URLhaus Database

You are currently viewing the URLhaus database entry for http://wi522012.ferozo.com/dhm/paclm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433157
URL: http://wi522012.ferozo.com/dhm/paclm/
URL Status:Offline
Host: wi522012.ferozo.com
Date added:2020-08-14 12:16:05 UTC
Last online:2022-05-26 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-14 12:18:02 UTC to abuse{at}hostmar[dot]com,abuse{at}dattatec[dot]com,pablo[dot]pepe{at}adinet[dot]com[dot]uy)
Takedown time:1 year, 9 month, 19 days, 23 hours, 19 minutes Bad (down since 2022-05-26 11:37:35 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-25PO_08142020EX.docdoc 62ca2bba8580af8bfe0f7e0f0e3d7ef5ec3db1e92989fabd18f1cdc0fde766a8n/a Heodo
2022-04-24PO_08142020EX.docdoc 74647bb2b27f1d6c5a70d0e32333ac9e04e79ab81452d0d62f893b3d9668f975n/a Heodo
2022-04-21PO_08142020EX.docdoc 8ba43011431ebb65ffd026459d7a3d0efd300496b2c25e81c2a21bc0398a09can/a Heodo
2021-10-23PO_08142020EX.docdoc b7b26d2ffa78d7ca390dd89a58e46a46de17eb569fd3081eb97be89eb37455acn/a Heodo
2021-10-22PO_08142020EX.docdoc 3996ea0a22190654452c91df56979b8c2c5c48eb5265a3164a9ce419dcc83570n/a Heodo
2020-10-31PO_08142020EX.docdoc 7b2c1dadd87f092e82d597f29be748284843b3df750d3fefb4693b9ecc41f1aen/a Heodo
2020-08-14PO_08142020EX.docdoc 79cd7f136cc0a61a98a896ade45d1aa6746869461a7524b0abcdb743ff8a454eVirustotal results 23.33%Heodo