URLhaus Database

You are currently viewing the URLhaus database entry for http://terrain.com.my/wp-admin/statement/CoDuFYh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761093
URL: http://terrain.com.my/wp-admin/statement/CoDuFYh/
URL Status:Offline
Host: terrain.com.my
Date added:2020-10-28 13:37:10 UTC
Last online:2020-11-16 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 13:38:02 UTC to abuse{at}shinjiru[dot]com[dot]my)
Takedown time:19 days, 8 hours, 43 minutes Bad (down since 2020-11-16 22:21:31 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-05P-100120 QSDD-102920.docdoc ccdb2c5ed40ad6227647ac04e1d3d1cb499a0d67ae9dc428c3ef6b275f786a8cVirustotal results 23.81% Heodo
2020-10-28Inv_4263.docdoc 5177894154a2ad0d67c6ea62534a27cdc18b7cfe9c73c8ec6071d72fb8c198a2Virustotal results 22.58% Heodo
2020-10-28Y00547 invoicing.docdoc 77373248ec2c394eb9cfd85b94e561cdd8ed66646be0298961d65b24a97305e5Virustotal results 22.22% Heodo
2020-10-28MD-100120 QOBB-102820.docdoc ba3c399c241634f2921ab5d9573e69dd0695eac55c17bedb283e7df2b9de3f8fVirustotal results 20.63% Heodo
2020-10-28October invoice.docdoc e69175f1d0fc57715610220f59992ae3a56ac12d27917162e4626cd0ef2bfc30Virustotal results 19.05% Heodo
2020-10-28invoice #40309.docdoc 370a1b3953c1d27da53e168e6823424b68b8c5cb85ef92fc2e758f360b283b0cVirustotal results 17.46% Heodo
2020-10-28invoice #32636.docdoc d1f0145ea0d4e036edd208387b5c7c012b0eec91562b6f210853152462b2ff63Virustotal results 16.39% Heodo
2020-10-28Invoice.docdoc fadcbe7aa3d7b823b03d2627cf8a05b229e0f6c7518a71b9c4a106155b04df3cVirustotal results 17.46% Heodo
2020-10-28H00750 invoicing.docdoc 7e7bd61af07906f31a4efa5442f7cfda98c0047ef70e15f64e37c5d4882917b2Virustotal results 17.46%Heodo
2020-10-28Electronic form.docdoc 448eabf56cc654711f7a3a6005be397a5aeda5ba6f329742da01cf7d31712931Virustotal results 17.46% Heodo
2020-10-28invoice #7778.docdoc 3732182a2ad2854b3f9ae9a1eeaaec7d53eb43bbc485318ae0a2f573a0159b0cVirustotal results 16.39% Heodo
2020-10-28October invoice.docdoc b9bb095da1e8ad66589f36b496ee1e2e924f04f73374e3b76f630fbf6c9f573en/a Heodo
2020-10-28Invoice 4790902.docdoc 2d02f7d64430a41c50eaaed46dce33dcc544dc0d4904fd4561e8ebd851447952Virustotal results 18.03% Heodo
2020-10-28form.docdoc b00550f671513ffe17557a492f220d6aca912058514c8d39a3d4abe9fe52895bVirustotal results 17.46% Heodo
2020-10-28October invoice.docdoc 1803944ee4f9bc9077c04710e033b33e5ce91263d2b9f5409f742caee5f45fceVirustotal results 16.39% Heodo
2020-10-28Electronic form.docdoc 81a28a01618707472c50609e10b45b9e7900ae5e34a761d053954fb7581c4677Virustotal results 18.03% Heodo
2020-10-28October invoice.docdoc 19aaa433ecca6fd07745038e78b223ac4492123a79f15b2e209298466f35cbe8n/a Heodo
2020-10-28invoices 4994 & 6765.docdoc 56e06f27b7f8905f084ac7ddc933236bdf650363aee629d7dd7e1c831aa9ca7eVirustotal results 17.74% Heodo
2020-10-28Electronic form.docdoc 8d1b0623db4f3599679e4e49851df6cc812d8838f4b4428e1884fbbc8b5d44ceVirustotal results 20.63% Heodo
2020-10-28form.docdoc 7b55e5dcf03999a440acbe690dddf943d03bd37fbfc7892d196708992044efdfVirustotal results 18.03% Heodo
2020-10-285847012339.docdoc a15065cc7906ff0f92eab6e94d12157947b02e7b25586b84a8ed21aa4852e7b0Virustotal results 16.39% Heodo
2020-10-28W3532301102NY.docdoc e1a1c8b02de20858f2703c835ecd985f2b744816cd4f8757ca7e12af15d3af11Virustotal results 16.13% Heodo
2020-10-28invoice #86514.docdoc d4d88bb7b289fc8fe85835f356c30440662efd3f2a033d4b99bda2f234647243Virustotal results 17.46% Heodo