URLhaus Database

You are currently viewing the URLhaus database entry for http://odeftg.com/odeftg.com/sites/i1m335x2789107218367vcvjzgfux010k24b/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:596166
URL: http://odeftg.com/odeftg.com/sites/i1m335x2789107218367vcvjzgfux010k24b/
URL Status:Offline
Host: odeftg.com
Date added:2020-09-22 11:52:05 UTC
Last online:2020-09-25 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 11:54:05 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:3 days, 8 hours, 46 minutes Bad (down since 2020-09-25 20:40:19 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24BAL_RWU_090120_TPH_092420.docdoc eded433f531513b960d540a5a009de4bf991d6ef3a525317bc5c1ee9f10c1192Virustotal results 20.97%Heodo
2020-09-24INV_VPO_090120_WVO_092420.docdoc e5b9b4889b3cad8f0920a0d4153cab5517ce077683139476f36bc1bf91652725Virustotal results 21.31%Heodo
2020-09-24FILE_PO_09242020EX.docdoc 84d837274cbcc7fea7d1806754185fecba6c90d352208ed2c444996864073135Virustotal results 22.58%Heodo
2020-09-24LVMY_5055130357.docdoc 860994a6cb882e801a963f6e00a8bca34f28efaa71b690e5f77b8c2e644dafb6Virustotal results 21.31%Heodo
2020-09-24FILE_010103501186622468.docdoc 54d6881837b3fcb6a0b3e639c58f6e159abb745d0862e1f5cabe6c7df3a3da12n/aHeodo
2020-09-24REP_PO_09242020EX.docdoc e2dffd7e2a3663a738dac21fd590dec2cce14df9ccf7aebcc5944258a827bc04n/aHeodo
2020-09-23Q_PO_09242020EX.docdoc 7340c303b5ff42ef74e8996ab95aa2b6b742e4efcc852b96349ea6085e592f37Virustotal results 29.03%Heodo
2020-09-237JYU3OU4AUCH5K0S.docdoc 76435bca763f869f80daabd795435e20bd52e2cff25a5594ccc20c8be946a2e8Virustotal results 37.10%Heodo
2020-09-23BAL_TL1PJAG1Y2G.docdoc f62ef7f415a25bbe326cecb39a15134327c963de9253795427a71974f8845b6fVirustotal results 34.43%Heodo
2020-09-23OJK_PO_09242020EX.docdoc c9de56d138a927505138fdf267dafe6d598cdd4338db121b7d7b5f9a982a3a49Virustotal results 41.94%Heodo
2020-09-23J_ZL6571057172OB.docdoc ce373513080505fd4e582d2b84d8a670e7c84c18db398f74ddce4490adb67517Virustotal results 35.48%Heodo
2020-09-23BAL_86253096.docdoc 8baf1240f6b87a1faeefc1474c846750b7bcf2feb0aaeeef6ccc53420596b41eVirustotal results 33.87%Heodo
2020-09-23REP_25804812.docdoc 5d5e964840d2d7f401bae3568724b259b02c4485c211ccc7ec23c0273d11edd1Virustotal results 35.48% Heodo
2020-09-23FILE_35401643186372882.docdoc 46cfb218b8b268ef4372057514f93c2282c6eeb1474b574f5f8a3c291cb6269eVirustotal results 34.43%Heodo
2020-09-23INV_24029294.docdoc c987b077ae0b47cf29fddf96a9339df37f08fc068fc536cd8728d5e75c827ecaVirustotal results 33.87%Heodo
2020-09-23FILE_ZKV8711WV7IAGN.docdoc 5d0b46e5ac5ae916c339102eb13396bf43d1c7c757bc63c6ddad859b8ba97f05n/aHeodo
2020-09-23PO_09232020EX.docdoc 26614fe04700998a42fbb7c3d84cbce63bd4a32aa9de3efe130ee1366827c094Virustotal results 34.43%Heodo
2020-09-23DOC_86537185431419747.docdoc b09074b0d262c73c66430e4e968ebee0cb946881c69d7b7fd8bc9130a1731482n/aHeodo
2020-09-23REP_9383613450709.docdoc b1d1c08b520e22fcababa993c5280c6d4ee437f6b8d975b210780fe78530e581Virustotal results 35.48%Heodo
2020-09-23E_PO_09232020EX.docdoc a877dd61b25805e938555868388a8543768fb01e9c45ae6072c261f61264d466Virustotal results 34.43%Heodo
2020-09-23II9162201098JP.docdoc 936e0b3b696a31047618a5ffe005e0500e2dd472581d4df1580db803e19cca8aVirustotal results 35.48%Heodo
2020-09-23EEB_090120_JLI_092320.docdoc 6eefa0014179d081dc54eac6a974dde6c888d89c9cf4a70614edab3682525d6bVirustotal results 35.48%Heodo
2020-09-23DOC_19462565.docdoc 128899ba979bf0b5b07a74f82789e723583f279e2163a0e6b6cfb5de09c0f0d1Virustotal results 35.48%Heodo
2020-09-23INV_16141563.docdoc e446be795bac5464b1bb80859e2ffd0857fe8d26f1f6973457b491498010f0c1Virustotal results 26.67%Heodo
2020-09-23INV_52022250.docdoc dab27520c5577f059d11bd78d22f8d5cf492cdc0150781ba9b28b5fbacc5c185Virustotal results 27.42%Heodo
2020-09-23INV_PO_09232020EX.docdoc 1c64de03ffee1b612358e9f45424fa90efb35ee3f384839c5d48f8932bdb23a9Virustotal results 31.15%Heodo
2020-09-22BAL_DL7359340874LN.docdoc 0bf81a6e813d1474fb8f3bc1b2071f479aa978b3e536a2c960d60226fd1ebaaeVirustotal results 30.65%Heodo
2020-09-22Z_7554968126731574374.docdoc 8b086b781acec12715982f30c39eb5d20950325e39a5d84b33a6df96d9edcf8cVirustotal results 31.15%Heodo
2020-09-2226906944.docdoc af31068680a432b4d1d2164488f6353795fbb745479373bbafc6a60e9cf25169Virustotal results 30.65%Heodo
2020-09-22M_70K5QK3OC.docdoc 0c850e85bc3e92d0551863e1ce5cd03c3c3404ceeb7e38aed586706c4134f4a2Virustotal results 29.03%Heodo
2020-09-22INV_Z4UXDI2.docdoc b171914b2e5a10fd997e51268f01a70b254f0aa55080906c36c6159bd325c9fen/aHeodo
2020-09-22INV_20399091.docdoc 23bc63af094f80c54cfecb85f86f0b2f1975ae55f29d9d66ea61d6612c36a567Virustotal results 27.87%Heodo
2020-09-22T_72624880680308302896.docdoc e543adff7cba9ec05fc7d78a55b89e22cea00ca50df6e67e06250420b9f2ec48n/aHeodo
2020-09-22INV_EB9699663323IQ.docdoc be8eff5238b1b4c55eaf6bf5399d71b18bc093dbf2344c41e86f192173e1a5efVirustotal results 27.42%Heodo
2020-09-22BAL_M7DDOIIZ.docdoc c6e601d3f1268441a2518c331465ffd7acd22aae6e1526662ffcac834946f259Virustotal results 27.42%Heodo
2020-09-22Z33R5I5.docdoc b9230204a6b5bb648c78437d34a9350a40aa179243813ecef19402cd1f319b96n/aHeodo
2020-09-22REP_MDY_090120_VKD_092220.docdoc 98f1a8a99449cb92a1d946e110ba5decc069079ddd01fe5ded4bc075313f3bd6Virustotal results 27.87%Heodo
2020-09-2282528704.docdoc 526a3a875236eb66c2fa9894594c30025d794c8ecbe0dde1fd873dedfab79497Virustotal results 21.74%Heodo
2020-09-22BAL_XN7279578100MY.docdoc fa7f4b3fa89ce1e3cf1f45674f36346e729aced2de513c5a058f935c65b3cffcVirustotal results 28.33%Heodo
2020-09-22LCAQ_CFB_090120_VKO_092220.docdoc c288a47cc4303a39755120a6450d469a858b7bb662f27fddf022bb2fad4553efn/aHeodo
2020-09-22Y_KYO_090120_YXR_092220.docdoc 02503f6546f32015f98eb839efb8b3d86d56b8ab5de5a30b5d6e99b4bd41802dVirustotal results 32.26%Heodo
2020-09-22INV_65415711.docdoc 87f58543c86151e96b31f59d447ae70c1bc19c0eaec22d93d1291679cae0ea67Virustotal results 32.20%Heodo
2020-09-22DTG_E4AIHGZDP.docdoc 2bf3d0be0ec0aaaf33db1bbe5cd306e4f922dc550013d001e834f25ad4897e2cVirustotal results 28.33%Heodo
2020-09-22S_YOKGL1VLG.docdoc 930940e5133c0fce0276ae473de2d29fcb04655dfe1604df2e4499dd27e81eb9Virustotal results 25.00%Heodo
2020-09-22PO_09222020EX.docdoc a9eaf02d745472a4b410b1baef20b073bce933c2e1c7a99fb183e33a47a2e622Virustotal results 23.33%Heodo
2020-09-22BPXDIEQ.docdoc 50938c1e8bcfd60435f294949bf3b07533f8b5ccf1cf92d08a77f4a222037092Virustotal results 46.77%Heodo
2020-09-22REP_LBREVHMFO98H.docdoc f8268201b25212a26e7e88ac111369a98dc7773599dec9742198ad00e0bbd2fcVirustotal results 23.73%Heodo
2020-09-22DOC_PO_09222020EX.docdoc ae6b87ac0454384d2f1770703311136edbffed03236d3d126f8523fefbd9b378Virustotal results 24.59%Heodo
2020-09-22U3K4REIR2EVOW.docdoc a714039155100cefcde16b35ce58326190b758e5cb309369d07650f56ea89a13Virustotal results 23.33%Heodo
2020-09-2259805183.docdoc deb600ac1ac3e5230085da737631928e9460610812ddec5ab166f830acd7a411n/aHeodo
2020-09-2251169205553819.docdoc c644ecae09d26a7e2d91c741f78016ac572f541901955f91642e77b55cdd4f74Virustotal results 33.33%Heodo
2020-09-22HC5861936357XT.docdoc 05404c17be10900ee0d7234c36b3ef17ea901447793a0b3ef2548d3784cc1f30Virustotal results 37.10%Heodo
2020-09-22ZJ_HYC_090120_KDQ_092220.docdoc 2dc0808180195ca8f163cfeea23029ac8604e3b2346a77198554dec0dee2ac4cVirustotal results 30.00%Heodo
2020-09-22LA_FZ2748289797ET.docdoc 0490f225c70972f96003689bd80f008021b6a7fe6e0973bed7e7caa00b972edbVirustotal results 24.14%Heodo
2020-09-22INV_29223957.docdoc 013f49af6f7f5e1e34116aa22e1bc2ba4babbb2c0b0f97bf4da287ce88b16a16Virustotal results 50.85%Heodo