URLhaus Database

You are currently viewing the URLhaus database entry for http://hoofdynamics.com/beretta-m9-eumks/iYFDr7N2zyqWx690ykE3h6KykQDvmM46VlGmewMobbGMfEV0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:940953
URL: http://hoofdynamics.com/beretta-m9-eumks/iYFDr7N2zyqWx690ykE3h6KykQDvmM46VlGmewMobbGMfEV0/
URL Status:Offline
Host: hoofdynamics.com
Date added:2020-12-23 11:57:04 UTC
Last online:2021-01-05 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-23 11:58:02 UTC to abuse{at}alchemy[dot]net,dnsadmin{at}alchemy[dot]net,support{at}vitalix[dot]net)
Takedown time:12 days, 18 hours, 42 minutes Bad (down since 2021-01-05 06:40:36 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23X5ZL880H.docdoc 768f3c029cc79ae21d7c732487da93f0e8c7d19a83737f9ce7e107e3adc9054cVirustotal results 43.55%Heodo
2020-12-23Q1AR2RE5HJMWR.docdoc bce89cd09be85ac647d834fb41cec14c3f695ddd559477288bd3853accb78258Virustotal results 42.86%Heodo
2020-12-23HYVWPFU0NQ1LM6.docdoc c8d4a144217b712971ade5a673650773aaa202a9836fdd8c3ae73ba08bd5398en/aHeodo
2020-12-2349QS5V225T7YX.docdoc 6ed5539e92f43fcde23dc6343c4f41a93050576180fad637adc5014a49ed38aan/aHeodo
2020-12-23DIR87WOOS9U.docdoc eb7cf5978cb5fad16c2d882814f893891ca689483719bebe706f3f3a5a87d33dn/aHeodo
2020-12-23IVTFJN5PL6DSSVQ.docdoc 54ed122348f1eb4575e53cf51a436566a3a19e35d0120a52eb54ef53895f855en/aHeodo
2020-12-23ONE6XYOAP69.docdoc 460e772fe33a8f6054329997f77e044e08d85f72b2cb3c8d122096c879176eb4n/aHeodo
2020-12-23YJC01FV.docdoc 883f2d94856edd7ee7d9ddefb4cb9c49b0300ad23fad3aa88f3c020d166b771en/aHeodo
2020-12-237US2JZ2C2TBJ.docdoc 70cc44f855631b3a9358c0b5f202406738d8b5c6a21133f6ae2d775aaa3a8ecfn/aHeodo
2020-12-230IK5XDAJ6J4.docdoc 94d804683ab1c9195ece193461e872d75b4835c2ee0fc73886dcca02a89463edn/aHeodo
2020-12-23RYHELDE9S9FGQFZ.docdoc 8aac323bb90b4aa43f663e31e58a2973cf36b32fc5acfeec8d40fca09a50a7b5n/aHeodo
2020-12-23665W0B.docdoc 08907511869c01824c3fa593161c3d71a507c9a403faefdb197811e3adaa4f8dn/aHeodo
2020-12-23IU0VN4D.docdoc 649918360167560700dc33d77632806bcc52576e640559297ce216691ea5dfd1Virustotal results 27.12%Heodo
2020-12-23MIUZUTDJAEVW.docdoc 63725aa4926dac422d6710c815b80ad10e66b882656195a75ef13b9816cf7c53n/aHeodo
2020-12-235ZEA9B9.docdoc 093e325f8e17124f9f181fc838f22a865b3b150c5cde9e1254345ebd6fb189dbn/aHeodo
2020-12-23XWJFM4DY3KKTQM61.docdoc 0149c806df64185dc66ee1fdc857e25ee93def1f7db847487674959d2b9306d1n/aHeodo
2020-12-23UODC9XMCDS9.docdoc a28b7c24587230e5ac5533afb0324572f1d1341d264eccba2aaf6b2a34e5ce81n/aHeodo