URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ticketshd.com/wp-content/FUfYNLqU2DDO4ts6A3L9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:944669
URL: http://www.ticketshd.com/wp-content/FUfYNLqU2DDO4ts6A3L9/
URL Status:Offline
Host: www.ticketshd.com
Date added:2020-12-29 15:44:05 UTC
Last online:2020-12-29 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-29 15:44:12 UTC to abuse{at}vps[dot]ua)
Takedown time:1 hour, 28 minutes Good (down since 2020-12-29 17:12:12 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-299UIGYCBZMT0FACO7.docdoc b537a61b49cb5e779aae45b4d93395adc4124f38cde9997187e31c92d146d8bbVirustotal results 42.62%Heodo
2020-12-2955IXDPRF8G7D8W.docdoc 6a493e8b5ff18bfa985491dff440f85ab81458e502477a4163d174b2f068d2a0Virustotal results 39.68%Heodo
2020-12-29BHKHD3U65B3R.docdoc 87fde4723bbbdcde8c933fca20f34a74b2d6ca37d6c015a228e5e33c86ce7eddn/aHeodo
2020-12-29DIIK0UJ8HFFV24.docdoc 9f6e30efb9df731c394c6258f97818c93d88efbca7acd4f2290bc784cfafd057Virustotal results 39.68%Heodo
2020-12-2943274FCVTOI.docdoc e0a6211f261f1dad74877fe1f03bb64bb2db249de6e13b9ea140b05da66395deVirustotal results 39.68%Heodo
2020-12-29D3GSBGJQPIO.docdoc 605ea5154e06e5f2f924f710ca1d11860d6a1d580c332e987d868bb932f74d69n/aHeodo