URLhaus Database

You are currently viewing the URLhaus database entry for https://frajamomadrid.com/wp-content/INC/bzxmot0s/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:734674
URL: https://frajamomadrid.com/wp-content/INC/bzxmot0s/
URL Status:Offline
Host: frajamomadrid.com
Date added:2020-10-22 12:58:05 UTC
Last online:2020-10-25 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 13:00:05 UTC to abuse{at}ovh[dot]net)
Takedown time:3 days, 7 hours, 52 minutes Bad (down since 2020-10-25 20:52:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22BAL_SRH_100120_VFZ_102220.docdoc 4cbf400ac380f9f7eacf85fc40e4445447d878ad4023e251f16769b44ff39a46Virustotal results 39.62%Heodo
2020-10-22PMO_100120_FTG_102220.docdoc 001639b7cc59c0a2584aa6a318a5f5b65adab079e516f81c1053efbd1feac7ccn/aHeodo
2020-10-22BAL_MXV_100120_NYZ_102220.docdoc 9c025489858b7549f67ca1cfe82ab121254e8ab5c19ac7ee160108297862e9bdn/aHeodo
2020-10-22U_ONX_100120_FUQ_102220.docdoc 0dcf5051405a8df1087b5cf36dc02c73c8625397dd38bbee394b11858055e85bVirustotal results 38.89%Heodo
2020-10-22PO_10222020EX.docdoc 0b9036fd0fb6b0170883b15323d34e278388c2ee3e9639f5341c44b7cc9f3403Virustotal results 38.89%Heodo
2020-10-22H_LU5621940033OP.docdoc 95b893f910c8291bc7f9bfdc79062c9dadcc155dca9459d12504fef14167aaf3Virustotal results 37.50%Heodo
2020-10-22XC1581H0W7ZBE13I.docdoc b56dbb47b8ccce583801528377d4979222c7ccdcc3bcab559a7fa6469fe02008Virustotal results 38.98%Heodo
2020-10-22REP_MAI_100120_JDG_102220.docdoc 5071f2da34845b41b8e65266293f6756c12aef537eaa3777eeb4f6333f6191d5Virustotal results 36.54%Heodo
2020-10-22REP_V22CN00E8Y42.docdoc 577c203950be63bd35f6a6eea0fceb7ba785d7b2b6d8e3c702fd6d3f59adb81aVirustotal results 56.45%Heodo
2020-10-22REP_60316437.docdoc 4d021161076f99a75dfb666d3e39d11b00bd70327c45d3d5b013c27c361dd74bn/aHeodo
2020-10-22PO_10222020EX.docdoc 98a7403f2284947cdcc0c179ba703329edb0e717b26a20be473a2c606a8abab6n/aHeodo
2020-10-22M_ZTI93GSMPTEAFKYJ.docdoc 1a6ddadc772f06b99c0286b4d3d96639582499d811601fa4b402619a7ffa4c80Virustotal results 50.00%Heodo
2020-10-22E3N8WWZ5.docdoc 2c353218e1a20d8e435f57ae45682506c746562bae6f4761e2398d7caf09791bVirustotal results 49.18%Heodo
2020-10-22FILE_00276429512842.docdoc 8fff54beb4262f2a56b898c4004613c1f1fd9933cdcd99c0f45ea1eafb125b48Virustotal results 48.39%Heodo
2020-10-22H_DR1013195064LW.docdoc ae5168eab14a38621615d44a35ff6af0052fabf8af421ef2c66f783169b808e8Virustotal results 46.77%Heodo
2020-10-22INV_PO_10222020EX.docdoc 7eaf0df9dd2a33ee958384a9472366f58f1c0a204360efea6a7f8b0d298560d0Virustotal results 45.00%Heodo