URLhaus Database

You are currently viewing the URLhaus database entry for http://suhu.site/wp-admin/s4mfy7P7JqkCV8jGwEfR8IybeIMlqs6U6im7MvhfsQjp5ep3DYcQGvwDkFMY5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:945299
URL: http://suhu.site/wp-admin/s4mfy7P7JqkCV8jGwEfR8IybeIMlqs6U6im7MvhfsQjp5ep3DYcQGvwDkFMY5/
URL Status:Offline
Host: suhu.site
Date added:2020-12-30 06:27:03 UTC
Last online:2021-02-04 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-30 07:24:02 UTC to noc{at}apik[dot]co[dot]id)
Takedown time:1 month, 6 days, 14 hours, 26 minutes Bad (down since 2021-02-04 21:51:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-028BHYE3LQJS8.docdoc 43af38ecd27585f00463abfee0ca7f492fb36fa862c8d215447d59be27652589Virustotal results 61.90%Heodo
2020-12-30IHEDBBPPE58MOG4.docdoc d34dfac031661724abb4626c78172927bd98aec10118ac0117285d1ee6be8cc8n/aHeodo
2020-12-30XQE0OI61X7XBCVK4.docdoc 097234279d3321c5af9e943ee4171b8b30258cc924fa909d3219fc21f69aa4e6Virustotal results 27.42%Heodo
2020-12-30BGKPGMYWHD1P.docdoc 4c0bd56c72fbb8e4fc45f671c03970329a3070b215f7727f83040d529e44f5e3n/aHeodo
2020-12-30G1W3UBFT3.docdoc ff851095aca5969d1f70e5be1a645bf840e10b191b9037c50da8be304f5c01baVirustotal results 29.03%Heodo
2020-12-30GMPXDDH3ACEIJ39H.docdoc d3b4663e294cfce22aed52067a56d10cbd57c0ce477d110616debd538660a115n/aHeodo
2020-12-30MQJ5UL95HDT.docdoc 3c5a0e1906eb2a02dc597a235c6ba9b3faccc526ef1aa3b2f34f462257ff7261n/aHeodo
2020-12-30OGZHT322.docdoc 9828c9c819155af174adfcce8cc53b4dbc8e10db6f0f4b0661fe7225bb7f1b55Virustotal results 26.98%Heodo
2020-12-301GE372CG.docdoc 6ea37605aea5591d5271248f640a3dbeb9edec2ae1fcef4954213d025a812d4en/aHeodo
2020-12-30OLSTEVJF.docdoc c6333efba033ab3aa174d7b6254aa11c1b7c56ae806599e8b9361bf603477a09n/aHeodo
2020-12-30HFRDENF9X.docdoc 98434e35b67922ba13789c603c7e90797ae599f7458b281dae2823eb14389296n/aHeodo