URLhaus Database

You are currently viewing the URLhaus database entry for https://commodex.com/img/parts_service/rd3zut/r3j2996390081516mil754zjy9vv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433040
URL: https://commodex.com/img/parts_service/rd3zut/r3j2996390081516mil754zjy9vv/
URL Status:Offline
Host: commodex.com
Date added:2020-08-14 09:14:36 UTC
Last online:2021-02-24 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-14 09:16:02 UTC to arin-abuse{at}tucows[dot]com)
Takedown time:6 months, 13 days, 23 hours, 30 minutes Bad (down since 2021-02-24 08:46:54 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15REP_GC1402680436JP.docdoc 55f8854dbcaa2832aa10f768c129ab27544b5b153c7e4ea008f7ae9444681eecVirustotal results 47.46%Heodo
2020-08-15LY_30266213641137480807.docdoc f8b496c0f286d5a7fccc4ede8b957465c515601307821f28b9353d38e79ad46eVirustotal results 40.68%Heodo
2020-08-15FJS_080120_GTK_081520.docdoc b165a72e79277f849a4ef95a5f985c8d4c92c6685bdeedd4326c941c9931c1c8Virustotal results 41.07%Heodo
2020-08-15REP_47QPWWRL31NTSA.docdoc 45d56ae98b903ed9de020e018e51c9d37a174963d35142bde75b6da213b0afffVirustotal results 38.60%Heodo
2020-08-14VCJ_080120_IRW_081420.docdoc d7172f5348db3ac97dd9b2e49bc36fda6f2f64c3bcbadcdd6d30a74281ead16dVirustotal results 38.98%Heodo
2020-08-14INV_FWP_080120_KGH_081420.docdoc e6fead9f89084cb5b8aa3bd84f6ad71c0547b9d1c700805bdc45f2382d5bb2ffVirustotal results 40.00%Heodo
2020-08-14LSPQ_IT0162968435SE.docdoc 41aaeee86aca179d46c937a4e3b3294e1fa6fc9aac94f1f58637a7c4ee2ad263Virustotal results 32.20%Heodo
2020-08-14REP_00113549354.docdoc 69c0f172c5f915aae73813afb13b0dea6ea5b676961d73b0b57614b1c0f24332Virustotal results 31.67%Heodo
2020-08-14PO_08142020EX.docdoc 82faf0336d491e0636c3f7cc5aa74e9ac373f01ff2b04bfcc96bc453ffac266eVirustotal results 25.00%Heodo
2020-08-14FILE_PO_08142020EX.docdoc 7b33cb52d7aadc252be1077c9acda4ca235a69d419c1673b40823778ae8b5a3cVirustotal results 22.95%Heodo
2020-08-14INV_WB8306522215JR.docdoc 69c415173df24e36396e61f51ceac50bcc46a2e54ed558e7e88e26b9c05f24f2Virustotal results 22.95%Heodo