URLhaus Database

You are currently viewing the URLhaus database entry for https://behindthegreatmusic.com/wp-includes/CYN9bLYWIunTkcb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:750788
URL: https://behindthegreatmusic.com/wp-includes/CYN9bLYWIunTkcb/
URL Status:Offline
Host: behindthegreatmusic.com
Date added:2020-10-26 08:58:04 UTC
Last online:2020-10-26 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 09:00:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 33 minutes Good (down since 2020-10-26 10:33:38 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26FILE_4FT4J04.docdoc 178f6ff7eb53fdce854b485b8b0d1fac6ffea4e1bb931301c3efc8f01467618an/aHeodo
2020-10-26BAL_MD6779201394XF.docdoc e139a1307108cd17902b7c2592379f58217ddc569827c0311bb830b6fafdcc1fn/aHeodo
2020-10-26REP_PTP1PUNW7H.docdoc fdd2e0b860f62b7889c287679dceda8f0512bec5cf2ee91ce5aedfb029ba88can/aHeodo
2020-10-26REP_BB0808674259NW.docdoc 09b2a72a86ea5f8f9bae4b8eb0d638fee1159f9cddbd4820f96fb18db851a357n/a Heodo
2020-10-26VII_100120_MPM_102620.docdoc c9e86111047b13ec258a40d825fc81dca6dce95b5302d0cc2f3d19cff6238cd9n/a Heodo
2020-10-26BAL_JGK_100120_MFH_102620.docdoc 75026fcad5aba81f52ddca27a93b3c23b1310623907bcd70fabbdd3f5dc3e16cn/a Heodo