URLhaus Database

You are currently viewing the URLhaus database entry for http://wedeofficial.com/cgi-bin/Reporting/erEu9nkuQC0pltBu5z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:624759
URL: http://wedeofficial.com/cgi-bin/Reporting/erEu9nkuQC0pltBu5z/
URL Status:Offline
Host: wedeofficial.com
Date added:2020-09-29 19:52:38 UTC
Last online:2020-09-30 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 19:54:02 UTC to abuse{at}deneva[dot]co[dot]id)
Takedown time:4 hours, 40 minutes Good (down since 2020-09-30 00:34:20 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-3051099JP SJ886.docdoc b89e3c01c95337c6976cfdbc20163b4375eb1a0a76a87335e891fcd932c361d1Virustotal results 30.00%Heodo
2020-09-29Dat 2020_09_30 QJU723836.docdoc 98c87f2f2e124f5e8444896304f556a844430d6543223343abc894702abf99e3n/aHeodo
2020-09-2900127ZPM-IH886482.docdoc 44deee00b7451801d4a17c257ab6e48d119efdd78dcbed03daf5cfeb20a84b51Virustotal results 30.65%Heodo
2020-09-29Dat 20200930 1938.docdoc 349dd2ac63132716ea7360223fd038575e1b7144925c60d87589880fbd488670Virustotal results 29.03% Heodo
2020-09-29626063 10252.docdoc 08c3a51969b9ccfcd46ad14ef1a7599a798c21e693a582ac6d8f449f77f4fc09n/aHeodo
2020-09-29List-2020_09_30-V76469.docdoc eeb152640a9662420b865da4ac765f66469ebd7aa3568a51b62e286ce5806435Virustotal results 19.35%Heodo
2020-09-29doc-2020_09_30-9241.docdoc eece33d8fe3704d0c5ed8c9cbe5420d406c6e1fb12f835a35d64fb6507eb1b17n/aHeodo
2020-09-29Attachment_H3413.docdoc 733396f8631195450342e999f4b7d1e4134dae74cc2ec95438d0c2611e65a6e5n/aHeodo
2020-09-29Attachments.docdoc 81ab077a6be72ef3259c480e236c9480c05071f894380d3da428414a92c9c427n/a Heodo
2020-09-29EJ15788_20200929_962.docdoc 3ed38db3201fe400b1e0533ba551a1f631a550297afec1d65ce776dc9ed958e0Virustotal results 21.31%Heodo
2020-09-29WFX8200-2020_09_29-555.docdoc 546e960f2f85a196f5e12d60e0eedeeab059bf99f6e448a7b7f3bd6706b8166cn/a Heodo
2020-09-29Attachments-2020_09_29-3526.docdoc f7a5f4499460af59d26675a0a4e6e45c7422b7f830447a95d261fb2950001aafVirustotal results 19.35%Heodo
2020-09-29Inf-2020_09_29-924.docdoc 0495b89fed42b19dc6fd71b8f9a2dbea746f203b28ce8388a4069e86385b5207n/aHeodo