URLhaus Database

You are currently viewing the URLhaus database entry for https://suhu.site/wp-admin/s4mfy7P7JqkCV8jGwEfR8IybeIMlqs6U6im7MvhfsQjp5ep3DYcQGvwDkFMY5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:945195
URL: https://suhu.site/wp-admin/s4mfy7P7JqkCV8jGwEfR8IybeIMlqs6U6im7MvhfsQjp5ep3DYcQGvwDkFMY5/
URL Status:Offline
Host: suhu.site
Date added:2020-12-30 02:48:07 UTC
Last online:2021-02-04 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-30 02:50:04 UTC to noc{at}apik[dot]co[dot]id)
Takedown time:1 month, 6 days, 19 hours, 15 minutes Bad (down since 2021-02-04 22:05:24 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-31ISWNNQ83JO.docdoc 43af38ecd27585f00463abfee0ca7f492fb36fa862c8d215447d59be27652589Virustotal results 50.00%Heodo
2020-12-31UYKVRGK.docdoc 12e7ab9e39a4de6501f16fd9e897cca63076a1760d5a6d030ab577db61cc82b1Virustotal results 49.21%Heodo
2020-12-31AXVDNPXB6.docdoc f13634d2bd3bc1469174a0cb871c0d10bcd89c1431232838e1251c25ce568a0aVirustotal results 48.33%Heodo
2020-12-301GE372CG.docdoc 6ea37605aea5591d5271248f640a3dbeb9edec2ae1fcef4954213d025a812d4eVirustotal results 22.58%Heodo
2020-12-30GWMJOWWXAPKTF2Z.docdoc f075b561422f41b4412421cd0aa5bbcb988f960c4c632de46179b64e8467601cn/aHeodo
2020-12-30ZIM0UU3.docdoc b82b450a954e7a9f387e756a4f192f137aca695016f21f9ef99b1117ac7dd808n/aHeodo
2020-12-3005W63AMLG7.docdoc 4a5d601a84c5c5244615e1f860e6d52fed614858dfbd0215b97b32414ca56f43n/aHeodo
2020-12-30CFFTOP.docdoc b5f5bab1debd9fd60535f3a992c4f90f462f3c42896c05138b18e67c36d111edn/aHeodo
2020-12-30NEUOMPSZMLCU6.docdoc a586bd9284e08911b3ba6a021732d976be512698b16238e9ada5a5d08b477fban/aHeodo
2020-12-305BGH149M62B6E.docdoc add8349cc360e174c38c2d36277412b334744b3af808d91097b5b9e9c9834f3fVirustotal results 49.21%Heodo
2020-12-30OARWD42ZTTHTCDA.docdoc fe615d9510f8a8a4f2392eb1dbaf75fee4054136fc2da4a69d52c6e1b8c696c9n/aHeodo
2020-12-30ZKSJCZBVQAOW.docdoc b418b8729a429df3b5029222db61b762411c34971aa6c76b3fed3d12146a984dVirustotal results 50.79%Heodo