URLhaus Database

You are currently viewing the URLhaus database entry for http://sebayu.com.my/wp-includes/open_module/close_portal/m1EdRo9UMxX_dler4Lxi7vdnh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436262
URL: http://sebayu.com.my/wp-includes/open_module/close_portal/m1EdRo9UMxX_dler4Lxi7vdnh/
URL Status:Offline
Host: sebayu.com.my
Date added:2020-08-19 00:24:18 UTC
Last online:2020-08-21 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 00:26:02 UTC to abuse{at}web-hosting[dot]net[dot]my)
Takedown time:2 days, 2 hours, 4 minutes Poor (down since 2020-08-21 02:30:24 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19rep-2020_08_19-RC110.docdoc 418836a63d85c9e9f92094437a4c568d7846aa2ff9d05e55982526a2744aa52bVirustotal results 27.12%Heodo
2020-08-19Inf-20200819-344382.docdoc 7833c0d39d11142241550af1fa9cb743026dc00c841f79a52d695fd8e9bfdd43Virustotal results 46.67%Heodo
2020-08-19Dat_20200819_L51072.docdoc 63c85fe46afbae39a953f205b3b3d63109f1f4e6aabe61d3d1b9deb3ac66d335n/aHeodo
2020-08-19Doc 2020_08_19 AG971468.docdoc b4109096624dd29f07d9e5c328637c66396a4c0ba53760b48905a4d81e829027n/aHeodo
2020-08-19INF 2020_08_19 4331.docdoc a86c28f5295c185f2915ee99a403ab19f16f198486e5274d3f17319864566716Virustotal results 45.00%Heodo