URLhaus Database

You are currently viewing the URLhaus database entry for http://profdevplus.org/wp-admin/https://paclm/66qlKdRnEZPN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:495602
URL: http://profdevplus.org/wp-admin/https://paclm/66qlKdRnEZPN/
URL Status:Offline
Host: profdevplus.org
Date added:2020-09-14 12:47:05 UTC
Last online:2020-09-14 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 12:48:28 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:3 hours, 38 minutes Good (down since 2020-09-14 16:26:55 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14Mes-2020_09_14-5795574.docdoc 0a57a981b3f9ff07b93b6d4ee241f3fe439ae244ddde2afaa7447c7fc23e841dn/aHeodo
2020-09-14DAT 449394.docdoc e42ab2c33e334aaa8d441b35ee6af4cfbf0b44d94e1a27383f436682592d0560n/aHeodo
2020-09-14INF 20200914 BK520.docdoc 86c0ce7ddf5c6e12b271984c7724e66b7b8db3ccc611a9635d8482bc01c86931Virustotal results 20.34%Heodo
2020-09-14MES.docdoc 0b783948053f5f1dadd529527bbbea3e2ed5e25f1cfa250aca3b6620aac9c26cVirustotal results 17.24%Heodo
2020-09-14FILE 2020_09_14 328.docdoc eedba6a1fec17811ed9e71674bca1376d7ae271b00bb6f4c3cff98b375b500a1Virustotal results 18.64%Heodo
2020-09-14Doc_20200914_381157.docdoc fb254543c44a1cd539f80a6ad686889e82942bde7aebada34cfe594da563ce12n/aHeodo
2020-09-14Rep 20200914 Y51786.docdoc 18a349df5779d75e3edfa11a8e4f4b08c492ca0012594283a64d35f672e7c639Virustotal results 20.00%Heodo
2020-09-14DAT_RJP67500.docdoc 709e80f7feba536995dab42bea3297f819ef278046977ac98457c0cf63b676c3Virustotal results 21.67%Heodo
2020-09-14inf_20200914_752.docdoc 94a373559487c9c043237211dcefdeac88a165bd1277f93549776815939bc1aan/aHeodo
2020-09-14UNTITLED-AG89111.docdoc f1f5cf89e4efd6d4fda071cfc2489dc4f7ebbee392f80bcfda05d7b16a296d72n/aHeodo