URLhaus Database

You are currently viewing the URLhaus database entry for http://odeftg.com/odeftg.com/https:/OCT/JisZ4GPkuVF1RiIH8RZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453390
URL: http://odeftg.com/odeftg.com/https:/OCT/JisZ4GPkuVF1RiIH8RZ/
URL Status:Offline
Host: odeftg.com
Date added:2020-09-04 15:43:34 UTC
Last online:2020-09-25 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 15:44:07 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:21 days, 5 hours, 2 minutes Bad (down since 2020-09-25 20:47:01 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05Inf_20200905_460001.docdoc 4c3f9a91ab8bd67a7de8b61f6d5e49c34a0c3ded123f63205f02d17ff570c204Virustotal results 30.00%Heodo
2020-09-05list IA565454.docdoc 8abd1fd956a522b05535b6b9ddb53a6c4353e20235979a9ed05679ac4f2a95caVirustotal results 29.31%Heodo
2020-09-05Arc 776952.docdoc 0b9a2df9ae8e7dd522a8250303134d9778a41e95d02c06cd0b6a060afdb62cbdVirustotal results 30.51%Heodo
2020-09-05FILE 2020_09_05 32745.docdoc e598cf9a18d4db4fa8174ec8f921eb470f8b844063cec6fa35185f7f8f1d2b4bVirustotal results 30.00%Heodo
2020-09-05arc_20200905_8120.docdoc 99b355a60a9590d4a7695c3e6dbd12bcc643041c7f98e39ebb7bd29d4300b770Virustotal results 27.87%Heodo
2020-09-05Arc 20200905 JIK018.docdoc 4d9d90d94b53b4f6c108a22f33df509c8cfac067f9a6b6d83fd50b9b1157d8b1Virustotal results 30.00%Heodo
2020-09-05File_20200905_8140.docdoc 4160aae4b7d4ee73a7137bbd2d8c5cad6f215282af86bec49526c1b15db1c50eVirustotal results 31.03%Heodo
2020-09-05Attachment_ZA970.docdoc 178548af9f561e5bf22a2a3bf689025f6219b073e79e56ea0b74f164dc02820eVirustotal results 29.51%Heodo
2020-09-05rep_2020_09_05_36388.docdoc 54fac54bf401937afa1a48e9545b32e46ac8be7c543918e4a841177baf879ea3n/aHeodo
2020-09-05mes_398570.docdoc 0274b67e43f98e65033f7b7b9c341a6560e515e61187693dfa5b941a2545309fVirustotal results 30.36%Heodo
2020-09-05Inf_2020_09_05_051.docdoc 27ad65edce895a8ac105708b7510859313c9f88cec6a66611b581bc480ad6676Virustotal results 30.51%Heodo
2020-09-05Mes_2020_09_05_07121.docdoc c1658fd6974ace7a621b0e46c9d3f1bbb8ad7d3ddeb3032082937f3133c1c063n/aHeodo
2020-09-05RYU378_20200905_MO103.docdoc dd845235b8dc3a025eea6b0904c7e90b610afc290c4b55a7921062ba9f33cddeVirustotal results 30.51%Heodo
2020-09-05Dat 2020_09_05.docdoc 51da971ad054a7cc8d3a929c87eba819eed539387ca660dad760e7bcf2477562Virustotal results 28.33%Heodo
2020-09-05inf IX080.docdoc 1fde53646d2021d4bd959bcc2ee2b8c1db5ca4b112b58af96efc114ffd4dc6e6n/aHeodo
2020-09-05FILE_2020_09_05_669.docdoc eda41409cac593fa280357f888dfed9313d45a2523ff59de058f32b76478d925Virustotal results 27.87%Heodo
2020-09-05mes_2020_09_05_6076972.docdoc 4845d731ee51494da878e4a1e0c22ad0e6e1885aebe593bb6b3adf115f9c84d3Virustotal results 28.81%Heodo
2020-09-05FILE_2020_09_05_202.docdoc b1d37441a65187f53492dcd30fe0d3fafb9de343694c7ac79d3ce5434cec9350Virustotal results 28.33%Heodo
2020-09-05Mes 20200905 OMS9633.docdoc 7b33fe4f09c06251aba09bbc5407ae8fd899bae0a40d3e7d55f3806a8b6a74a6Virustotal results 28.33%Heodo
2020-09-05doc 2020_09_05 HVK510.docdoc 0ca5df179f725a9c12ba1385711972c7e55bc02359435e954db6e65f1e2036fdVirustotal results 27.87%Heodo
2020-09-050390762_ZG266003.docdoc dcb081f33d098bd8befd0776a185a13823b7a4f29087f39cfb3b1cc9693722f9Virustotal results 26.67%Heodo
2020-09-0539973L C007785.docdoc 2ddd8ba7251afbeee6c41576c377265c1a2a9f5370cd66683c24db0c89a0062dVirustotal results 26.32%Heodo
2020-09-05Attachment 2020_09_05.docdoc c66ac5fc632592fd547d29b2ea0d58d6fd421effca802489611fb9a43a656a45n/aHeodo
2020-09-05arc-20200905-542361.docdoc 0917f0cbca78c19301ba65aa799b29dcf90ee3666fc9f8b83f00c5ea34a0eba6Virustotal results 26.67%Heodo
2020-09-05Attachment-2020_09_05-VOI66791.docdoc a4455d8697ed542eb675343e5b8806faa6b522c16a69fa423acaef8577319b47Virustotal results 25.86%Heodo
2020-09-05LIST_0610.docdoc 8d7ac57ba3c19f60ff3e7d2e5bccfb5a790b9d05c84fd5237e4235be91fde6a9Virustotal results 27.12%Heodo
2020-09-05MES-2020_09_05-702.docdoc f3c01505f223d53a856b4cbb5201b5cbad5706145be5e214e266f4570491a8ccVirustotal results 26.67%Heodo
2020-09-05FILE 2020_09_05 35556.docdoc 83d89a6f47106112698cbbe3f9f407abbefeaa5304896f38e7bff037db8cf901Virustotal results 25.42%Heodo
2020-09-05Dat-20200905-EHW337.docdoc 198707cda9c385ee925491c9dceb437dd9d3f34cba7e5cf6d99bf895f28bdb76n/aHeodo
2020-09-05Attachment_2020_09_05_4754964.docdoc 08946ba696e1f6e1da7e3f5cc61273c6d9c2bc25f61ff89151213d62d4c8e625Virustotal results 21.67%Heodo
2020-09-05Untitled 20200905.docdoc 349685f93e08324717dd09b79130205af7e095872a599905ac58c453d5a4f25eVirustotal results 22.41%Heodo
2020-09-05inf.docdoc 2d5d1fe8c77135420414a5cef6384683cfbf59f04e7e9b03c909c2f4c3ec54e9n/aHeodo
2020-09-05INF 20200905.docdoc 3c51d26e98137dad5c907c872c1af3b0faea7094df4acb08d71d8873e8800a9dn/aHeodo
2020-09-05INF 2020_09_05 JVK58953.docdoc a0c340e5b8f401a13ec7ea03f405623ed8532d1bdfc9f708d34ad94a2c14ac47Virustotal results 22.03%Heodo
2020-09-05INF-Q2088.docdoc 5d1e5bc11522b6d4daf399dbbd1a18561ee98aad33dce8f798e2aad3a2a5c329Virustotal results 22.03%Heodo
2020-09-05DAT 20200905 BI309.docdoc ac03cec1ea7e2d4ba254b3225a617ff11bb93247cfd84340907d0533522327e4Virustotal results 21.67%Heodo
2020-09-04Untitled_2020_09_05.docdoc d9a9da6db3834089876251db68e72db8a21ff82ee58ca338a43a055110f793c4n/aHeodo
2020-09-04File-2020_09_05.docdoc 6d8bb4cc926450189c32b7634d2940fba6556c2865096d7ccafec6b4b6e0c396Virustotal results 21.31%Heodo
2020-09-04inf 20200905 1272268.docdoc a68967c55063a216717a336462d01e74b4dbf73c0e3ad3b56bfe2c4ab10f3b38Virustotal results 23.73%Heodo
2020-09-04List-2020_09_05.docdoc 88d669402f9cb6d3c39a7de76b5e16c45d5db2b7a4e5c5f2b9ec112d299f85d6Virustotal results 21.67%Heodo
2020-09-04LIST-2020_09_05-6185.docdoc 0f264ea12ac1b1f96e80c683d7aabce629b15ded57f43e29a4faa7cbf057d673Virustotal results 21.67%Heodo
2020-09-04Doc 2020_09_05 644.docdoc a8e4d449c8018f90196d3de6e14d75cdca5c5f76b989880e012890f87d43f6c9Virustotal results 21.67%Heodo
2020-09-04INF-2020_09_05-71213.docdoc 44f213e9ff99dece96ea33d94a4e46bb3e508480002c5e255d46ca711b44a9e3Virustotal results 20.00%Heodo
2020-09-04Inf_9968.docdoc 17387deff7e3725fb0ae1aacebcb5e9be101e9ad64a337ce858202ef07458f1cVirustotal results 20.00%Heodo
2020-09-04list-ZFI85446.docdoc d22f6705c1735812ddadd90de20741627b3116e4f8f97de636b160757970fc90Virustotal results 20.00%Heodo
2020-09-04580503 2020_09_05 D074780.docdoc b177d6304e1239837128c14fc3423ded464e3877b918bdf27db3d2f40375c398Virustotal results 20.00%Heodo
2020-09-04804 Z7885.docdoc 4ad62f2c57a013638168235884ebd78c0b024008e87c9b2e84719d7543132e4dn/aHeodo
2020-09-04Mes.docdoc bd6fabb51f037d2253220c55129be8125a21f63b579dd69ca9d82604f0208b60Virustotal results 20.34%Heodo
2020-09-04Doc-0592.docdoc 9c0798c3e8889889ef70b039545920afb91f1508144606704a1889286192bbf9Virustotal results 20.34%Heodo
2020-09-04INF-20200904-NQX086232.docdoc aa3db031e17cd90af00951bc4d86c18c8e42328f47e9014b552993ff1b29c557Virustotal results 20.34%Heodo
2020-09-04LIST TF277685.docdoc be20749611f2a5d9a09e4782aa4443e339c5e6e4bffe65d32debca99b53d8d59Virustotal results 38.33%Heodo
2020-09-04ARC-20200904-056.docdoc 4c213965b64b715680686d5c98d5d0129fdccb424a5e74f561c6969fa785d75cVirustotal results 38.33%Heodo
2020-09-04LIST 20200904.docdoc 0cfb4e12de240822e52fa2d66698bdcfea13a994ccf47b7fa45634e0dfff294an/aHeodo
2020-09-04ARC 727.docdoc 53e22a87b7381a9a4a9bea066f9d1b435964fddef4e38f321f372fe6abc16854n/aHeodo
2020-09-04MES-20200904-UVK2009.docdoc 95718b95b1e8732ffb58a93557e44c7e7f99a0dec4ab200ad2ffa83e6b455780Virustotal results 36.21%Heodo
2020-09-04REP.docdoc 380c46aa7a6ebfb32b4e005930aa368ca90386ecf02e2587a0c6f035569df404Virustotal results 35.59%Heodo
2020-09-04MES 20200904 L854.docdoc a49d6ff985f57e4d6e09893b343f97b9da664ae8c0b7c0e95f18f1a8f119f1a8Virustotal results 35.00% Heodo
2020-09-04MES-XQA993931.docdoc 8a87e7dcaf07545941e8f4859526c55f0b840dc1d051e86b09200a3a49ba5c01Virustotal results 35.00%Heodo
2020-09-04doc 2020_09_04.docdoc cc4f7c86201d0618e4cc76f2030913800e738cb4a46496daa65e8f3507b3e12dVirustotal results 35.59%Heodo
2020-09-04arc_2020_09_04.docdoc 270c40ed02166b3f9687722a922082abd182688cb3cc27d4f0f27ff8af729b53n/aHeodo
2020-09-04UNTITLED 7840894.docdoc a7f35b06b6d94b7aacb7aaf4681b81b3373a4051b74e97e01ae6d58a2f052b27Virustotal results 35.00%Heodo
2020-09-04arc 20200904 F530093.docdoc e4006ffd7617f48dca3ed5e7220e159de2160b07f86452e1fcb7fa0f27ed1d9aVirustotal results 35.59%Heodo
2020-09-04Arc-Z57534.docdoc 5234c75f7c7319ead0ebe23478edfa5dc335ceea2205e3d61db96bf6c414e852n/aHeodo
2020-09-0403317 SLU47942.docdoc 38723e854156b62f83e4cdcf30c187c9fc432db05f0f55e1c824b40c7d02a489Virustotal results 35.59%Heodo
2020-09-04REP 20200904 V508959.docdoc d4416a6ff0dbbf8a60d1df15030c7eeaf6be3883b9f4df72bd6312eb84caa672n/aHeodo
2020-09-04Z2789 97341.docdoc 372bcdfc09a2f41eb9dff01047e6a63434a940526a08cc40100a82046d9c6fbaVirustotal results 33.90%Heodo