URLhaus Database

You are currently viewing the URLhaus database entry for http://prodreamweb.com.my/css/Scan/uWIc5KsJTcPOSzsJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:728003
URL: http://prodreamweb.com.my/css/Scan/uWIc5KsJTcPOSzsJ/
URL Status:Offline
Host: prodreamweb.com.my
Date added:2020-10-21 07:51:11 UTC
Last online:2020-10-30 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 07:52:10 UTC to abuse{at}shinjiru[dot]com[dot]my)
Takedown time:8 days, 20 hours, 42 minutes Bad (down since 2020-10-30 04:34:39 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21inf L0203.docdoc 8697e6d0c8627cfe2860549ddb1ae28ca48ab2da445d41bde0c40a99d5bb5fd9n/aHeodo
2020-10-21Arc_2020_10_21.docdoc d66507e04664bc245fc279c53f5be49bc10b2677f4a82db33eb921845d8000ban/aHeodo
2020-10-21Dat_20201021_35104.docdoc 881741565a39d73570fb7d87b93748e3cbbf48fdae4e6d4f005df02ea864d60fVirustotal results 29.03%Heodo
2020-10-21file_20201021_QT707.docdoc 6531b0ec21c07726a5ffd07358273a78cff9d8df4475f1bf34e27d1b8214dd63n/aHeodo
2020-10-21rep WP846966.docdoc 07bfe70b006fae4c1bdd4778f53370a428d8752e8e40fe8eb644ba21f3e1f542Virustotal results 29.03%Heodo
2020-10-21MES-2020_10_21-7242.docdoc 7b379e5dd60536e28d876fd99a019dbf070807482a1aa9e2f29ce9957914c93eVirustotal results 32.14%Heodo
2020-10-21ARC 2020_10_21 XTX63537.docdoc 594a6eef3e44943900de1819e7f249e6d8ed1d6764c6e49c7d78e945c1abf414n/aHeodo
2020-10-21FILE_20201021_RE7462.docdoc c92086217b63c4a5dfd561918668da011a1e09b8d04b1672ed82632dbd83c31an/aHeodo
2020-10-21Doc.docdoc 4d3bc1b77a1cef393383658706c061b23e13b90285e20612b2116243b1f07785n/aHeodo
2020-10-21arc-2020_10_21.docdoc 5345d6e5353bc1e7033c52b7dee86c2f0482a5f53bc23b6e3e29f03ba5f0b84bn/aHeodo
2020-10-21UNTITLED 2214.docdoc a495d84c58b2b130270804a0b6840b81578da34154f42c5223e3f34214daae0en/aHeodo
2020-10-21Arc_20201021_37456.docdoc 979c0685f093ea7bc14af8e86d49f06dcc4789b17b8fe8b318df26f5012b8f6cn/aHeodo
2020-10-21Arc_20201021.docdoc 00bc15a84388d64b7c6738b353ff98ea3fa7a31e15ffee14c215f289ee94b318Virustotal results 26.23%Heodo