URLhaus Database

You are currently viewing the URLhaus database entry for https://metodoretardex.com/email-a-friend/Document/1vdec0651283661130304cxlpfgypfj5d5hlxa5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:430515
URL: https://metodoretardex.com/email-a-friend/Document/1vdec0651283661130304cxlpfgypfj5d5hlxa5/
URL Status:Offline
Host: metodoretardex.com
Date added:2020-08-12 15:04:33 UTC
Last online:2020-08-13 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-12 15:06:06 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 4 hours, 15 minutes Poor (down since 2020-08-13 19:21:30 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13XL_DLLY9HR86.docdoc 41a0d09fc217911df24c7529fa274764addf047b407ce938a2ecc6df48bf03d5Virustotal results 28.33%Heodo
2020-08-13X_PO_08132020EX.docdoc 2712c4838033dedebf571013a2e3334dd6644d201c60f66a6580f25e578f7aa8Virustotal results 28.33%Heodo
2020-08-13BAL_WVZ_080120_QVJ_081320.docdoc 955f9eb7beb83d16fecdc7a1273c10b47d58b3461bc1743591284266167bbb41Virustotal results 25.42%Heodo
2020-08-13REP_PO_08132020EX.docdoc 3a38bfcf301f812b13ecefc82919227b6b84aeec8c038286bd84a4fca51aecd4Virustotal results 52.46%Heodo
2020-08-129559958077445632194.docdoc b09cdb8f91eb70d7f179d304a4585ab2b1867a160d9760ab236065aae029268dVirustotal results 50.82%Heodo
2020-08-12AMQL1FT6F.docdoc 46b8a4b2982c4321ecd75bac7301a0a5083bb123d93194885db88b08a6fc7bb9Virustotal results 48.33%Heodo
2020-08-12PO_08122020EX.docdoc 8aa9bf144243719f3c0a1db1e4d2dfc49338783ab393cc5e26e1a16f93e6e6acVirustotal results 31.67%Heodo