URLhaus Database

You are currently viewing the URLhaus database entry for http://mpgpro.ru/wp-content/eTrac/eFq2z1psSHA1ei2jf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698673
URL: http://mpgpro.ru/wp-content/eTrac/eFq2z1psSHA1ei2jf/
URL Status:Offline
Host: mpgpro.ru
Date added:2020-10-15 22:06:04 UTC
Last online:2020-10-16 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 22:08:04 UTC to abuse{at}reg[dot]ru)
Takedown time:8 hours, 22 minutes Good (down since 2020-10-16 06:30:28 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16ARC 20201016.docdoc 1bce0620f3ce7ad399b5bce897242f60a98af20118452134bca8d7729a9799c6n/aHeodo
2020-10-16arc-20201016-731306.docdoc e52f2635e68a8f40c8e47ed31a932dbd89ca5e423bc8565b71df778c2c7c2eb7Virustotal results 51.61%Heodo
2020-10-16Mes 20201016 ID0128.docdoc ad29fba32bbfa20e1769369f3a121ce461433fc55e719db4c522855e858262a1n/aHeodo
2020-10-16File-20201016.docdoc a6091d359b405ea83e58000e282b0bd40824c64d36b4546077d786ff19124be1n/aHeodo
2020-10-16Untitled-20201016-23904.docdoc a47762c209b57d46904972127a1289ee6b304fad012783b113472df47b76d81fn/aHeodo
2020-10-16list_2020_10_16_D61632.docdoc 8d55bfa88aac7102ed41f043d7266e85bfd3e83d0d8f7d298876419eb1bde683n/aHeodo
2020-10-16inf_2020_10_16_Y909.docdoc 33e9aa06794873710331ae9974a1df6d3d1529d39553dbd6a504a1181b05bbe1Virustotal results 46.77%Heodo
2020-10-16arc_Y350620.docdoc d779a23df9f672a173e5db73dec484b9b58435f3cc4db430e5b5a97c6021fff3Virustotal results 46.77%Heodo
2020-10-16rep-20201016-B05183.docdoc aabb9ea2a83771f9921f5d074e4cf99314607d95cb6f4b069f4ffbca8b18a8f8n/aHeodo
2020-10-16ARC 2020_10_16 9129.docdoc 878bb13d04d93f1209ba23990aef838329f86ff7fbd86d5bc6bd24da81dbf0f7n/aHeodo
2020-10-16List_9575699.docdoc c7cf5a3d5d7fa1c15561e9ae23236bca356132e283a8651ce8f9257bdf79f77eVirustotal results 42.62%Heodo
2020-10-1605272856_E309.docdoc eab5eed41969a9071221c46da6c2e5cbad82ce39b400964b2a4cc2c05d5617efVirustotal results 41.94%Heodo
2020-10-16MES 16159.docdoc 77336efe637e5b6480a97a6764e16c75424a6c44345993fbc87a04fdb1a4437dVirustotal results 42.62%Heodo
2020-10-16INF_20201016.docdoc 38a5fb11e6266a457f515df1b8c3ba51c2dfafb32164cec12057a63a473daad6Virustotal results 41.94%Heodo
2020-10-15Untitled_2020_10_16_EF58658.docdoc b060160af00ceb90812eb219ac8e72258f487365866f64374c5786171cd6c947n/aHeodo
2020-10-15Attachments_2020_10_16_TP179.docdoc 4be03f6e2d9d995b0c327a02bb5c0dd41b90691a3da98e256f2defb4695ef311Virustotal results 42.62%Heodo
2020-10-15Arc FW727.docdoc e9bb85a4542b6d954e0643d3a11e297ddd82611c26f5b20de5e92bbc0ca77418Virustotal results 38.71%Heodo
2020-10-15Dat-OUZ93546.docdoc 47ce9bcd74cf07f1e9312e71da59c363eb8c6b91f592da4c37aada97a38318bfVirustotal results 38.71% Heodo
2020-10-15doc 20201016 21758.docdoc 5cd96c13db27678a592b3f51d44ba42985b5dd571a8c393baddead43dc655f54Virustotal results 37.70%Heodo