URLhaus Database

You are currently viewing the URLhaus database entry for https://oedb.tk/wp-content/lm/kYOrrsjm6pzO1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:751119
URL: https://oedb.tk/wp-content/lm/kYOrrsjm6pzO1/
URL Status:Offline
Host: oedb.tk
Date added:2020-10-26 10:28:05 UTC
Last online:2020-10-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 10:30:08 UTC to abuse{at}upcloud[dot]com)
Takedown time:2 days, 21 hours, 31 minutes Poor (down since 2020-10-29 08:01:51 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26REP 20201026.docdoc 5997e3c32bcc3a6e5f160f819589680d30b890f4fe2faef068e92c7deeb02685Virustotal results 33.96%Heodo
2020-10-26arc-2020_10_26-K593414.docdoc c4840ad377c3998eae6bcb0ef239f283ecbbb3c896e8004fd674d10234a00189Virustotal results 31.75%Heodo
2020-10-26Arc_S5774.docdoc d1abcf7be3ad51873e8f18e2f2d07487da68b9450943ee963efc561fd680fc3dn/aHeodo
2020-10-26Untitled_7024563.docdoc 27cfb56065bfa97353a5055efa2c90006603cf05afc44450549a6ec705c9fb16n/aHeodo
2020-10-265007L_2020_10_26_2807.docdoc 4c42cdb38e4b83de81d9ae2f8e709dfb3eb681761bc551eeab0b6338bb249882Virustotal results 28.57%Heodo
2020-10-26Doc 58781.docdoc 81c551477e20018dc6980134d9c3e9f964fd1c50ff65ac4e0ed7e6471aa058e7Virustotal results 29.03%Heodo
2020-10-26rep-20201026-UMK3578.docdoc 7440dda8e555e9035377fc29f2d9172549267ddd4e94229023c0109b5d2d9e2eVirustotal results 32.69%Heodo
2020-10-26mes_20201026_416.docdoc 448ac203510436aa6fb70c37c6bf2d4ed7569e681d6d3f27512fde7a1fd0990cVirustotal results 28.57%Heodo
2020-10-26Rep_20201026_G688610.docdoc 8fa6b4ff0a164073304538a362010521446ed8adc11963e56a59640c1e957e6en/aHeodo
2020-10-26015535-2020_10_26-1468129.docdoc a947fcb77a0c612b58f08de1d48958d952fd256f382018867b5a61b5ddcf5631Virustotal results 28.57%Heodo
2020-10-26arc_2020_10_26_Q0583.docdoc a95d76e7de33604c21ca0ae2b22b2515d5f809b3431a70116bab4040d8a58fcbn/aHeodo
2020-10-26Attachment_20201026_O62265.docdoc d6f7bdb1b5ff4287a1bb5679161b98f7941f0091197b37d04fba163501754706n/aHeodo
2020-10-26list-ZR63457.docdoc 7568f48fe0645ea9cdd165c0432da115295430c4e8064301c518360ad8153dben/aHeodo
2020-10-2664762W-20201026-ZVL49296.docdoc 001c7f2cf9518d78d50711633e4f0cb168bbc4ab2c923ead7c41febf6e3fdfadVirustotal results 27.42%Heodo