URLhaus Database

You are currently viewing the URLhaus database entry for https://datalycs.ml/plainfield-m1/Pages/q5q94WtrKG1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:723084
URL: https://datalycs.ml/plainfield-m1/Pages/q5q94WtrKG1/
URL Status:Offline
Host: datalycs.ml
Date added:2020-10-20 11:05:05 UTC
Last online:2020-10-20 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 11:06:34 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:8 hours, 17 minutes Good (down since 2020-10-20 19:24:19 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20dat D15626.docdoc 0b00749d78b513081990655af401c2601f50fce225b7148879646c3c8d68c35cn/aHeodo
2020-10-20Doc_20201020_11054.docdoc df65ee2a7d5267831782113a83d3d5928360f99572f7d9ba2f2c6f3affe5707dn/aHeodo
2020-10-20Attachments-20201020-969.docdoc 66b2823c1c92be5e6a57845608811e8adeb4494b456aaad4a6c280aae34a6359n/aHeodo
2020-10-20Attachment-20201020-1363061.docdoc ef6f58d61cb76b5886a5f0c9b7fc91d07c6da5130abdb537020db8b348b4df1an/aHeodo
2020-10-204168425-20201020-IJ717583.docdoc 980f165923cab75e3f3a70e4f55669d7e72f99af0f8ee789a4ce91e746cc0faan/aHeodo
2020-10-20rep_1790.docdoc 68bd8ec45a679c9c45f700ac2ea653efeb32f2a321a443b6e804fcfc0ec69065n/aHeodo
2020-10-20Arc_20201020_EG873870.docdoc e61bbba014ba814fe2a9468b7bdd4836be933cfcfb7a076f6ea33d4e7c713fc1Virustotal results 30.00%Heodo
2020-10-20Rep_2020_10_20_O457.docdoc dc3b45f1416ab3f1c9bf6ab1700e98205047906775831c6fc72cf4cde3dbb6ebn/aHeodo
2020-10-20file-2020_10_20-688249.docdoc 838f9fd0c536a3d5f2cb4031a2e784cfe408a2aec8876be02f874e96438a3625n/aHeodo
2020-10-20list-3169.docdoc 123723b516e6fc91c1cdf19558205f1768cf8d773e7d13023e179c8cc6e6cf08Virustotal results 32.26%Heodo
2020-10-20ARC-XG604.docdoc 3b68b1d64aa626e000ac7440865669e7d4a1d301a10d07f54e4af75edc5aa8d8n/aHeodo
2020-10-20ARC-20201020-SMB1140.docdoc 932cc29a17e8257b56982aa2894be64e95b279928a4dad094994202e6aa32cb7Virustotal results 35.85%Heodo
2020-10-20Attachment 20201020 108.docdoc 419d5780d07436769c78422c22db0f351a8517f058dbfbc6320fc2c6f337abfen/aHeodo
2020-10-20FILE-95627.docdoc 1b352b6666e927f78ff2dcd4f53c554e2af3697ded24857b7b98bc8cd25b6ffbn/aHeodo
2020-10-20R846.docdoc d98f26da9dd79c4a39085174946c13d4d0d1655bed138a2273ba0b92eca640cen/aHeodo
2020-10-20dat_77288.docdoc 253a23db09dd9cf26085981b5fbbb900a9c07a2a4880ee60cdb4233356f78c6an/aHeodo
2020-10-20Arc-JPA766.docdoc 1a265459c27acae7080d7baec40e76eb713df7c2c289400b49b72cf9d4ccef8aVirustotal results 32.26%Heodo