URLhaus Database

You are currently viewing the URLhaus database entry for http://mayphiendich.net/content2/swift/gn3a4bcu/x7365105889mvm9i9ktkq7vc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436755
URL: http://mayphiendich.net/content2/swift/gn3a4bcu/x7365105889mvm9i9ktkq7vc/
URL Status:Offline
Host: mayphiendich.net
Date added:2020-08-19 17:50:29 UTC
Last online:2020-08-19 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-19 17:52:06 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 9 minutes Good (down since 2020-08-19 21:01:17 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19X_1977842114224.docdoc 1b110485a730140a1499cfb4e0313b280748117cd1f41699438e6e103af73ea7Virustotal results 17.24%Heodo
2020-08-197646362309501.docdoc c3f0d0d594a74f097907231612a0cd0da8c75160a2ae1064a3744ecdea407986Virustotal results 15.00%Heodo
2020-08-19INV_4077982451180092484.docdoc 7feab4f1f35adcc7433afdbf4448e5b79996fbe150dfe6e0f708a6c13ce86f7bVirustotal results 23.33%Heodo
2020-08-19FILE_3003536931.docdoc 7f3f68fc29feddc0494e2e4853b7454b5d0cceeabe5e0bcd13029c5ec301e9c6n/aHeodo
2020-08-19BAL_R54AGHAUFLEKNMY.docdoc a882484dd319c7363eab50da170eaf45d0be854d4208c86d3d9fa00621f2f9d9n/aHeodo
2020-08-193GFK8FVQ6.docdoc 529390562b286d3c2cfdfec7f930327818909b300cf64609a2d6d8bb3e5d47ebn/aHeodo
2020-08-19FILE_71378900746888.docdoc 90499b6cd235fd63115a4d18f0989f842252935038f4cadec17f85a2081b1cfdn/aHeodo
2020-08-19REP_31761953772195.docdoc 863115404bb5f48e7f22e292813820254117f2cac7a97b266e8a8fd6359557ddn/aHeodo
2020-08-19FILE_NBT_080120_XMV_081920.docdoc 0d9522e1c5d18866b466aa9d28546adc56ea56f6d821fdda5ab77b1285b9e0d8Virustotal results 23.33%Heodo
2020-08-19REP_PO_08192020EX.docdoc ed6f742fc6e103f092e9fd9301bf4ec786e88abca3ec1593661c4083f398616dn/aHeodo
2020-08-19FILE_66376496003319514396.docdoc 76b5b8d527359fb1183fc7e4e4eb0dc5369aa0126843b1ec8d04f73c658e0b15n/aHeodo
2020-08-19FILE_799620281277976595401207.docdoc 13b1f46a749e4cc9b3bf917bb29bac23d8c73b5fd97982cc625304ca1ed50edfn/aHeodo