URLhaus Database

You are currently viewing the URLhaus database entry for https://dbhmedicare.com.my/wp-admin/protected_box/MdZpQ9Th_zNAkOqAEidW_area/25390922_tPGWSpqI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432301
URL: https://dbhmedicare.com.my/wp-admin/protected_box/MdZpQ9Th_zNAkOqAEidW_area/25390922_tPGWSpqI/
URL Status:Offline
Host: dbhmedicare.com.my
Date added:2020-08-13 18:54:11 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):No
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15File_2020_08_15.docdoc 489e84c61f0e1903d9276dc7bba7fe7f936f26076d1276f41c8c52b3e3f2ffafVirustotal results 45.10%Heodo
2020-08-15Dat_20200815_YET6773.docdoc 3d0f2d26b212b8b5e15f8a6afbeff9fe0dbb6f5ab1bd25602b569df788ac4ae3Virustotal results 42.37%Heodo
2020-08-15FILE_20200815_2323.docdoc b4f5b5f33eb7a5a0d0bb1176d6f8b744020182040e9c66d0008fe869eca26cb9Virustotal results 38.98%Heodo
2020-08-14rep 20200814 SD402.docdoc 301fd0696df4354fea7f502a753193313493b4e003a3978b8d9574f6193b0f5fVirustotal results 37.93%Heodo
2020-08-14Doc.docdoc 0ef5d74fb08d3234223c5162b3fd727867ff508dd8b18bd06e88f88aae28d985Virustotal results 38.33%Heodo
2020-08-14Rep-20200814-Q4495.docdoc 2fd4c28254c26ca6af5c733fdd3f3b02460bbd37bd5338fd6cd609d68786743cVirustotal results 30.00%Heodo
2020-08-14Arc.docdoc 2883a855a5d3d792060cb4da7861c9f198ad05183837025afd773345603fb9e2Virustotal results 29.51%Heodo
2020-08-14Rep-2020_08_14-XN079.docdoc 2f1330991673c9225dbd65674c8cfb95a5e88d3d71c00c088314f509c6888a98Virustotal results 23.73%Heodo
2020-08-14ARC-JRF9298.docdoc 6af630f2e8eba8699fb72196cd2a2dae2660d9ff10f3899585f70b8a99087838Virustotal results 23.33%Heodo
2020-08-14FILE_2020_08_14.docdoc c09ca830d8e72158e3a845643e41facf35f4022b75b424c044f6ee936abbebf6Virustotal results 23.33%Heodo
2020-08-14Arc_2020_08_14_315.docdoc 319fe85b3e7bce40e737aff5b4e5d9987b512efd112919da1526dcdae8f44b13Virustotal results 38.98%Heodo
2020-08-14inf 2020_08_14 151934.docdoc 019623e49bf01d6e8e75763a29436c9b1199ae4a976f5d164445405e33e4b49bVirustotal results 36.07%Heodo
2020-08-13list_2020_08_14_4266053.docdoc 142798a8e40b9b11fe631f384e89f852c79de5a82b17392df6b46479be0a861eVirustotal results 35.00%Heodo
2020-08-13INF-2020_08_13-4468.docdoc 147c789ee92535626bf97593edc4cba8eb038bbe791b789dcd5b3bd764422ab3Virustotal results 36.07%Heodo