URLhaus Database

You are currently viewing the URLhaus database entry for http://mormedia.biz/stevewarren/vs960uun-iar8yhzl-resource/guarded-zt956i-ctX2mVZ2M/WBXFoAVlC-mMG43tdbqvnM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433197
URL: http://mormedia.biz/stevewarren/vs960uun-iar8yhzl-resource/guarded-zt956i-ctX2mVZ2M/WBXFoAVlC-mMG43tdbqvnM/
URL Status:Offline
Host: mormedia.biz
Date added:2020-08-14 13:24:06 UTC
Last online:2020-08-14 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002867763 created on 2020-08-14 13:26:10 UTC)
Takedown time:3 hours, 32 minutes Good (down since 2020-08-14 16:58:52 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14dat_4708.docdoc 42ff2736d6bea5f31eaa0cf531bf67861730ec192bd418caf52c3346eaab02a3Virustotal results 31.67%Heodo
2020-08-14doc_2020_08_14_K3421.docdoc a675c1f8716e8abbf91707c8dac69b2d16c14ea7177a8fabb92c4061b65dda9dn/aHeodo
2020-08-14Doc_20200814_410.docdoc 15bf348877c0e16234c6803525f0e8b19c7a3d2ec536f2f930e0f9c22d6f79bfVirustotal results 26.67%Heodo
2020-08-14Rep 1671968.docdoc e56836746be09c9508de189be4dcb73b8d44bcca31a24567423635ab94ec1cb2Virustotal results 31.15%Heodo
2020-08-14Mes_JQ9894.docdoc 78252ad2b7fdf76084db5db5d08d225e76927350c41b4ee9774a52c519bd085aVirustotal results 27.12%Heodo
2020-08-14Inf-2020_08_14.docdoc 5876c2aff80aa6b77b5351c4d919c3e040396b20c9634b560c16ccddca37a55eVirustotal results 25.00%Heodo