URLhaus Database

You are currently viewing the URLhaus database entry for http://hebasharkas.com/wp-includes/xudNqer/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432810
URL: http://hebasharkas.com/wp-includes/xudNqer/
URL Status:Offline
Host: hebasharkas.com
Date added:2020-08-14 04:38:33 UTC
Last online:2020-09-01 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-14 04:40:03 UTC to abuse{at}contabo[dot]de)
Takedown time:18 days, 17 hours, 40 minutes Bad (down since 2020-09-01 22:20:50 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18Invoice 477 107907235.docdoc ebc98d0c466d423bce68f58425090a3e72dec8423a47f77a4eb9cbea0c0d3b5dVirustotal results 60.34%Heodo
2020-08-14INVOICEM774324671.docdoc c3ae8c61792f7f79027f657cd9c31091416b63260177f881c549a7dfda0a04eeVirustotal results 33.33%Heodo
2020-08-14INVOICE_ZKJZ192_441235.docdoc 8c7b70ac18632b9f9a785376d2b3052c939dc86148c26b710dcae2e8072c836dVirustotal results 31.15%Heodo
2020-08-14Invoice_KWAW17_60237269.docdoc 3d56178779af4f3321a7d6adabc672edb3e9036292191e34bb37d215e19a9f4bVirustotal results 30.00%Heodo
2020-08-14Inv-ETPC2301-1051051.docdoc c2af257a8a40028722b621eec7a07631530b6ad0a75733f89eb70aad03b1e4b7Virustotal results 30.00%Heodo
2020-08-14INVOICE K2 112270.docdoc 936f0b1c957e1480cdba3c5cefac63730008c19b570d825bd0d6c6de85ca38b2Virustotal results 27.87%Heodo
2020-08-14invoice_IB21_014109.docdoc 9d6676d7926e7555e55f55924ee0a8082d62b5b813ac98704090a5a23e7a1775Virustotal results 25.42%Heodo
2020-08-14INVOICE-JNR10-496143254.docdoc 104251c4ce5ddfa9732871b3478c81882c4e2544e2f2b615ee7e05a6c4c35b0cVirustotal results 26.67%Heodo
2020-08-14InvoiceGKB4988087211.docdoc 6805a810bcf466e80e587c1933e7d96d2e378735619324aa1ad6dc04d8173d68Virustotal results 26.67%Heodo
2020-08-14invoice-KK2214-197275739.docdoc 287b1c2cdc4b225da919062620fa3a273db58864387add5e91f642613c416075Virustotal results 25.00%Heodo
2020-08-14invoiceGV03523719070.docdoc 31fd17ea13411b2b4c8a726012b7e3390527519bfcb805d9d895877a627c8f7eVirustotal results 26.23%Heodo
2020-08-14invoiceLF200877530.docdoc 293c5df488141cb4aaa3c1d4e450c5f3fce9c1b3ff26d587b42c17d6a05758b2Virustotal results 26.23%Heodo
2020-08-14invoiceI085020124.docdoc 3d1d9383eb8fa943d9a30683c659bf8dbd0728daae34c9e0227d1585f26cb327Virustotal results 25.00%Heodo
2020-08-14Inv-I9-553861886.docdoc 73d4b0a7ca15e61e87a8fe48a88037618e4b4aac3d8a94cf4583f52cbab9bcc1n/aHeodo
2020-08-14INVOICEG002197569.docdoc 2a7342691538ac359f25d6ccd05e6b81f64ea3dfb5fe8af5f23eb3f3425a056aVirustotal results 23.73%Heodo
2020-08-14Inv-Y58-7945078.docdoc 9767bd56721afd6905bab6c3a1a8790999605c8e5b91b2dfded3a0849c7e5d60Virustotal results 23.33%Heodo
2020-08-14Inv_UVQ932_160214347.docdoc f841c145c39f74c12260a67c686e4dde761614e633f204a3e68f47750f2e6d1fVirustotal results 23.33%Heodo
2020-08-14Invoice_WZOK25_80743678.docdoc 99db7baf30cee72146c4791d36d158ca3ed62a58dd3bd57b7bfa60d0f13b08d9Virustotal results 24.59%Heodo
2020-08-14invoiceQN604536168053.docdoc 538aec1c87a88d78a75a417c253579be5fa18cefce592109122505cf70f2eea9Virustotal results 40.68%Heodo
2020-08-14INVOICE_PEUM26_52385347.docdoc fb17807621969c33d345882ad5ae95cd5294c32509e13a6fe8ce1d317a5c3f4dVirustotal results 38.60% Heodo
2020-08-14invoice_QID18_387579710.docdoc 3132acbb0aa02f175f2e8bf589a53e732564cf73f1f003cb64c842ba52d3c889Virustotal results 41.67% Heodo
2020-08-14Invoice-ZTSQ7-845649.docdoc 845f584a4b58e05f5eabb64041142baac8b97a971f88d4cb2544c4ac3af97a3aVirustotal results 40.00%Heodo
2020-08-14Invoice 4608 276978.docdoc 382eeb05e0b37509916697e88d5f58e00cfd17db07cf9b27240fd84aa4bcd26eVirustotal results 40.00%Heodo
2020-08-14Invoice-2127-62514373.docdoc 0a113fe937499c36099951c617841d7ac21c77a953e277ce6ee04023944a1ebfVirustotal results 40.00%Heodo