URLhaus Database

You are currently viewing the URLhaus database entry for http://corporateworldwidetransportation.com/wp-includes/lm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437824
URL: http://corporateworldwidetransportation.com/wp-includes/lm/
URL Status:Offline
Host: corporateworldwidetransportation.com
Date added:2020-08-21 02:11:34 UTC
Last online:2020-08-21 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002878945 created on 2020-08-21 02:12:06 UTC)
Takedown time:15 hours, 42 minutes Good (down since 2020-08-21 17:54:52 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21Z_35191450.docdoc fbd63265ff2f62db6c66adcef3562a678b0243b77f9be2a726d4bcf87f68a9c8Virustotal results 28.07%Heodo
2020-08-21NQZA_89519524.docdoc c6a5cc3476c048456af1997e698dc72231c1be3e590f6c9783e8adf136320f46n/aHeodo
2020-08-21INV_ARJ_080120_OEX_082120.docdoc c1d3d7bacb25843fa99dcaf27b12c5b8c6d6aa2168fc23b63e39305c631ff01fVirustotal results 27.59%Heodo
2020-08-21YTND_DVQ_080120_IDS_082120.docdoc c8ec1a9b7d385d96166c22f142d0437768d0db460b1cbfcc53cd796bb0662569n/aHeodo
2020-08-21INV_40023451.docdoc 33da171c98a915b6b46ee6b15f06b10f57557c479fe659f138921a4578264ab1Virustotal results 27.59%Heodo
2020-08-21RKQDXMD1781K.docdoc 3e8208734b44f5600a38c69cd3cd3275d2fe8dc82af7ec78c8619383741b66d7n/aHeodo
2020-08-21REP_QV9CS0ZXHP4.docdoc 01298d83e8f16304e95326dc2aaeba75fb90913b8e359ba16ffa314513f6ef63n/aHeodo
2020-08-21MCD_080120_LXH_082120.docdoc a733a4e6024de8fb8639c32f10763eb1350346440beca5654a2d0dcb93ad94f0Virustotal results 22.03%Heodo
2020-08-21INV_GA1325285656IO.docdoc 58a281604d8cc5a9b15fef92ce48e6bdb1b9e8af97e86b1ea772bf6555a5b26dn/aHeodo
2020-08-21FILE_QLK_080120_QZY_082120.docdoc bce60944d3f355c0b0204703032c8c88b18863aab47ce9c419f3b2b9bead9c9bVirustotal results 22.41%Heodo
2020-08-21DOC_PO_08212020EX.docdoc 71168d573c54a2d35fe5f22691d9090791fe2c78cd932b4c9fdfec7062329f87Virustotal results 20.34%Heodo
2020-08-21REP_PO_08212020EX.docdoc 8a887dca0fea26577923cdf9c4985eac7870541eacebc98ac38b51a4bda04ab7n/aHeodo
2020-08-21J_29561758.docdoc a8f4d3cce2e44d80f854033bc5abd85b25fef08d58f6cd0c2e3624ab6c5833bbn/aHeodo
2020-08-21DT_IE1959862028JE.docdoc 83912e356ffc063006637864e3ceed204efd7141ac92b7ff91fc4e3372c2552cn/aHeodo
2020-08-2182535784.docdoc e0edc38058ce9b689134aaa2fde3ffec05c36a32a51eb58932d313160434ec50n/aHeodo
2020-08-2172NIOCDVDS.docdoc eea83be73bb6b63138b070ecbc75bc0af0a8f6540fb9125735eda75701adc2b5Virustotal results 20.69%Heodo
2020-08-21U_94543583.docdoc dd3afacc150ce99efa0843ef4211a83be23385d9f1d8661b1fd04f45975323e0Virustotal results 20.69%Heodo
2020-08-2165281193.docdoc a99bc78979b657a1d16c9c3cb64ddfbd2d0317097210ad0dd85088b7a6c1b3ceVirustotal results 31.03%Heodo
2020-08-21INV_4FHQ13AWM5DVLC.docdoc dfa53b1ba591b08dacd3b798dedee90d559b092102517b46cd1a04bccf51e386n/aHeodo
2020-08-21INV_0CDUWGYJFQR.docdoc f4cf506743474d0a3cd6642db40bb54301ec4a84e38d41782b1199600b16df5dn/aHeodo
2020-08-21T_865369380073399894695157.docdoc c6fbe26a69de6c684e24b5438000839980b291ba697b3749c226ee5871517433n/aHeodo
2020-08-21FILE_VL6585486642FB.docdoc fd2732589c07dc97af78689360772ace939ebdbf5c47132f7df607d9e24a267dVirustotal results 29.31%Heodo
2020-08-21REP_89869096.docdoc 0566ee320bea900383d9ca704bf88d12efbcb69e6eed4b55d1e904ced4c6af2an/aHeodo
2020-08-21IFI_080120_EOK_082120.docdoc af3988b7856704b5467030ee792d90beff86f1f453c3280c8d0f822b2dc9898fn/aHeodo
2020-08-21FILE_2233324773461894.docdoc 29489d8ec25a46a76a0bb977cba3d4260eef3e2520e1b060a323df2c5f8cd8fbn/aHeodo
2020-08-21JB_30415320.docdoc 346bffecd143569cdd0fb796380eb297dbf4b03fbb9c68edf994501847763d20Virustotal results 31.03%Heodo
2020-08-21IAW_XVOTPX9V7.docdoc b067f851af29843c48232b84fd2062937192d864d7f69979bc590786f4f4d4d7n/aHeodo
2020-08-21XOR_080120_HMQ_082120.docdoc 7112a5a9264a099d9056f3d980c95fead062c56ea04362528c505bcc6ddd2b1dn/aHeodo
2020-08-21REP_03GQTVC.docdoc 47f6342732efcd12286d1c14e1c445d607ea2b4f637b7dee23dac0db3edc2993Virustotal results 26.67%Heodo
2020-08-2175834627.docdoc c87f02029dfc7cc838cdbd76fe5640ab9778826bebdd965fd772f7b853d4178cn/aHeodo
2020-08-21FILE_AN9780996937NB.docdoc 32473b384e1e07f387b80575017b09c425d1bee0904b9d96319e3bb72e7d6ecfn/aHeodo
2020-08-21FILE_KJ2488893540ON.docdoc 4ab707775fa2390fd9243175abdd54e81f7bf91607d4d7fc5c97be1d43f8606bVirustotal results 31.03%Heodo
2020-08-21REP_PO_08212020EX.docdoc 24fd38bc7a9fc81d9db5634f8d3c76f68707dd688bd30ade28d86def52b8aa8bn/aHeodo
2020-08-21DOC_HLH_080120_YER_082120.docdoc bae16ea340cc512d6e1934d205bb3f0e34da81c10bbdf1a411b338c91f415c03n/aHeodo