URLhaus Database

You are currently viewing the URLhaus database entry for https://otex.inform.md/wp-admin/QTMqrsIWIyh5ItLgRerrr7G164gzzVAsaMnyOVhqNrs4aVkRNyxlCoYqr0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:949457
URL: https://otex.inform.md/wp-admin/QTMqrsIWIyh5ItLgRerrr7G164gzzVAsaMnyOVhqNrs4aVkRNyxlCoYqr0/
URL Status:Offline
Host: otex.inform.md
Date added:2021-01-05 12:21:03 UTC
Last online:2021-01-05 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-05 12:22:22 UTC to abuse{at}fornex[dot]com)
Takedown time:1 hour, 58 minutes Good (down since 2021-01-05 14:21:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-05IJ0IZJYGEDEQ6.docdoc 74cc67c1d7468460ff1f1fa0123fc12507010fe38a0931d6aae10ff539e0b63dVirustotal results 34.92%Heodo
2021-01-052IAJOA06.docdoc 56107ecbd594f1c684f729d239e501bb2d1561d6a584d7ba0a0d69ded2bbbb18Virustotal results 34.92%Heodo
2021-01-05G2WWMMDZ9T.docdoc dec912faff311861c29da440acd2b9397c1e37bfb5be458cb8b21fcfc150d152Virustotal results 34.92%Heodo
2021-01-05GJGKOU5HSBIWQ1LF.docdoc 80fadde081a035c58538d60c3829934f50b57a18850e7506eae4157595906af0Virustotal results 34.92%Heodo
2021-01-05MLOLM6Q9.docdoc ef6c966c74e229e34f880f5df67c40fc69a57caf55d1b033527dd9c5be04516bVirustotal results 33.33%Heodo
2021-01-05QFVXNUA.docdoc 2325bb3d4ffb081d6234ed1bca74f8662b1f85c6d27d6dec106e376590b7263fVirustotal results 34.92%Heodo
2021-01-05M7PRY8LEUQE.docdoc 01bce41750258f3d232b9eb7fe7901a88167254f0fe956f557bb33aced7cfec5Virustotal results 31.15%Heodo
2021-01-050YJYUP5FY24I66.docdoc b7a15626391073fea818a17906f508b97f3ecc2657103fc17761d2868b5a65e6Virustotal results 33.33%Heodo
2021-01-05V2QL3CRBB6JUD.docdoc 755c1e87c9c3e345b5eca450c1c72e05e691421932a8d8e26048990f9cb2ab5bVirustotal results 33.87%Heodo
2021-01-05G0BOZQV7QT0BYU.docdoc fb98c716e390d5ee1a67d0672d65fb94afc21949fcb158f654fb6405c079071fn/aHeodo