URLhaus Database

You are currently viewing the URLhaus database entry for https://villamark.net/wbkszp/https://DOC/4rM4T48HdGs4AXhOktP/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:496599
URL: https://villamark.net/wbkszp/https://DOC/4rM4T48HdGs4AXhOktP/
URL Status:Offline
Host: villamark.net
Date added:2020-09-14 14:01:11 UTC
Last online:2020-09-16 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 14:02:12 UTC to abuse{at}contabo[dot]de)
Takedown time:1 day, 17 hours, 14 minutes Poor (down since 2020-09-16 07:16:36 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14Rep-2020_09_14-0676255.docdoc 8014f6ab3e277e6346b2e49fae79962948c0b264e7000be259601b0b715b3e15Virustotal results 25.42%Heodo
2020-09-14inf 2020_09_14 BFQ409823.docdoc d61eed6495d66ec5c0af991b418af8f8feaba83378a99261c374e11c7e64f98cn/aHeodo
2020-09-14doc 20200914 50360.docdoc d01054cbeb1b74004b1711e8cca1bb9c162c86117e09a0e4110ac90bd1848809Virustotal results 25.42%Heodo
2020-09-14List-855270.docdoc e50ebba147c9a5a494145d0e722bf188c43eae950ffb9067a80dd7a21aaf9fa9n/aHeodo
2020-09-14REP_ZLS545.docdoc 707c1063c30249706f5b47d56c8d6b057f13c1ba249b6fb0a9e86fced1ccc340n/aHeodo
2020-09-147135-20200914-0562.docdoc 3172b64121f2b22437fb59afa7124acec2dde11e932b900ab8b1e038be9f8f08n/aHeodo
2020-09-14list_2020_09_14_9652.docdoc 41a5219800a60a147e301cb5ee472f45de2130aa095d82a52fa81121b5881860Virustotal results 22.03%Heodo
2020-09-14Rep-2020_09_14.docdoc 63ab439cb5788c279996c35d7e41341081f97dadb4b255653cb11194a9368465Virustotal results 20.34%Heodo
2020-09-14file 2020_09_14 QWR29047.docdoc f463cf4d92f75e61f9c1a076fe61975011301f50d20a575e76b350fdaabf40c7n/aHeodo
2020-09-14Attachment_163612.docdoc 246d8db0406a7eefb66059e1c8e4d1c5ea419c31bc641f11ee15ecfda9f5eda9n/aHeodo
2020-09-14Rep 755.docdoc 30dd2df0674e842f8a3bfd8880f538175f2f42045d66060984f720b865acd353Virustotal results 20.34%Heodo
2020-09-144691553 20200914 24372.docdoc 383354c8056fb386a9af9f40c354846726ff04165ca01390075eeefad8c28faaVirustotal results 20.69%Heodo
2020-09-14Attachment-2020_09_14-0354057.docdoc 922d0848bdeb45de8993cf7663e729ccc87c4b6f7c93ece47472e9cd8cce416aVirustotal results 20.69%Heodo
2020-09-14REP_20200914.docdoc e42ab2c33e334aaa8d441b35ee6af4cfbf0b44d94e1a27383f436682592d0560Virustotal results 19.30%Heodo
2020-09-14ARC-20200914-5205.docdoc 0cf52559a9a78a8c8be555f2bee5c45e2366e7de21f1864cd8b9ea50e0afac76Virustotal results 21.15% Heodo
2020-09-14list_20200914_7491.docdoc c10c5243885706282a292c88ce519427d115edbc902b77dfa717be2204d55e9bn/aHeodo
2020-09-14inf_UN474889.docdoc 0b783948053f5f1dadd529527bbbea3e2ed5e25f1cfa250aca3b6620aac9c26cVirustotal results 17.24%Heodo
2020-09-14inf-2020_09_14-549.docdoc eedba6a1fec17811ed9e71674bca1376d7ae271b00bb6f4c3cff98b375b500a1n/aHeodo
2020-09-14Attachment_Y32213.docdoc f2532fbd7526347c12c5da9c6ba031fb982c33d496a1ea109c43c4dee64d9b41Virustotal results 18.33%Heodo