URLhaus Database

You are currently viewing the URLhaus database entry for http://ymgggp.com/wp-content/open-box/special-portal/1wbu-1svs9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428791
URL: http://ymgggp.com/wp-content/open-box/special-portal/1wbu-1svs9/
URL Status:Offline
Host: ymgggp.com
Date added:2020-08-10 19:02:05 UTC
Last online:2020-08-12 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-10 19:04:02 UTC to abuse{at}linode[dot]com)
Takedown time:1 day, 23 hours, 57 minutes Poor (down since 2020-08-12 19:02:01 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12Mes 2020_08_12 V646.docdoc a96471c2ef6e0f48534a2d7bf4dae0559e635b17db0c186973c27ccb3a6bb53cVirustotal results 45.76%Heodo
2020-08-12File 2020_08_12 217.docdoc 5533ab63812eabe5768d2caa2256c6534a3aff9db5cd8df51be63d972b48bc37n/aHeodo
2020-08-12List_20200812_X30301.docdoc c3c7747e66aafb9af769e878af351dc5bf1d8a99d79617122ee15e02ace032b3Virustotal results 40.98%Heodo
2020-08-12LIST_20200812_5958.docdoc 0cb6700ec14b3bab7a93b82cff3e797676931357fa974ebe8a16b0de55eaead7Virustotal results 38.98%Heodo
2020-08-12arc_UCS854145.docdoc 6641adcec7b25c5a81e2f4515fe7303a71891b0f67e21a805817f013de9178c3Virustotal results 31.67%Heodo
2020-08-12DAT 20200812 H77649.docdoc 9e2108ece91a29ed453a943489b8fbf126a00114b4aa73c987b230e4a83bc5cdVirustotal results 30.00%Heodo
2020-08-12MES 0699.docdoc 98cdaca6fb4bec5a48ca84cbfa00b123f41849a8c0e94c9a7a0b5e2e00bc2ddeVirustotal results 28.33%Heodo
2020-08-12list 20200812.docdoc ab27914f156acd19f0881239e640672cdeb34584233e8b0c5c1e5207c1135e4bVirustotal results 28.33%Heodo
2020-08-12DAT 149472.docdoc dfd7cacf89ae3e789859a1008834beb34dd19ee305c54436efbcd70b475e4a0aVirustotal results 28.81%Heodo
2020-08-12LIST 2020_08_12.docdoc 9a3e221e7a322b7b9aba32f18fc7ef8751835341d9657cecbb8b53596702b4fbVirustotal results 28.33%Heodo
2020-08-12Arc-TWW00954.docdoc e94ead4e6b8438aedef07e9e5e01539d442aec9f156f80f4ee23677610ce9d29Virustotal results 28.33%Heodo
2020-08-12Dat-92982.docdoc ec492f642a8aa6fa2d723853f3406c42a3604e895011181c3589e5794cfd4375Virustotal results 28.81%Heodo
2020-08-12mes 20200812 2727.docdoc 39561a75fef92cc0d348f65d09feca92d1752da2928ff0217a3ba4f1db86c28fVirustotal results 28.33%Heodo
2020-08-12REP_20200812_Y01937.docdoc cf5c6559dfa14321a13a819d36e2bd4d75a84f866b63a4880da5d2eb28b4df87Virustotal results 28.81%Heodo
2020-08-12ARC-648858.docdoc 50ef5d0b0b7a0a0854a2bcf084cf61dca7c50050f555e23a4d4bf3e23a37a96eVirustotal results 28.81%Heodo
2020-08-12INF-20200812-MKG926396.docdoc c0d8e5987556d7ff3a75369c9d63e09f487dfdc0b64d5c719f649fc8f28c325bVirustotal results 29.31%Heodo
2020-08-12dat-20200812-HFM500.docdoc c5cf72d67d389db548717373f054466733e27034856015726230320261c7186fVirustotal results 28.81%Heodo
2020-08-12mes 20200812 RII2828.docdoc f5ec89a6e0a9e6f12727251ded2279035d817716542203ea13f4de99606a8974Virustotal results 29.31%Heodo
2020-08-12dat_164.docdoc e9e73551b173018c97ccd712ad5590dad7d9a180b3a4d70750d5c56ce4ad282bVirustotal results 28.33%Heodo
2020-08-12Doc PH984.docdoc ad251da9007f172f593f82d473b173f76d24aec811e95a5187722427da340622Virustotal results 51.72%Heodo
2020-08-12Dat-20200812.docdoc 2180342d9c66c0f6df8550aaaa50fa5977e4186f3934cd927c5ceeabcd3cca0aVirustotal results 51.67%Heodo
2020-08-12list_20200812_C6131.docdoc 1f2721d86674c089b606753be49e601afa652cd0daa1af0a19239ca33981af29Virustotal results 51.67%Heodo
2020-08-12rep-2020_08_12.docdoc a3703f60dbe4aa622cfc6db9fd27551cf9e8bf6398ee8727250898a495583e23Virustotal results 48.33%Heodo
2020-08-12dat_C21279.docdoc d6ceff199daed77e31636bbce10dd06d27353c4064b10c076028aea4313071c1Virustotal results 49.18%Heodo
2020-08-12arc 3046069.docdoc aa16198b53e4a0f12906d869baf7d712279438c0e5cb818a405a26f02d9b29d0Virustotal results 53.45%Heodo
2020-08-12arc_2020_08_12_005.docdoc 590e4167894112b18705fca17ee4057b39745b4af8c182ee650b066c9b195f8cVirustotal results 48.57%Heodo
2020-08-12LIST 094.docdoc fadf9dff9ac739df4bfe67bb110d2570b3a8b56ff10d4d0a619ec013819ee896n/aHeodo
2020-08-12list 20200812 ID687942.docdoc a86eec1385c130042a6609edfa33a94bd2e475ddda047eb16553247dd67622b9Virustotal results 49.12%Heodo
2020-08-12LIST_2020_08_12_JPM066199.docdoc 6fa74bb52572c68bce1d712b488aea9184f884d85ef22b26492011dc0fbec3a8Virustotal results 50.00%Heodo
2020-08-12MES_20200812_6545859.docdoc 7d7ecd381d765e01cbb41e6b0a254b7bc60ebb1d59c3c212286dbb9054e5093dn/aHeodo
2020-08-12file-2020_08_12-4369.docdoc 2d9d999204b6190a6e91bc1da7b0330466f17a916b33c2cab9bd681bc5060e10Virustotal results 48.33%Heodo
2020-08-12Inf 2020_08_12 L544.docdoc e49959014262227a3e6ca5bc2937e6afab83a251fc694000d1a3d38e7814d9dcVirustotal results 50.85%Heodo
2020-08-11file_2020_08_12_WD6879.docdoc db2aadedc60eea4a3a77bfbd6c1334cfca2091f721e34c196cde4f47624bcb90Virustotal results 49.15%Heodo
2020-08-11inf-5665436.docdoc d135bfa839f7aced43217658d78cc59d8c51a7120940e59b3c805612e1b276eeVirustotal results 50.85%Heodo
2020-08-11Inf 20200812 760700.docdoc 1a7a977f0328b4118f2f26182d1cedae0c09afdd9819c51e56fd41599e8bcf29Virustotal results 48.33%Heodo
2020-08-11Inf.docdoc 215dc1b22108efcdd066fc117c1a8aa3e86d4c0bc38bcfc5210977c9b7b97264Virustotal results 49.18%Heodo
2020-08-11Mes_20200812_H1812.docdoc 04eb4b28247dcf99dd7a07b62ab41575834d865c72e083dafd8e6b620a6e23cbVirustotal results 49.18%Heodo
2020-08-11File-20200812-9150.docdoc 7100d7486bcccf991906541b709fd020c8cf3aebaed5025f37c19ea15924b034Virustotal results 50.00%Heodo
2020-08-11MES_2020_08_12_4593264.docdoc 5e024e08e0d813ae8a53e1428e482971b0b92dd724030cbc1e80219aebccb455n/aHeodo
2020-08-11arc 20200811 821064.docdoc 6bbbfea0979ddea7c5b31d79ead31b118ac7455812560b7e9bea64b8d1cc3366Virustotal results 47.46%Heodo
2020-08-11LIST BJQ543.docdoc 6c43bac38a962a5ba3d1c691a45946526dc5a550897af82d14982b94077a6d29Virustotal results 48.33%Heodo
2020-08-11DAT.docdoc 505bf00a3f0c6b5d8ececc410f78de1bdb0fffc8fe7a3324166448fbb3a213f0Virustotal results 46.67%Heodo
2020-08-11doc 2020_08_11.docdoc 669795b953f2d46ec362bc03adae579299f4c4a42392c7cbdfef5ab5b54b5ec1Virustotal results 37.70%Heodo
2020-08-11doc 2020_08_11 A363.docdoc 1da87bf7cde42012d6ef60a19e839e43b5cf12ca5942cd31c40cc0ac0e31da49Virustotal results 40.68%Heodo
2020-08-11arc 2020_08_11 8361.docdoc 9081c21cb26135e8d85675222746dc6dd85b90f195e45ca7cc051103751fa512n/aHeodo
2020-08-11ARC 2020_08_11 MK37938.docdoc 0c2fd444f2fb9f77cde4f5629c19ea2ff814f7cda10a63a6bc6227d3ce403b4bVirustotal results 36.07%Heodo
2020-08-11List-1650441.docdoc 4a0b580e9b59383cef5ee984231048e27d3e01c6bbc31f779fc80f435d286940Virustotal results 37.29%Heodo
2020-08-11doc_2020_08_11_LUR5354.docdoc d2d1169820bcf260d48e6273ea105b4db9727fcaf8702362a7c8d3b8ca93b1b6Virustotal results 36.07%Heodo
2020-08-11Mes 2020_08_11 K344044.docdoc bef25908178e50a5ea5c9427e2d767e442719458414443980f1d1454659d4804Virustotal results 32.20%Heodo
2020-08-11rep_V099278.docdoc d959ba3063627e8c1ba90a9562d91943c0a6e82b8b2b749750fc5900649b6a12Virustotal results 31.15%Heodo
2020-08-11doc R9100.docdoc 356e3d6505e5c614fd7fe96e3e20c392e04e5b6e552a28f069dd37250d00508eVirustotal results 30.00%Heodo
2020-08-11List_2020_08_11_AAK402.docdoc c279b2621cc960bc14d86aa7b7a8ed1d61346e3e582e77072b43a1631871f3f1Virustotal results 30.00%Heodo
2020-08-11Inf 833.docdoc 5c7e33c23d454291dacaf4ae431d451d0659a56b3cf2e2a0ed82002b5ee21bdcVirustotal results 27.87%Heodo
2020-08-11dat 2020_08_11 FM200251.docdoc 03ae6dacc26669e23257af7d5e8a8c8d15bdbe6cc973112960392ab22d03d93fVirustotal results 25.42%Heodo
2020-08-11DAT-2020_08_11-3681.docdoc 23315f65b06123e965e1949c08085c097b3efc919a3807955cd3e1acc596e809Virustotal results 25.00%Heodo
2020-08-11FILE 2020_08_11 N995718.docdoc b9d7c3f1fc34b47554d301ba8d6d5a60e86fb6db50fe0d212aeae580a8c38840Virustotal results 25.42%Heodo
2020-08-11MES-XWS207.docdoc d990f8ea6afdd409b408fefaf18c4bb205c5fef6397e1e6d7c9466a47b138cb1Virustotal results 24.59%Heodo
2020-08-11doc_2020_08_11.docdoc 9715534fe73d1a63f33ee24b769c7a8dfdadedb96b0c0e52fe0fa713f889d37cVirustotal results 23.33%Heodo
2020-08-11Inf 2020_08_11.docdoc 5920c7e4ce5cd003b9b0fc667cf8b9414312502656caee024acae86456e58ce0Virustotal results 25.42%Heodo
2020-08-11LIST_TRK421428.docdoc bdec17a0bd8af4f682e06a0e45531d3e90242d09c6a7e99b3c293fcd72418b21Virustotal results 23.64%Heodo
2020-08-11FILE.docdoc 6f6d3a2edfa5349cbbf5092d5138b5d29762b0e6d2d173974a37f21f3713bdf5Virustotal results 24.14%Heodo
2020-08-11Mes-S895519.docdoc 1120dc774813691b283970a1c385789e1348091375188983a903c5143f52beacVirustotal results 24.14%Heodo
2020-08-11List 20200811 4203785.docdoc 2625218978dc84d278092066c6e099ed58f536ea22be875f879d7180bf1a0eabVirustotal results 22.03%Heodo
2020-08-11LIST_L291.docdoc eaa9a3fa2103d303ee4a16d7a20d7fa41d0047bd31a6bd1e1a6718cf4df41881Virustotal results 22.58%Heodo
2020-08-11arc_E7229.docdoc bac9a9d3b5783ae78298bfd2e768bbca94c8d87986fc65ffe746ed49ccd32c6cVirustotal results 23.33%Heodo
2020-08-11doc 2020_08_11 CA6754.docdoc ad8ecc85066be281b996f847814e7770dd2316faeaf97406e310db7bd1e3498fVirustotal results 20.97%Heodo
2020-08-11Rep 20200811 A807240.docdoc ca9e326f9883ccb0ff723213e72819c6bbf04eeb79ff50338ea5f87f22337781Virustotal results 23.33%Heodo
2020-08-11Arc-2020_08_11-C040.docdoc 9dea2448db7b1a50b96944b0d89c0541ea881d78e7b0cd42598ae3bac80bc3ceVirustotal results 23.33%Heodo
2020-08-11mes.docdoc c63d69fb1a335468a6aeebc2b8af051bf71cb55b4808a17409b332fc70728b8cVirustotal results 44.83%Heodo
2020-08-11file 20200811 661449.docdoc 9cc9ffc477277e4e3f239e9614780f61763818b20a39f9bbdd64fc1b3239b42aVirustotal results 43.55%Heodo
2020-08-11File.docdoc fce0f3d055c058d10eaff76ccd0a00bc87a7fb733b1ce6894e486b39ebf6793fVirustotal results 42.37% Heodo
2020-08-11List-20200811.docdoc cae649fa4834fbe773a6759d1c55036ab5a152fa90aa2f64b7751e50b3e7deebVirustotal results 43.33% Heodo
2020-08-11list_QNH72649.docdoc 353b24cd1dbb7be15133b64495afbbd1846a83e775870f07cef1efc21c411ddfVirustotal results 44.26% Heodo
2020-08-11Mes-20200811-9510.docdoc bd21c54cff53a13d78966917cf55e87135e7020967d2416f6a0b259beba63dbaVirustotal results 43.55% Heodo
2020-08-11rep 19833.docdoc 980c5eb49f054079a587ddcfe2c193c45a1a6be41100c5f1179df24c87986712Virustotal results 42.62% Heodo
2020-08-11DAT-2020_08_11-0564.docdoc 92f8226b4916acee5abadfd888bd396b2979be223db46252b4decde8b4b3667cVirustotal results 45.00% Heodo
2020-08-11file-20200811-E482.docdoc e4790d41e27c6978baf5ccf9461b74b1e9606fdc7edcb4d2022edafc3d8a6fd6Virustotal results 41.38% Heodo
2020-08-11file 20200811 NJ53162.docdoc 13c77da9bbdaea66303dfe4cfcb8b5a9f8eae8d46f1e710ab6574c73b2c1d91eVirustotal results 44.83%Heodo
2020-08-11arc 2020_08_11 DZU6721.docdoc 3b8c4e97505c638f5483d32e67e05043b3f245cb397a0069370eec83299bb2deVirustotal results 43.33% Heodo
2020-08-11DAT 20200811 613.docdoc bda55acb649535e7d61133cf076b1604f3da829aa4d7b45a7bf3ba27466d9c3aVirustotal results 45.76% Heodo
2020-08-10Arc 0635.docdoc 1ff50f088800028624af3ad83890529e6cd409d4c797d27b35f77e33fe36793eVirustotal results 40.00% Heodo
2020-08-10File 0968946.docdoc a685d179f34dc5fcb9fdb968d93826a1931f9e729bd7fa6491dc6cacf4ca0c68Virustotal results 40.00% Heodo
2020-08-10list-20200811-31840.docdoc 230cc48c70942780ddd2cc9327ac6c9b96bd8c1272c1ad0ccde75cced629204aVirustotal results 40.98% Heodo
2020-08-10rep-2020_08_11-2961.docdoc 6c9c1e35a22b32ad9722b917f0562f65ec1e6f847bcbd63e4b5ca9a09738f860n/a Heodo
2020-08-10Mes_E315.docdoc d1995ed56b0d8d1b1696cf696e047d70dd9f86f9ba8dfeb1903fa84aa82f3e94Virustotal results 41.67% Heodo
2020-08-10Dat 2020_08_11 688773.docdoc 3b59369e3166425caaacc1f0c00428539ecec010f83337e7af44a660bc6c7735Virustotal results 40.00% Heodo
2020-08-10doc_20200811_3433129.docdoc 8bac60fe9c581db6206a5ca49fc3fc76df934a47006c8effcd145a6ab3c70cc8Virustotal results 40.98% Heodo
2020-08-10FILE-2020_08_11-AYO5866.docdoc 69a6b1c09608f190a59315faa99814cad90c3eda1f938f379415adb9ce80d7fdVirustotal results 40.68% Heodo
2020-08-10mes-20200811.docdoc 3708962d8333f33b8ca2229ccdf932d5f06c2e380b5634afb33c2b29e209e269Virustotal results 41.67% Heodo
2020-08-10arc 20200811.docdoc 8f9e5cbc1eaf541061e1c1fd545d23d12c9af3e75781e353cb46b9de8dfd728eVirustotal results 41.67% Heodo
2020-08-10MES-786.docdoc 6fdba2a3c021e527cc4d508e143f075fee286280cbb58cc759f2c7968248b1c6Virustotal results 41.67% Heodo
2020-08-10list 20200811 W26458.docdoc 47c81bf4ef434b2d8dcc344dd6d8bb166138e0df39808d51dc12f319eb134129n/a Heodo
2020-08-10arc 53801.docdoc b5184411717b5186e80a521f6b70c47091f21c4e9c586d2f565438dfaba70d7dn/a Heodo
2020-08-10File_36471.docdoc 21d305c97502379abad7f15c44454ff18239806f9839d1e72f83028893df2fa4n/a Heodo
2020-08-10DAT-603463.docdoc 6d218e558b2cf4b5f4564d9bbfe8feb68602b363228a53f9c7e7aba48ae19d1dVirustotal results 41.67% Heodo
2020-08-10MES-JV66812.docdoc d486a449b6d68310c6965a1dc538a48d27ca880c9a33ad021ad7a4bdf7c0430bVirustotal results 41.38% Heodo