URLhaus Database

You are currently viewing the URLhaus database entry for https://www.themoviebazar.com/wp-content/public/Fcn2lp9O2PU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752642
URL: https://www.themoviebazar.com/wp-content/public/Fcn2lp9O2PU/
URL Status:Offline
Host: www.themoviebazar.com
Date added:2020-10-26 17:21:06 UTC
Last online:2020-10-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 17:22:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 59 minutes Good (down since 2020-10-26 20:21:29 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2636644QBN-2020_10_26-P877693.docdoc 677737fcf18e303ef12992e548f6232d1b01e6d2597dd2e96205b41b8a4944f4n/a Heodo
2020-10-26ARC_20201026_NT3764.docdoc 170a9758c76a32bd4e24cee76623adf33c333d7d26762d04cc35e5f358ebbae5n/aHeodo
2020-10-26doc_2020_10_26_5629883.docdoc 5369fae3eee921b1fd6ea820a171f8f50eaef5e7d347d0ea9085495f429e08d5n/aHeodo
2020-10-26RQJ77538_2020_10_26_047904.docdoc 6d252fc3ba68da45fad2284e5547eb0fe7029784ee30376bfaf260b04ae48775Virustotal results 34.43% Heodo
2020-10-2623718586-20201026-K3060.docdoc 3b55dfa7a1df5a559786cab3c6b18c92c2425ca31ff2b0fa10a5441e724751a0Virustotal results 35.19%Heodo
2020-10-26dat 3873.docdoc 6cffcd0e36c9599da564a917fc81648334bd014dc1e0eefd9328399d2bdba6ddn/a Heodo
2020-10-26List_2020_10_26.docdoc 459b1860e1450f3fa8d1c7378ac31152aed86cc3710dac9e1b9ab6a24c29a5can/a Heodo
2020-10-26DAT-2020_10_26.docdoc acd703f0a8149ca48dffc7b4fec1276ff6782fad7f5d99ec43de8a954e92a83en/aHeodo