URLhaus Database

You are currently viewing the URLhaus database entry for http://abcd.bg/wwvv2/DOC/d3z7815y3qj2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436252
URL: http://abcd.bg/wwvv2/DOC/d3z7815y3qj2/
URL Status:Offline
Host: abcd.bg
Date added:2020-08-19 00:08:04 UTC
Last online:2021-07-16 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-19 00:10:03 UTC to abuse{at}mediatemple[dot]net)
Takedown time:11 months, 1 days, 15 hours, 37 minutes Bad (down since 2021-07-16 15:47:35 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-06-10KF_81881637.docdoc 953aa7e768da992bad5022edcb252dffcb1cfac786ec59cd4359af3ee331aa3dn/a Heodo
2021-05-29KF_81881637.docdoc 7ef4e244401f962d7dfac252040230292faff50eacc55659b6bd94b08af5d685n/a Heodo
2021-05-17KF_81881637.docdoc 227ede901485e6009b2040f7867c83ae4fa0a33a4e039a07f905afb27600eb2dn/a Heodo
2020-08-22KF_81881637.docdoc 315af08c7e6bb4c97b5e8c5c4d7099bf7d56d511bc140e91f9ea94ea42da9236Virustotal results 64.41%Heodo
2020-08-19AA8202308407YO.docdoc 5b39d05fd1a75574a20fce09addb52c62b766bb08f8812b8d692936918ba780dVirustotal results 46.67%Heodo
2020-08-19INV_PO_08192020EX.docdoc 9ea591e1d7a55e8030d08c4d52a5f187c45415192f0417c121de3875d92245c1Virustotal results 47.46%Heodo
2020-08-19BAL_PO_08192020EX.docdoc 28e4449bf2803e0d685599cbfbd23a03ac3f9a69b25f6a2669de4ce252de4073Virustotal results 48.21%Heodo
2020-08-19INV_NFT_080120_OLX_081920.docdoc 546326b982f8d4e1c2af1b80d268127974403aae48e453ff6d8f1820120a8d0fVirustotal results 45.76%Heodo
2020-08-19F_49245596.docdoc 94fe6d0cc1723a60d8965c606027ad0283a60c1f4677cf33c8cb85fd202bbc60Virustotal results 46.67%Heodo
2020-08-19FILE_PO_08192020EX.docdoc bb7514867d581af837a3d30b735e4c0e010220c3b2bee800c0217cb4e7275e3cVirustotal results 46.67%Heodo
2020-08-19T_TVL_080120_ZMH_081920.docdoc 034413e15c11f242017c25c7a467c44104af729b4008793cc2254fafd97fa392Virustotal results 46.67%Heodo