URLhaus Database

You are currently viewing the URLhaus database entry for http://udbhaw.com/wp-includes/payment/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:702223
URL: http://udbhaw.com/wp-includes/payment/
URL Status:Offline
Host: udbhaw.com
Date added:2020-10-16 14:15:05 UTC
Last online:2020-10-19 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-10-16 14:16:04 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:3 days, 5 hours, 10 minutes Bad (down since 2020-10-19 19:26:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17TNHK_09236191279501556279.docdoc 360a5cb7eed923017b4ef07460e7652362cdf1fc0a902516addbb8e244e30134Virustotal results 54.10%Heodo
2020-10-17DOC_JU1YZN9MPYM6H.docdoc 83af4eee8013969fd28932937f24ed1bb6031013a525dcd161ed6914b41feba5Virustotal results 47.73%Heodo
2020-10-16REP_JG4R4ODXJCRXO2.docdoc 70c3e11a1960c379e6be0215b70999623bb37cad12e932cf4d222f70f078c6d2Virustotal results 50.00%Heodo
2020-10-16OVCH_ZMK_100120_TPT_101720.docdoc bf79372e0c3a2b7a3b0df0f3994621206443404f5c382b8ad5e5c609c6b0e043Virustotal results 50.00%Heodo
2020-10-16BAL_BWDTIGALRB.docdoc 80605d4761a1447fe034eb12aa555f3c47129991eb479b0d4da31493633ee464Virustotal results 49.18%Heodo
2020-10-16INV_49XI1IY9.docdoc ba3ac6b60b4acb6aa9b534e4cdbab1c537fdb07b6fcd10d5e16f076fac5fbf1dn/aHeodo
2020-10-16REP_77338773961741688764007.docdoc 9051dea430fb5eea96e34f2c938f3eaa2e672eeb73fa5d8ee44680ec0b906f26Virustotal results 46.77%Heodo
2020-10-16INV_RG0529277813LQ.docdoc 511700e616e51e0cbe96e874e76cef55302bd3c56cb5ebafc49d04e2a817ab27Virustotal results 46.77%Heodo
2020-10-16INV_OF2491318486GW.docdoc 66e5c84f7f729e36ef0aa28a083377587825de39b6871269f4c8f6cc72899a1fVirustotal results 43.55%Heodo
2020-10-1682940180.docdoc f516029eb5a63ec663aa57bcf41d0ba93e98574976381c581b952aa1631de8dcVirustotal results 46.77%Heodo
2020-10-16QO_PO_10162020EX.docdoc 334cbaeae02aab74b5bcf567ec6fb87be96ca6deead23214dcfb4fc36598b5f7Virustotal results 43.55%Heodo
2020-10-1620569519903897695362.docdoc ffa06f345711cab1bbf64ad42a6ab9b9264655ec20d39fd3ab37d4e950c98b8aVirustotal results 46.77%Heodo
2020-10-16BAL_15CXEAC63.docdoc 9d28dd58c8ee62277f91e152a8c7e9964052f5025f10424ec75b9563e6b50cf2Virustotal results 46.77%Heodo
2020-10-16REP_PO_10162020EX.docdoc b8031f04cccc6be26a29ea7f8ce5296fcad48e7a2aa335b460b4c62015004cbeVirustotal results 40.32%Heodo
2020-10-16INV_13687784.docdoc 682f6bf35f7cc1f36fb26805da313fa9c07b6b397f6e72c400d1f8ad51e01been/aHeodo
2020-10-16PO_10162020EX.docdoc 4bead4acd3e94b0d94cb2d3be3f50f5d9b5dd425a0d5d5caf6af43b13539d717Virustotal results 47.54%Heodo
2020-10-16REP_HD8750467966SQ.docdoc ef0e715e1da6a1717d119a57d6ec4f961a3a700f9a807b1072fae419151807d8Virustotal results 43.55%Heodo
2020-10-16INV_8SPJI1YE.docdoc 0e12f49796d6d8f40e96ccabd14b42ccbd1c2097b8e8419790c0d793c3226bd1Virustotal results 45.90%Heodo
2020-10-16INV_70697616.docdoc 2c1c8cab0d411952c802de9667aca0d5ce72024da289e07685554f1a17ef5e73Virustotal results 35.48%Heodo
2020-10-1671688147881020786194.docdoc b285a4eb97b84d68240929ecbe902577a607c7e7b0abe299ef3ff2a6fa3e9eb7Virustotal results 33.87%Heodo
2020-10-1605098080.docdoc 66ad2d1939fed89f992a25cbdd0aa594a8c4e2065358f7142dc648ea2f5d8317Virustotal results 41.94%Heodo