799.docdoc c1fc85d3b078b060a5335fd6ccf06322f2e7f97c39ff74defd85719891c024d2n/a Heodo
2020-08-10INVOICE HQF7 84673908.docdoc 8d633fb09549bd4202d9b0fb92938e6c836b543d4aca5c21cda1f385b948c636Virustotal results 40.00% Heodo
2020-08-10Invoice-MS616-590289.docdoc 54daa69279ba46571d3bfda4b3b8b6f552f34d59053e6c895b56f843b7ac74c3Virustotal results 43.86% Heodo
2020-08-10INVOICEL572797537.docdoc 96379d3c95f98bfe9120778d7b62fa83e9ee5f7f151ae6ba8c6b169dd1a94d14n/a Heodo
2020-08-10invoice_MH4138_42998889.docdoc fd4a3abaeef0f14c5df818296353fc22cca15439026cf73373152b3554d243f2n/a Heodo
2020-08-10Invoice_J2_282439985.docdoc 9dee7b99229da39cdbc49e96e13a04cc9830de7c5049cf4b3da0ce59ce9caa35Virustotal results 40.68% Heodo
2020-08-10Invoice E478 835135.docdoc baa5032273841510fc30e55fe98c2a295e6c5e0871282e755a8d51a41c553ea0n/a Heodo
2020-08-10Invoice-179-32724028.docdoc b14fa823fbecfbb25d2c29a40205a6577a24684a9827ac93050101cb39930f54n/a Heodo
2020-08-10Invoice-AM4-456435844.docdoc c4a2bae75c280e941ca37cd555c596ade2a07a15b03258f045f333b36c647e3aVirustotal results 41.67% Heodo
2020-08-10INVOICEQXR17085748844.docdoc af0d5de2d7c042299a5923c3e41fcd47126cc3aef353aa3c5d690d4037af51fbVirustotal results 40.98% Heodo
2020-08-10invoice YN8 89244563.docdoc 14045c2a1f8106f62cca9878b82b62d33cbe757e36d4f41266e905a0d3db4121Virustotal results 41.67% Heodo
2020-08-10INVOICE-RH7834-65597847.docdoc 774530c33388236c1d8ab53566cbeeca0155a6e56f23a1195721e3f400869d9fn/a Heodo
2020-08-10Invoice_IQB6815_19350043.docdoc 54cb06956136a0df1683233191b174ee8a72c9aaf5dc08ec4ca50b90df27435cVirustotal results 42.37% Heodo
2020-08-10invoice 2 45130940.docdoc beee072969002550ae344d89f60fa2fbbeadbe74b97db6a20749b4471ab6f593Virustotal results 41.67% Heodo
2020-08-10Inv-DF3-762619.docdoc 4b1c0cd4b9c61e033476d74f34c90051b873f4d3a48c5ae7fdbff99f31fd10bcVirustotal results 41.67% Heodo
2020-08-10Invoice-FAL4114-909189.docdoc 77a7f63308c650adce9fed7787d7c8347409d01157adfedff5c9ba2815a668f1Virustotal results 40.98% Heodo
2020-08-10Invoice-RP3-4367149.docdoc 97a12872e1a90576545f3e2f3e0a49751b3f666b1cb16148177733fb58f87bd7Virustotal results 40.32% Heodo
2020-08-10invoice VZ277 91439348.docdoc b4590afc8fab4b9b2123a9c9f71f8f96b0ce29e3203f32876b5b65c919dc0675Virustotal results 43.33% Heodo
2020-08-10INVOICE8538351377107.docdoc 50dc61537bd9f610a60010718e78309dd3142bc281b484bc4ae76d38397aa724n/a Heodo
2020-08-10Invoice724360282.docdoc 837235f4d4509f8d6551f724d18d3a6c133038c7194abb3c65c7364ec33a4a31Virustotal results 40.98% Heodo
2020-08-10invoice 8351 1313680.docdoc afe4673ec323502e26eb3d3c453006149dbe88eeb83356eac9fff81077de6786n/a Heodo