URLhaus Database

You are currently viewing the URLhaus database entry for http://happybirthdayarfeen.com/purging/DBjhlcnDMWo6vZmKjoPqo3V7Jun2GKdQvamnPcK6y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:939766
URL: http://happybirthdayarfeen.com/purging/DBjhlcnDMWo6vZmKjoPqo3V7Jun2GKdQvamnPcK6y/
URL Status:Offline
Host: happybirthdayarfeen.com
Date added:2020-12-22 22:33:04 UTC
Last online:2020-12-28 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003190636 created on 2020-12-22 22:34:06 UTC)
Takedown time:5 days, 17 hours, 0 minutes Bad (down since 2020-12-28 15:34:20 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-24C2LSG4WXESTHX.docdoc 768f3c029cc79ae21d7c732487da93f0e8c7d19a83737f9ce7e107e3adc9054cVirustotal results 43.55%Heodo
2020-12-23UBAPPM86PI7W2GY.docdoc 1b7862cdd7e11129f0b2efba625efa4a4298cc9610881f0e2ecfef4299a10afaVirustotal results 22.22%Heodo
2020-12-23C6HE6L7GN.docdoc 49b57af908f1e6a1383dd5b05ff24cc5208663b87a405e1e35828689f7c9cdd3n/aHeodo
2020-12-23SW2N871GVENP.docdoc a8a5d52ccfe6f7bcc1ef7c99087ec90083ea7e3851e760b0653bd4189d54bc9en/aHeodo
2020-12-23IWLKN3PBP.docdoc ebfadd85753d033e248aedd9f9c5772331aff8dc35049d0842e8c423d64ea08cVirustotal results 20.63%Heodo
2020-12-239O2FN3QIF8Q4.docdoc f0a4ee510f94aaef257225740c62c4a65b2da3ced23ca6b1513b9fbe11fd3cd8n/aHeodo
2020-12-230VLYSP3L3VT6.docdoc 60029fa95c17ba479a9ed424abc3a3f684111997424360741b67de478d0bcd4dVirustotal results 20.63%Heodo
2020-12-23YG1KHA5S.docdoc 3fbfd6e982d209b8a17b661954954d34ed049c93ae235bd736f558199b81aa94Virustotal results 41.27%Heodo
2020-12-23HI8B1602WR.docdoc a59e3318597fa65b37e597175045690d391ef038c7e58869d71ba50ab499cc64n/aHeodo
2020-12-23NTPSPWD2P68F8.docdoc 77476e25aa9034df5f54eb93a92ea7144c57945b92eed68b1956044666957d33n/aHeodo
2020-12-23B2LC79.docdoc 5a7b88efdd393de9fda81ff445cef38671de030ac35cba26f9b198481bfa29c7n/aHeodo
2020-12-23OLIXAB.docdoc e269c87f3edd655d2fa4f379bac4ddee2c652386ccd598daf260157b1b9c033cn/aHeodo
2020-12-23O2FGB2.docdoc 098fd9226fa629b47b6a137b89e9f3f85f74266c494382a6678d910af2cf8130n/aHeodo
2020-12-232Z3YRBR2Y4U04.docdoc 70cd2d38d41ecad15addac25c6e09641cce2f946161ecf261e639a09576ecb8bn/aHeodo
2020-12-23SCO7EQDBY.docdoc b534c439ac7a89c6af82331ebd70e5b5ce5e13a2e871bb7ab122b00004605e97n/aHeodo
2020-12-23U5ZM1CVCXGXE.docdoc fd76c945ff05629b1e31b55378f97c543c8dce7496389385dae3fd4b8acfd12dn/aHeodo
2020-12-2363OHGU4AC4.docdoc 68e9fac6a7996f04c150777aec9f02864a62b4c0d59675625c1801a231461a0bVirustotal results 25.40%Heodo
2020-12-23MBB5ZPEIJ4SA0O.docdoc 0351492c5d95a607178dc17826f59c46ee6ed33afaec7f54ad50d4e3935112cbVirustotal results 30.16%Heodo
2020-12-23CQ2MORUJ0.docdoc 810ffc95c449b426c6bfc03c98c5e10cfbecbfff7858f10cd9c1c5ec29e2216en/aHeodo
2020-12-23ZFN9CUTL0WC120V5.docdoc 4eba0fea9764ce2f90ad0ab87a752c374f7f33295336278b98cea9f8cf47255fVirustotal results 31.75%Heodo
2020-12-23I74MULSZHFVG.docdoc ef1b1013a1aee1aea1889ea4f3f736bac21dca5f8d940f13dbd2c332a8c8ac69n/aHeodo
2020-12-23FIQKEENVYIA32.docdoc 168fe6ffe9e78f01a7f784833ba9306ef1edad3ccea334df35937424ef0220bcn/aHeodo
2020-12-23W47GTVIGTR.docdoc ba96b09e7eeac72b4363f7b0749f36b0f3b68ecb4b3c40462d0f9d426b4cb483n/aHeodo
2020-12-23IAPWC9Q80W7.docdoc c29f20dc33cf2304271a54734dc3746f342898284264bd66094dee544fc133bdn/aHeodo
2020-12-23GCWRIW.docdoc 9c7952a624d186c2b830ab71d66e1e4369b998c0cfbf98bbc7530f5369530000Virustotal results 27.42%Heodo
2020-12-23AMJ8ZTG.docdoc 1a0263e1f86a9148e3b7434c12cc232b3a3c92df63c0aa48641c627e87949106Virustotal results 26.98%Heodo
2020-12-235V7HJC9KUQT.docdoc 47a492a3a0bfd3d8e0e6c5b72d0594fc8f387d657c457da34d5b7c097f8ab9deVirustotal results 26.98%Heodo
2020-12-23G907V1V.docdoc 9d2ad424f8d1a39e1cf83b8d64131bc94d8b8ecf787b626e1118e348fc967f10Virustotal results 25.40%Heodo
2020-12-23JEXU8KM1UF.docdoc 64e04bddf27b3d535ea895f4dc08267a98a4c401edadc68e3caf7f6f850c4f64Virustotal results 25.40%Heodo
2020-12-22ED5U1SE6PBBZ.docdoc 000b049debe1595e96d46d2cb910795e269d9d3f1b3210bfa45901356b3b3b3an/aHeodo
2020-12-2211397C8ZVVOP2.docdoc 54a40564f1605df3d177f233fb61ed59c38f1c8adea1284aab637fed81289a4dn/aHeodo
2020-12-22MMUGC5AH39.docdoc b88940065daeda56e1e49c0db60c1e275b39e435f83b785742242104d173a57aVirustotal results 22.22%Heodo
2020-12-22VORB9QPAT.docdoc 46935fc92d4e420a9f07c05550f0eb53c8ccff96b0f5fac35b1c8e716ed81ff5Virustotal results 22.95%Heodo
2020-12-22C3OGR3.docdoc bdfab9675a34c6da34487f2c70f297960002e6c3c2a8e6fdc60ae7edbe67101en/aHeodo