URLhaus Database

You are currently viewing the URLhaus database entry for https://t-dagger.com.pk/wp-content/plugins/akismet/DOC/wjFqyqsyXeM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:696103
URL: https://t-dagger.com.pk/wp-content/plugins/akismet/DOC/wjFqyqsyXeM/
URL Status:Offline
Host: t-dagger.com.pk
Date added:2020-10-15 05:15:06 UTC
Last online:2020-10-15 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 05:16:03 UTC to abuse{at}nayatel[dot]com)
Takedown time:2 hours, 12 minutes Good (down since 2020-10-15 07:28:23 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15Mes-522883.docdoc ff4cc20a94f3da13f940c0a284ad40954258b28ce2834c1e0cd03856ed8aad05n/aHeodo
2020-10-15UNTITLED-20201015-P6745.docdoc 38678660d5824f80d24ab6bf6e7b508c541afc8e8fd5ad57c0f94209cdf50161Virustotal results 28.33%Heodo
2020-10-15Dat.docdoc a99e5fef8c2c166acf8dba082f4cf5354ea32e0b06c34f8934c6dd577c11e619n/aHeodo
2020-10-15D0775 2020_10_15 P21887.docdoc f2a7610878aa6155ddeff814e5d349b61f26524765f59945194de7cf72594e25n/aHeodo
2020-10-15Mes_7954836.docdoc 72e8e736fa3a59434029878c15ccb716e521fe24b7b2ce2a0164e563953f0e1an/aHeodo