URLhaus Database

You are currently viewing the URLhaus database entry for http://simplefb.com/wp-includes/dfwq5wtss/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725911
URL: http://simplefb.com/wp-includes/dfwq5wtss/
URL Status:Offline
Host: simplefb.com
Date added:2020-10-20 22:45:05 UTC
Last online:2020-10-23 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003024729 created on 2020-10-20 22:46:06 UTC)
Takedown time:2 days, 12 hours, 44 minutes Poor (down since 2020-10-23 11:30:22 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21INV_VK0421972312SN.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 41.51%Heodo
2020-10-2182233850.docdoc b730b36a22a6d6da4bf394e59e3bdb0a0bc32a3adc8fea6f568a58b926a7fdc4n/aHeodo
2020-10-21REP_OOH_100120_SQE_102120.docdoc b96b5470dc7d8ed5cab5f58b9064e6c57382d8dbe135093a8ce692e5b4171266Virustotal results 41.07%Heodo
2020-10-2101616740.docdoc d22a87ba3c7e99020912f1d934019c267482e1fed55cd64d79f4e1147fa4609eVirustotal results 40.32%Heodo
2020-10-21INV_GH3593262293BK.docdoc 633b2b1963bd2dd467845e87a2d06ace1c22e9402d4dd3aee12618af8f0846a8Virustotal results 39.62%Heodo
2020-10-21FILE_IUC_100120_RSH_102120.docdoc ee8ef9beac4202e018577996e293215dd2cc1e260bca0ac0a38f9abcdcd4fa2dVirustotal results 33.96%Heodo
2020-10-21BAL_PO_10212020EX.docdoc 1cb0001d422c0b16aa106ca96ff8aa0db8fec461c49b8f80ac75b5ab4001803cVirustotal results 33.96%Heodo
2020-10-21VF1852085538LI.docdoc 99d7234dc759302b6b38de85547762ca5a46358e93508509b534755c9af8c309Virustotal results 30.19%Heodo
2020-10-21BAL_WAP_100120_QOL_102120.docdoc c0308a4a6567ed36df7165b3cffbe26f676322783de09900dd7b7e6b7d642b97Virustotal results 30.19%Heodo
2020-10-21LNXR_M5F0VMP.docdoc 25c71c161f7a916496cd76d407fc6a0863e2f36fa50e8b2cb886b5ca7b853dfan/aHeodo
2020-10-21H_SYSVDIO4XXU2.docdoc 65afacffdde9c2202e28125192dbfc1094522200913e53bd6d003b6a1754f3f7Virustotal results 20.97%Heodo
2020-10-21BAL_PO_10212020EX.docdoc fddd48d21efdc1d86734b611c1183bfe17b584b835bdb85655c3f9b17cf3e8afn/aHeodo
2020-10-21BAL_PO_10212020EX.docdoc abd94a7b58ada746b22d9d6a4ef2b3847deda4d5569325459951c0c7f3b2a355Virustotal results 33.96%Heodo
2020-10-21M_QWQ_100120_XYI_102120.docdoc 52caf1a070aa97f41dee32688e691efd22f50efe87a8f77d4a36a28281c19136Virustotal results 30.00%Heodo
2020-10-21FILE_681769085504290.docdoc 0ef3eb571df8fcaa4ad2f23f3daabf1bcbc17ee41a42913f623eaaf788f5e04cVirustotal results 30.65%Heodo
2020-10-21140717555715304697649.docdoc cb14f9efbce55984f2bdf345ced2928c530ab4b909c54aa15f7c8efee7490bb6Virustotal results 27.87%Heodo
2020-10-21DOC_TG4001892091HV.docdoc b97f1b7383623d24cfb725d25a28d8878a36f857a4f4e06cb475b1ce3538d343n/aHeodo
2020-10-21INV_1178090952294508.docdoc d2116981397601f48095f1a584c948e2e623ab4f0c5b2f393479cb20d67bfa90Virustotal results 26.67%Heodo
2020-10-21C_4OQPYHUST.docdoc 88c45b613e6367cbb58e012779f1cd95ff6a44efc175b2163185aa309e18573fn/aHeodo
2020-10-21DOC_PM5QOFE0.docdoc a3b816362471dd5502a7f46f5dc0bdab4ecfff681f06c9aab0d9e227ec535faen/aHeodo
2020-10-21ICO_100120_FDN_102120.docdoc d09a3b2020a8fe4602378a86d4e37891b134569113ac01d5fb358f9538b5449an/aHeodo
2020-10-21REP_21884867.docdoc 345865d30681e3e80a301984ee82920018dba62cbbade4673c33cc2a0aa9555fn/aHeodo
2020-10-21A_WHS_100120_XJW_102120.docdoc d3eb1ac711c92a7ffd2516e93813ce184cf849bf5cc7890aadab90c20f450c17Virustotal results 50.00%Heodo
2020-10-2170376934.docdoc 0e7f06cdfc74e74e5e00123ac97222a4735cc7b8cb29ca8d7892df978f647a32n/aHeodo
2020-10-21LFKU_ED0910554585JC.docdoc 44ba6008506a7673feb84fe893ea958153dae8b82def146db7f497d3537bfbceVirustotal results 48.33%Heodo
2020-10-21DPZ_100120_HLU_102120.docdoc 5b78a4ef32efd6eba54e53df8b14092631d475f672d60774c26f20dbe0ed5f7fn/aHeodo
2020-10-21INV_MYG_100120_BEP_102120.docdoc 850a811a1e29aafadeaca369778609e35c77edcb8588f69f153e44195d40d6b5n/aHeodo
2020-10-21C_B9VED5GI.docdoc f6ca28aa0ec1ee28ce246d787de062e5b78554ec2cfc62fbf00db085c177b074Virustotal results 40.74%Heodo
2020-10-21S_PX1471874689RP.docdoc 1996ba49c1e42e54c8cd2717756d00e05f3290d1be0d606dc11a3ae0f556ffc9Virustotal results 41.94%Heodo
2020-10-21BAL_LNK_100120_QXN_102120.docdoc 4d674a6143e1a896967213d335f2d95bdcee16aa83b718071ad004c674e458c5n/aHeodo
2020-10-2167081311.docdoc 5f21cb8fe8e76f9363dee1df0517de6b04e70c797c10a473a7acdd92048b1260n/aHeodo
2020-10-2143488430.docdoc fe1e5c66a4990cc515e5925db68def9f29f1893d9c6d3fa6b47e05f5c5f618ddVirustotal results 46.55%Heodo
2020-10-21DZ7163680399ZE.docdoc cd230affe2cef8dd5938e3ea670dbd706c65f93341c35d2eaecf1a5ae6d8203aVirustotal results 48.28%Heodo
2020-10-21BAL_42324184.docdoc d0337f9e3f826764678ff11fd7e2b49a84db21bd33615cd0cc63e6654c502d9an/aHeodo
2020-10-21SLR_100120_FTC_102120.docdoc a977513362ad46e1cab8cdf98638a7e3edcd11796c732a818660e18e49b74a5an/aHeodo
2020-10-2184724480522780983532.docdoc d6053ab1f8a8801a71b22ecf5257f4cdfee7138eb99345ad33ff208e175aac0fVirustotal results 42.59%Heodo
2020-10-21BAL_41634967.docdoc 84feca377993d253e4d214e7c044ddd45eb3ef0f47796ef2970e9a5bd1f2f535Virustotal results 43.40%Heodo
2020-10-21BAL_435396982989929838.docdoc 8db61b871aac2949105b26c1ca2a22579e3b3d6e99aab20279c3bbea5dc87b8bn/aHeodo
2020-10-21RTIL_PO_10212020EX.docdoc 89e10dbffeb48b429f49468630b9b93f988c4ca3e6a7de17367b398447309bfen/aHeodo
2020-10-21PO_10212020EX.docdoc 7b59e4314d2b1bbefd045815d54be5bd19315bcd13e3de6816a36bfd0930e032Virustotal results 39.62%Heodo
2020-10-21QRV_100120_XXC_102120.docdoc e3b58bc04eecbb1fb55ace8390236594852afd2f07faf2b8bb7c84dec2fb1da1Virustotal results 38.89%Heodo
2020-10-21E_DR5150103149PC.docdoc cd0c0ee5979ebfa7ed73a40ee1f879f2b65cc57ed38619fc4f7e186c15e54128Virustotal results 38.89% Heodo
2020-10-20PO_10212020EX.docdoc 583a7bdb6f07cd4359433a437ffcb7f9dbe1ed88b0a51acfe8ebd88294c940d4n/aHeodo
2020-10-20U_JQ1413363785QP.docdoc 8cadf5fc31643a1acc9b991d110e039e7e0520e94783c61d9caf5ccb2481915eVirustotal results 44.64%Heodo