URLhaus Database

You are currently viewing the URLhaus database entry for http://julegaveregn.dk/wp-admin/http:/FILE/tJdkmCy7t7wIMk3sxch/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452156
URL: http://julegaveregn.dk/wp-admin/http:/FILE/tJdkmCy7t7wIMk3sxch/
URL Status:Offline
Host: julegaveregn.dk
Date added:2020-09-03 05:04:10 UTC
Last online:2020-09-03 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 08:40:49 UTC to abuse{at}zitcom[dot]dk)
Takedown time:6 hours, 13 minutes Good (down since 2020-09-03 14:54:13 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-0374146950_2020_09_03_5895505.docdoc 735617818e8d2ea0cf674f7722f0a4c73128aed869e1adffb63f34567a9d4647Virustotal results 20.00%Heodo
2020-09-03Arc-20200903-4730458.docdoc 7e979900e46de15883815a5c253c87cbb107219db542870c2c3da283394b7fc0Virustotal results 18.33%Heodo
2020-09-03inf-20200903.docdoc 2b4be15f0d85e69f6e3af8ff6a07242ceef68ac071cf2c5b71002187354cb1ceVirustotal results 22.03%Heodo
2020-09-03file-2020_09_03.docdoc 9a6f34385dbe97d930ddcc9802f71cb44af38c64df5b40a013d592052de7b0a4Virustotal results 22.03%Heodo
2020-09-03ARC-2020_09_03-IJ624759.docdoc 22a71ee772d1815f0554c2a1be645237d2c252db51d95ef7bf4128ed87308cfdn/aHeodo
2020-09-03List_20200903_IDR921591.docdoc c8a71c528548306c663f2b0c7b602a3d23ca301c9a946f6a105bd11ae7f1b8a6Virustotal results 21.67%Heodo
2020-09-03REP PG232.docdoc c0af2be2400e298680651009e6586ebd35f1655cc541948d513020e716155acfVirustotal results 20.00% Heodo
2020-09-03REP 20200903 G168704.docdoc f4fc8ed450e3b86dc85e37b8c98ea3a5749d5f4c25ce29f28691d08df1e56b9dn/aHeodo
2020-09-03Doc-20200903.docdoc f2ec9f235e2ecc536b662cc5fd8b7ebb4893228c8b9d52bdab8695bdba0ad2adn/aHeodo
2020-09-03Dat-20200903-SWE89263.docdoc 4605de521a5c8ea6ed6776f702bbc6cd5c5c7c4f5138782994e3de529ac5c2edn/aHeodo
2020-09-03rep_20200903_709.docdoc 6cffaf302f33249146288f181c629138504d72143a68e3c79b67c5a9ad8cbf0bn/aHeodo
2020-09-03FILE-S3918.docdoc 2f71eaa981c83d30d3ec1f042fab4edc54b367a5079b7ebbe32238cd5165b038n/aHeodo
2020-09-03Untitled-YB6921.docdoc 4a5029949cfff6d3fa6b2c99cccc0629409c47ec3c1998fc74c2af39a84fb774n/aHeodo
2020-09-03Mes 20200903 165169.docdoc 9775f8f46b36abeecfb6b000e26183a69e630b41dbdde865a9f58922e241ebedVirustotal results 18.33%Heodo
2020-09-03Dat_20200903_K4645.docdoc 68c5b0b61dcddea7b47c877d02a5d3d308d9753bcfd281a5aac05b1fbf496bf6Virustotal results 18.33%Heodo
2020-09-03Untitled JYW29688.docdoc d742952f4e6160da55a1d1f4851c20d36b539b3bd51eef7c8c3fb43aff4e7e8cVirustotal results 18.33%Heodo
2020-09-03Untitled_20200903_TCZ454125.docdoc 48cbc1f9d16ee39f9b8965f396d8004058d53b4391d3c72b810c214bc051d457Virustotal results 18.64%Heodo
2020-09-03doc_2020_09_03_3417.docdoc 114c63d1f56bdab107f97b6249d88799bc1902213c8dd15436b63373ec365ce4Virustotal results 18.33%Heodo
2020-09-03REP-186251.docdoc 290ed9c24539d01f8be31a788976ceda4646eccf4c0d685d5907a924a0aabf49Virustotal results 26.67%Heodo