URLhaus Database

You are currently viewing the URLhaus database entry for https://multi-medical.com/wp-content/vDDrgb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431477
URL: https://multi-medical.com/wp-content/vDDrgb/
URL Status:Offline
Host: multi-medical.com
Date added:2020-08-13 02:49:28 UTC
Last online:2020-08-13 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 02:50:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:17 hours, 45 minutes Good (down since 2020-08-13 20:35:21 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13Invoice_QT9_12955747.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13invoice_NYJ38_836198.docdoc 4dc091daaf9b2ff460f2d3494beb83445f498784dce48abf4d793b1fb6955f07Virustotal results 35.00%Heodo
2020-08-13Inv_XQT45_139513.docdoc 3d0036d52990a0213f5c99f7929c005ba31e75d971852d42cdb1343128b1584dn/aHeodo
2020-08-13Inv_4472_6177829.docdoc bb480394e0201866ae43a5b60c1ec371e3dd37a01e922a8dd5ff68d8cb325f3eVirustotal results 38.33%Heodo
2020-08-13INVOICE-X8-0733844.docdoc 7f84ffec8d67c90cf874b1c63419a909e57b6e610d050a800bccfef7de037607Virustotal results 37.29%Heodo
2020-08-13invoice_60_607425.docdoc b133317c26c5f7804469fdb2d3cfe7bff2c09e8009f94b7e2e89120b95b6a996Virustotal results 32.20%Heodo
2020-08-13INVOICE_VM0_507042.docdoc 82b0468b8277859b0d4bff3af6eff0d446bbba4daa11cb4d96b62160bb22e3cfVirustotal results 33.33%Heodo
2020-08-13InvoiceXV47401581.docdoc 196a89c54cda70af31877740ead0a738ead3533d3ef89e87e31b193044fb42f7Virustotal results 31.67%Heodo
2020-08-13Invoice-34-586883444.docdoc 0d943363cc7316d93b7afdeaedc54c7b7f8dd8b7d63b81516d89202f6d95f96dVirustotal results 28.33%Heodo
2020-08-13Invoice FAGW6 80158009.docdoc b4bb0ed99478a7910267de0a8b83d95d21e41f8104509a278fd52affedaeb887Virustotal results 28.33%Heodo
2020-08-13Invoice192818797.docdoc e2b52ca08d4008fa9685112c5dfd20fcc5fb9d70c23426f9a30404ece51ca0d1n/aHeodo
2020-08-13InvoiceIUST616380071.docdoc f392265c903b4cad60edb998054c18fcb2cfdfe7e9e068ad6119545be62062e6Virustotal results 28.33%Heodo
2020-08-13Inv-D95-84759887.docdoc 5d894ef153180b84776667977d9af12006256fd8598c0ce0738c65ee160e190cVirustotal results 26.67%Heodo
2020-08-13INVOICEAHFA646772473345.docdoc e9bc4332a3fd2de13d8f4d58aaf749131a93e652fd663f83005b1437936a715eVirustotal results 26.67%Heodo
2020-08-13invoiceZKCY042055821.docdoc b728f085e0e3133f7083a77948330f193955e186b2e479815f2657baf3802c57n/aHeodo
2020-08-13INVOICE_9273_4569189.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13Inv-6876-7967526.docdoc 86c0cc8d6327a374689e50a0d8bc139919ce31d297cce113a4e93bd78b8cd8a0Virustotal results 26.67%Heodo
2020-08-13InvoiceF726733797.docdoc c30a4592cd8e7e2a97b2ee19d0061553ccbd7cd1b7e2af8bca2dd6913a1bccb5n/aHeodo
2020-08-13invoice-W7538-155477.docdoc d9d595a78d3bf3bab0e65cd5eb3a71ba4bb95ed7850e84862d01930ceefd1c35Virustotal results 26.67%Heodo
2020-08-13Invoice-5284-532007.docdoc 8d3707b8799040b4d0ae3452f01c096d3658cb6636834e49f602c9f745ccd6edVirustotal results 26.92%Heodo
2020-08-13INVOICE 88 779981.docdoc f844331d28cf2533981a9e753d6df2e9677efadaeea9b2c014266991ae78280fVirustotal results 26.23%Heodo
2020-08-13InvoiceNBU86730273900.docdoc d4f1ca6b7e264ab843f2bf183ff3a4bc306e513e7b5edc1cd49154e8f0e88499Virustotal results 26.67%Heodo
2020-08-13INVOICE-C549-192170780.docdoc 7b6f86d6898258e9a8a5a572e055f9efc0d045b78fc6eb88c0d2f61f064629f2Virustotal results 25.00%Heodo
2020-08-13INVOICE_RVDO1535_049661853.docdoc cc8c1667a1b992293217c0bb3a7bd8be2cb3d4f83bdaa7746fdb6b36992bfa5bVirustotal results 25.00%Heodo
2020-08-13INVOICE-RH9672-034569652.docdoc e1b7a11726c385bcad71dfe791b165802cc625ceaf2f1550a5a10f5f222ea90dVirustotal results 51.67%Heodo
2020-08-13Invoice_X985_178797.docdoc 10531f315432369a9c0706bc00ac1405445316044a9ec07b03de6606a6a9f9fbVirustotal results 55.00%Heodo
2020-08-13Invoice 3 02888359.docdoc de63eeb9f1015ea52b0e1a4d4698d706634a985366000085cfc06c5295b0d165n/aHeodo
2020-08-13invoice_ZGUD611_607906427.docdoc 17b6049e45eaf5263f576de1799a8b8ccd0164f7e1241cf72738d56e8793458aVirustotal results 53.33%Heodo
2020-08-13Inv NUK5 430619475.docdoc fddf4cab73e6e2ff5c40c7fee09d52d5eb903e6bd17ad77aa292c6ded707f394n/aHeodo
2020-08-13Inv_Z6342_9401946.docdoc 41bf6fae061d1cb621549ff9961eca7a61ac789aa4b744c7fd50fd6ff1ae1b03Virustotal results 55.00%Heodo