URLhaus Database

You are currently viewing the URLhaus database entry for https://support.affordableblinds.com/wp-admin/VKzdk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:764564
URL: https://support.affordableblinds.com/wp-admin/VKzdk/
URL Status:Offline
Host: support.affordableblinds.com
Date added:2020-10-29 09:40:05 UTC
Last online:2020-10-29 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 09:42:04 UTC to abuse{at}liquidweb[dot]com)
Takedown time:5 hours, 50 minutes Good (down since 2020-10-29 15:32:51 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29MES_PO_10292020EX.docdoc 134e4b929d0e83768f3bad032abd87bd8d004dd2a7256fb9ff9d4bfa9f29e5fbVirustotal results 28.12%Heodo
2020-10-29DOC_HH0574702710GS.docdoc 5ed767510e9b2630ac3c6ea38470821c0c85acaf712cb5f45eddd5f6e0fcdc17n/aHeodo
2020-10-29File_3UPTJ8TZ1.docdoc dd1f36356c3a35bd4fa5c58dbc9798b01714e04d123539649c3932a8164288b8Virustotal results 26.98%Heodo
2020-10-29E_PO_10292020EX.docdoc 5db58ed4308eeb76f9c66c885d4f1b53530d6c42eac9d755e67bf41989094087n/a Heodo
2020-10-29M_RL8250867991TA.docdoc e134359bfa4a04bffabf20a6522d2a4c8d807619578853ba0387aa395b6495c9n/aHeodo
2020-10-29rep_22941031.docdoc 54f04e269a7b08a1ec3d9a71e00dfa86b9d8050533ef0d550298ea51f28775ffn/aHeodo
2020-10-29Untitled_EPA_100120_FIH_102920.docdoc 12c570f649005ea1ae77c36167843e3e87252075b68b652c5f05b0d8e54b2ad0Virustotal results 20.31%Heodo
2020-10-29FILE_07423841.docdoc af8373a05bb4ac069cb45da6f676db803e252cb4c3e378c3fe25375323c74db8n/aHeodo
2020-10-29rep_PO_10292020EX.docdoc 854dd0441e71fcb4f3237e94d7a738e26a8f320c3e5becd6b94aedcf7237eb09n/aHeodo
2020-10-29file_MTJ_100120_VKR_102920.docdoc 3a1dd7ec119b96ea68facb223082a398ff4c038e58e7d166c80d7a7d4a3758abVirustotal results 20.97%Heodo
2020-10-29FILE_RWT_100120_MCZ_102920.docdoc e774f5958547ef05060879d507586d22ab8e651bccd1b45eef5770a2a2e404e9n/aHeodo
2020-10-29List_59038017.docdoc 4105e48c905f55328aa0a89a608c302216a2d4b119573ef85d1e9902d0531119n/aHeodo
2020-10-29Dat_PO_10292020EX.docdoc 5a00d4a9d8e50c06f30007460af1dc4f73950dff8ef4d1966ec4098c16712bf0Virustotal results 42.86%Heodo
2020-10-29Y_64406843321254.docdoc b9e189f0cb3064ede89dc2167eca309a64edc4ae42aeda9b8fab875c4906b5dbn/aHeodo