URLhaus Database

You are currently viewing the URLhaus database entry for https://theepiccode.com/wp-admin/8r3jrrh-93008/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:440600
URL: https://theepiccode.com/wp-admin/8r3jrrh-93008/
URL Status:Offline
Host: theepiccode.com
Date added:2020-08-25 00:16:12 UTC
Last online:2020-08-25 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-25 00:18:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 13 minutes Good (down since 2020-08-25 02:31:19 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-25Inv. 07668389.docdoc fcd403ce13660e21c77d6e5cfd6eb32afff4ff88ab361a477a25d2fd1bf9ffean/aHeodo
2020-08-25August Invoice.docdoc d88ad8af3cdc4ade883d0afff8c98114ac25e6619b3334d3a51a12b4455d3734Virustotal results 37.29%Heodo
2020-08-25Invoice.docdoc db78896d8992dca8991556b8c86d49f8b09400f1f7ca3fcd7201a59405e6afa9Virustotal results 39.66%Heodo
2020-08-25Invoice 00609162.docdoc 8a4bfcef3795f1447eedb5f54a17d950cb575cb4aa5fab0efa1641b209eb67ffVirustotal results 38.98%Heodo
2020-08-25Invoice 290743.docdoc 93d414dd85aae52636e5f195908fe9f0a027a670020d8b52f37570ba6520068fVirustotal results 39.66%Heodo
2020-08-25Copy invoice #9287.docdoc 5a98792e4de10c9cc05bc756368773f9508680e67448b7185d3906959f288805Virustotal results 39.66%Heodo
2020-08-25007095819.docdoc f963aa15aeed7c58849f54812cf448a0df032cdb7724112e2adcd948aeaf00e3n/aHeodo