URLhaus Database

You are currently viewing the URLhaus database entry for http://danaplat.com/wp-admin/lm/eefUQ2k86er6BBYQ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:609971
URL: http://danaplat.com/wp-admin/lm/eefUQ2k86er6BBYQ/
URL Status:Offline
Host: danaplat.com
Date added:2020-09-24 12:36:13 UTC
Last online:2020-09-27 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 12:38:08 UTC to report{at}parspack[dot]com)
Takedown time:2 days, 18 hours, 18 minutes Poor (down since 2020-09-27 06:56:18 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-26ARC-PT40481.docdoc 4893d5828613a7b157505151182a80ad894439fe4f65ebeb87fcf641880ca47aVirustotal results 51.92%Heodo
2020-09-25MES 20200925 0766414.docdoc fe890849b50a3266c007ef8b917afc54bed8de8c8630f33cea2fb0d9d6bbccaen/aHeodo
2020-09-24LIST_20200924_PE47689.docdoc 48dcbfc04efdbf5c4e3c2ab520e718e34fbdaf95d38ffbdf469d4e40e850cf5dVirustotal results 22.58%Heodo
2020-09-24LIST-2020_09_24-WR3443.docdoc 6ca4c4bc99110bba835cc64055378d05d0ac578abdbfb73fd3b4bfd9958123b2Virustotal results 33.90%Heodo
2020-09-24dat-20200924.docdoc a173c80617eccbb5abd724c6c42da5355329ffc94e544185e1401d97c9146964Virustotal results 33.33%Heodo
2020-09-24Untitled_NB767.docdoc 8523ee64ad62d31567483e0e181de018dd58cff185667cb0564e0ace8f22eaa1Virustotal results 30.65%Heodo