URLhaus Database

You are currently viewing the URLhaus database entry for http://hacerm.com/404/private_disk/close_xFAxVUY_tvoXnLKp/4qgi8zi9ya2lgq_5szzs9s/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435194
URL: http://hacerm.com/404/private_disk/close_xFAxVUY_tvoXnLKp/4qgi8zi9ya2lgq_5szzs9s/
URL Status:Offline
Host: hacerm.com
Date added:2020-08-17 21:38:07 UTC
Last online:2020-08-18 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-08-17 21:40:03 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 hours, 48 minutes Good (down since 2020-08-18 03:28:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18Dat_2020_08_18_VZF887.docdoc 046ef2036e93a6cf34529a8ebbb37aa633f1036021511edbee0fd2fac0363770Virustotal results 41.67%Heodo
2020-08-18FILE_X3494.docdoc 503c77f99b0c8271cb80a1101e69d6c9060647f7a4a8451c23aae49bd344b634n/aHeodo
2020-08-18mes_676.docdoc 78159b47ee6e43a81e5f727e9f01d56700fb22cca0c9f6cde333e91c0130dee3n/aHeodo
2020-08-18ARC_20200818_009178.docdoc 2c71b781d036db2d4d077269622615c4f83acf550bc178674d9c49d9360376a9Virustotal results 44.07%Heodo
2020-08-18doc 20200818 TZB32039.docdoc 872c0c3578f24be338bcaa8a29f2b157d80a2d3d5e5ecbd33b028bced714c077Virustotal results 41.67%Heodo
2020-08-18doc-2020_08_18-ZVP326065.docdoc 0ffb643d2ef22089512c5de14e1d2f14d5632e77e9f609b1374c79fbe0a788e0n/aHeodo
2020-08-18Doc-2020_08_18-5784.docdoc d34a4e095dde98d6740346383251d18ce5f9bb8c58071f128db8083844be55e7Virustotal results 41.67%Heodo
2020-08-18File_20200818_9914.docdoc e7007d098ff3b77d307fdffbc2b566e6396298bfb9718bd207a8b377aca0b96aVirustotal results 42.62%Heodo
2020-08-18MES.docdoc e06e8e48dcd4936943a50e59934ee668ae53c0124eb36d4c25976cd8012facc6Virustotal results 41.67%Heodo
2020-08-18dat 2020_08_18 7539276.docdoc 8bbfe9b6aae9ae8cd42ef61b046d0c690f0637f216d5a22d4a5f7911b59469f7Virustotal results 41.67%Heodo
2020-08-18INF-2020_08_18.docdoc e976f7e4de4c0bedc4e4bbc27752994f9110c050508b106611f035260551a8e0n/aHeodo
2020-08-17doc-20200818-71107.docdoc cc2b2954e615657190a6b35c6784f2280cf56ca53c09647bcd8e096a005642cfVirustotal results 41.67%Heodo
2020-08-17Doc-2020_08_18-PK4211.docdoc 2e363ae514de57da55513b7e9b5499e658bb254447ad4bac734032c94faed259n/aHeodo
2020-08-17ARC 7921206.docdoc 32cb1657bab6cea4734f694fefe16389dca17cad7673cc0be676c77e070ae735Virustotal results 41.67% Heodo
2020-08-17Mes 20200818 PN627.docdoc 34c3b24fcdb685c45554b1bc9ab60336cfb9233e87c3f21c61bd63723fea1338Virustotal results 40.68% Heodo
2020-08-17file 20200818 NJ918.docdoc 6535313a52f000bc92afec62f22968677544878c5cf2109e862e72f7c441dda0Virustotal results 37.29% Heodo
2020-08-17Dat 20200818 82036.docdoc 818e631aced6291b95a641f2eace827a0b9f2ee202b364a3a09378bc52401e03Virustotal results 40.00%Heodo
2020-08-17Dat_20200818_013.docdoc b217056622d2655617081ef69ad65da589c7ca744d2d1d6b666425f5d55f4644Virustotal results 38.33% Heodo
2020-08-17inf.docdoc 67e3d2e4c15cbacbbe31eb1f9d4f091cb49509df87b5a84d5509f3a31e1810caVirustotal results 33.33% Heodo