URLhaus Database

You are currently viewing the URLhaus database entry for http://webmail.exgic.com/wp-admin/nd63in1hpo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:620409
URL: http://webmail.exgic.com/wp-admin/nd63in1hpo/
URL Status:Offline
Host: webmail.exgic.com
Date added:2020-09-29 03:10:12 UTC
Last online:2020-09-29 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 03:12:09 UTC to abuse{at}o2switch[dot]fr)
Takedown time:3 hours, 55 minutes Good (down since 2020-09-29 07:08:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29BAL_RB0517204912FR.docdoc b2e71daf0ebe60a19e0b62852d7198b9e94b1d5cc89227fed97ae2054e7e3d71n/aHeodo
2020-09-2992675740.docdoc 3d523f3d16239cdef719f2c6af5fa889c6ca70eb5efffc4c6382bd7ce77a7fa4Virustotal results 45.16%Heodo
2020-09-29INV_PO_09292020EX.docdoc 1c97235809cb8431eccb5413864eb8a08ec66dd0fc8d9a12cd8d8da9f8c9d40cn/aHeodo
2020-09-29PO_09292020EX.docdoc 8a631648269bad9635fcbab2e0111e4c50ffbbeffc7e2bf060d96a688062584fn/aHeodo
2020-09-29O1T0QRLYTRRU15O1.docdoc 1087155bc18fbbc2413d2ce4a37be877bff2d9d95202b3f9a9c5ba3a9c986e74n/aHeodo
2020-09-29AQD_090120_PPX_092920.docdoc 1f05ac51daee57a330e0b2e270a5455a23d6866da5392138b1403ac63e5b4793n/aHeodo
2020-09-29BAL_PO_09292020EX.docdoc 445961272dceef4776f9072dfcd5cc77442cb0cf111a6534219b4ddae904b052n/aHeodo
2020-09-29DOC_75748751.docdoc 9a3ffd4fcad019552ffa26b03d83f19a618ead38af864086924cbbc36623c0c2Virustotal results 41.94%Heodo
2020-09-29LGS_090120_IJJ_092920.docdoc 4b7fd3aa52853241aaa5c8d95e005ace57390afc9406bdf9da287bd7c6ccd123n/aHeodo
2020-09-29DOC_PO_09292020EX.docdoc 665a83304be8126632283c77fd184c5093b67885447b2ff3832e60ca7131675bVirustotal results 41.94%Heodo
2020-09-29FILE_PO_09292020EX.docdoc 0ff9018efbdc9cbf210116c70e1ac562faf91e20ccac146b25aca93b54061cd6Virustotal results 43.55%Heodo
2020-09-291103552075947337.docdoc e5d1b3e601628703582a921fef151b6f35ed2776cd4a18887cefac671899cee6n/aHeodo