URLhaus Database

You are currently viewing the URLhaus database entry for http://dialforamassage.com/wp-admin/50nue3/xn6ido864570357900989zl3np43xrhkushlgnd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:444799
URL: http://dialforamassage.com/wp-admin/50nue3/xn6ido864570357900989zl3np43xrhkushlgnd/
URL Status:Offline
Host: dialforamassage.com
Date added:2020-08-27 00:01:11 UTC
Last online:2020-10-09 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-27 00:02:02 UTC to abuse{at}contabo[dot]de)
Takedown time:1 month, 13 days, 5 hours, 30 minutes Bad (down since 2020-10-09 05:32:19 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27REP_64126883.docdoc 73e4f9b7e2b1344fb051326f62f3f0f65382219e844543aedc9a7dd5e6c72357Virustotal results 29.82%Heodo
2020-08-2737207133353349357657.docdoc 77823f121fe25decfc185abf589256c90a5c98daa17c8e6a6e2acc192bb84522n/aHeodo
2020-08-27BAL_02450597.docdoc 91eee6c53cef6973fbd184df00499fd451d2c44b837ff7011cd99368298633a2Virustotal results 29.31%Heodo
2020-08-27BAL_DQX_080120_QRC_082720.docdoc f3f87a6dd05dca7f7bf21316df4aa90bbc92fd53a45b004fa5edd7b6017ea8acVirustotal results 56.90%Heodo
2020-08-2724163451.docdoc 560fc48350b60321bef9c84786d68acb7b7f4414d53d1fe7660563cd05cb5a1aVirustotal results 54.39%Heodo
2020-08-27INV_HNY_080120_CVC_082720.docdoc ccd219a6f531ed3f9ff84a1ce8e664e71c3dcc4af09fe196889fe1e1b69ed956Virustotal results 31.03%Heodo
2020-08-27H_P6NIO14LP.docdoc 39af19338e24f5fcea02d5777af1f45eef1669e7834311632f223524b7e773c4Virustotal results 55.00%Heodo
2020-08-277BJDQSKBQ2.docdoc abd2e27899da09f53fa00ceb940f6a914cd44af6cd1d754f783aff922eb9c45bVirustotal results 55.93%Heodo
2020-08-27INV_TBG_080120_WNT_082720.docdoc 4e48203902e2971b1f0046c8b0e664760e818aad6c055903981a67549c91eab6Virustotal results 32.20%Heodo
2020-08-27B_08996239.docdoc 9284c7e6b91850c02fecc222938859e5545d62484b7d969c48c182c17b4e328bVirustotal results 30.51%Heodo
2020-08-27C_93986439.docdoc 41627e3471672730007dc13d026ac234950ae1f71564721c77dd5aff29e9c51bVirustotal results 32.14%Heodo
2020-08-27DOC_ZV0020282742XT.docdoc 5e2acb078bf706a90389d90636ddaf5d332c47325336781c2ab14600e34adb05Virustotal results 31.58%Heodo
2020-08-27W_PO_08272020EX.docdoc d20d5bab876240cbf908d60dc4ac87b57258f02fbd9202d50733891f22d29592Virustotal results 30.51%Heodo
2020-08-27RKK_080120_FPO_082720.docdoc 3dc40e9a60c8557b94a21581a58c4566273a45eef074c0fc78b62bf39eadf667Virustotal results 30.51%Heodo
2020-08-27AP1LZAZQLW06H.docdoc 4ce815a9423e52b38ceedc5af97bd2f02672b7ffde760730599452b87050eb7bVirustotal results 32.14%Heodo
2020-08-27JV5740847756XD.docdoc 7fe66f85659a10160846a834f8b4befde4e554e2c6e6586097218eed58c96790Virustotal results 32.76%Heodo
2020-08-27REP_PO_08272020EX.docdoc 343d1420630029215787dfd364a4faca7bc4ca38097daee242eb72f73a6e894cVirustotal results 33.33%Heodo
2020-08-27PO_08272020EX.docdoc 7e6ae0bfbd08090276dc8821dbac500fae364dab68dad84b1fc2c4d971080dccVirustotal results 31.58%Heodo
2020-08-27DOC_PO_08272020EX.docdoc cd0f5f2cc1f1f1bc7dc7bb9fe38aed374ad228315804fa2a759639ab42a35d89Virustotal results 32.76%Heodo
2020-08-2768562925.docdoc d8b2892cb235a6a574651012133c78ab0928fdd3ce752cc0699681a373778c04Virustotal results 28.33%Heodo
2020-08-27FILE_3704026780377764.docdoc dca5bf3ec81849f15a96ff016d862539ecab9711026c0dad8dfb63e8fcd6f256Virustotal results 28.07%Heodo