URLhaus Database

You are currently viewing the URLhaus database entry for http://uniteddatabase.net/wp-admin/Reporting/E8CzEni2M0kuyUH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:545241
URL: http://uniteddatabase.net/wp-admin/Reporting/E8CzEni2M0kuyUH/
URL Status:Offline
Host: uniteddatabase.net
Date added:2020-09-17 13:01:14 UTC
Last online:2020-09-17 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 13:02:02 UTC to abuse{at}quadranet[dot]com)
Takedown time:1 hour, 49 minutes Good (down since 2020-09-17 14:51:10 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17339162-20200917-O01378.docdoc f553c15ed918b0e4b4f782f1462862fb8d60a344e8fd5a5225066950f98afe8cn/aHeodo
2020-09-17ARC_20200917_RDE865905.docdoc f910334358562b3ff08ee76ddb3e496df83bbc1c9c33c3c5f7d549c2e7d73ea9Virustotal results 30.51%Heodo
2020-09-17REP-2020_09_17-FCC20024.docdoc cc96320d4b261455f9e38490eaeaa1f04d7eaf3c322dc6771225ad50a0f4a29en/aHeodo
2020-09-17file-FTA7313.docdoc 05ce719d6bbe09bf2fd00e9ce8c5d8a14c173ba82dd5a361d3a34c95586fe45dn/aHeodo
2020-09-17Rep 2020_09_17 4668915.docdoc 96eeeb31a1f499dfd36fd8dd65250c5639ec0b33444d5b47b2c37f95a2914336n/aHeodo