URLhaus Database

You are currently viewing the URLhaus database entry for http://www.mglgraphics.pt/wp-content/balance/egdfi8cxj1j/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:587693
URL: http://www.mglgraphics.pt/wp-content/balance/egdfi8cxj1j/
URL Status:Offline
Host: www.mglgraphics.pt
Date added:2020-09-21 16:56:34 UTC
Last online:2020-09-22 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 18:42:03 UTC to netops{at}singlehop[dot]com)
Takedown time:10 hours, 29 minutes Good (down since 2020-09-22 05:11:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22RO_YT4796874663VG.docdoc f129b606d5d067271568f8e80b03f9cf21754b288f67e302ffaba3aa3d679d3cn/aHeodo
2020-09-21O_LI3035789925ZI.docdoc 62f036b925c8b4c5c90b88eaf15e774481a952ac6e1c7596916e10054b82dacen/aHeodo
2020-09-21FILE_PO_09222020EX.docdoc 39de97c9d5604bd29ee471559a22ce1c35ad2157fb4d71802c96e7621cde7fe2Virustotal results 30.00% Heodo
2020-09-21L_DF0894330324XT.docdoc b0c1e64b3b04df99668587d56d89c513ced13de50d8596e1d49a2eac66c96049n/aHeodo
2020-09-21REP_05399876.docdoc a8f76389eb48147fbdfcf5e3037911b1d933d7e0a1da38d58125ee2b9084b561n/aHeodo
2020-09-21OI_73910848.docdoc 5f48ec62b70130e2ebbdf504c0de8057499f87bcf6bda3462f498f3d2e08c22bVirustotal results 28.33%Heodo
2020-09-21PO_09222020EX.docdoc 9e23f757e5e389aaaedeada32671c3f7a5620ec100069483a67b7305697a88c9Virustotal results 28.33%Heodo
2020-09-21A_1NC2SCD3HURE0.docdoc 92ee99cdff841cd67c677d847968d3a0eaed00d1fbb107b8da485b9a6ba4c608Virustotal results 27.59%Heodo
2020-09-2159753725.docdoc 2c13e193f719d9760c5efcdfc996df6b9ac513022ead472d1e901ea4c3aba62fn/a Heodo
2020-09-21REP_PO_09212020EX.docdoc e4bf7ba6d49953f6d305ed245b9ef7be426ea9b211bbd8aee04948809159fda8n/a Heodo
2020-09-21BAL_MY1691352900XP.docdoc f87c10d05f454254da53ad0717ce0f42871dd7293e1b24157355fc0544ac8926Virustotal results 24.56%Heodo