URLhaus Database

You are currently viewing the URLhaus database entry for https://villamark.net/wbkszp/https:/DOC/4rM4T48HdGs4AXhOktP/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:498610
URL: https://villamark.net/wbkszp/https:/DOC/4rM4T48HdGs4AXhOktP/
URL Status:Offline
Host: villamark.net
Date added:2020-09-14 15:33:08 UTC
Last online:2020-09-16 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 15:34:18 UTC to abuse{at}contabo[dot]de)
Takedown time:1 day, 15 hours, 36 minutes Poor (down since 2020-09-16 07:11:05 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14Rep-2020_09_14-0676255.docdoc 8014f6ab3e277e6346b2e49fae79962948c0b264e7000be259601b0b715b3e15Virustotal results 25.42%Heodo
2020-09-14992_2020_09_14_272647.docdoc 5171e0e602e27c4122239e9c7833c603beebb69bea148c5d29341990af469f55Virustotal results 25.86%Heodo
2020-09-14doc 20200914 50360.docdoc d01054cbeb1b74004b1711e8cca1bb9c162c86117e09a0e4110ac90bd1848809Virustotal results 25.42%Heodo
2020-09-14ST15447-2020_09_14.docdoc 9071af554116b7e5e92cbd63922f2d577d1fd912ed4fd121ab0762aa8b2dd589Virustotal results 24.56%Heodo
2020-09-14REP_ZLS545.docdoc 707c1063c30249706f5b47d56c8d6b057f13c1ba249b6fb0a9e86fced1ccc340Virustotal results 24.14%Heodo
2020-09-147135-20200914-0562.docdoc 3172b64121f2b22437fb59afa7124acec2dde11e932b900ab8b1e038be9f8f08n/aHeodo
2020-09-14list_2020_09_14_9652.docdoc 41a5219800a60a147e301cb5ee472f45de2130aa095d82a52fa81121b5881860Virustotal results 20.69%Heodo
2020-09-14inf_20200914_793655.docdoc 2f46a6507c4618f36225ba5ac1cdbe970be8c8842f309bb8ae5bfe88eef8e805Virustotal results 20.34%Heodo
2020-09-14Attachment_163612.docdoc 246d8db0406a7eefb66059e1c8e4d1c5ea419c31bc641f11ee15ecfda9f5eda9n/aHeodo
2020-09-14Rep 755.docdoc 30dd2df0674e842f8a3bfd8880f538175f2f42045d66060984f720b865acd353Virustotal results 20.34%Heodo
2020-09-14UNTITLED 2020_09_14.docdoc 9a0f46198571734b8b93f9254c1224df12e007530e2fbab39c49520f534e2a96n/aHeodo
2020-09-14UNTITLED 20200914 992.docdoc ed2623cbc3ddc280a2d77c1be9f87c90240c7ea5c9a4e9c6dcfa66b3194d1e1cVirustotal results 20.34%Heodo
2020-09-14mes-20200914-CP16440.docdoc a76e5f0c9067cd2cd19e85c30f44b763df4d42a5fd1c12cd4fe75cd8835de43bVirustotal results 20.69%Heodo