URLhaus Database

You are currently viewing the URLhaus database entry for http://diamondmodels.net/wp-admin/DOC/sw0C5itYiIQ39y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:735064
URL: http://diamondmodels.net/wp-admin/DOC/sw0C5itYiIQ39y/
URL Status:Offline
Host: diamondmodels.net
Date added:2020-10-22 14:39:05 UTC
Last online:2020-10-22 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 14:40:05 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 54 minutes Good (down since 2020-10-22 17:34:58 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Attachments-140660.docdoc 5f899d6ba79a78bc6e85428be8ba9150ce5bdad6dc475b35c61156ff8f21550dVirustotal results 36.36%Heodo
2020-10-2286357483-2020_10_22-TP465.docdoc 1897a70790c07d00de31ac18813c0c1c5f3344f9251634f3e8152603cdf6d13dVirustotal results 37.74%Heodo
2020-10-22Inf 20201022 BU753.docdoc 4de9fec585fa6040afe3d65e7285cc67c82cac4e61a964432d11ba94343301ddn/aHeodo
2020-10-22Rep_20201022_Z28764.docdoc 33d8282536536c651d28cb08401045d2a01d13e2606369788ecf8ffe2136a4b6n/a Heodo
2020-10-22INF.docdoc c3843a536f778e2e2d8bc6af3e608c492db004886b7a0cdcc32fe491ab6b43e1n/aHeodo
2020-10-22INF-4736.docdoc 5a03f653f2f8fde3d3c0b8332d25b332c8a0f25eeb2808547f9b9869611ef8bdn/a Heodo
2020-10-22Attachment 2020_10_22 P7997.docdoc b4ecb85b9a72552a80be2d95e54b442f55c46aa6252ba065e1cdf10bad5f06aan/aHeodo