URLhaus Database

You are currently viewing the URLhaus database entry for https://thedarkweb.biz/wp-includes/GM8JAVJ0NrwxYbCCDN466vcYmzEv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:955863
URL: https://thedarkweb.biz/wp-includes/GM8JAVJ0NrwxYbCCDN466vcYmzEv/
URL Status:Offline
Host: thedarkweb.biz
Date added:2021-01-12 17:27:05 UTC
Last online:2021-01-12 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-12 17:28:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 25 minutes Good (down since 2021-01-12 20:53:03 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-1260NP9YUSJDEB1W.docdoc 1c5577ae92907b0a10a1bef6a52aad25cc73e79b523c737d07e2f012009d7eb7Virustotal results 26.98%Heodo
2021-01-123ZN9MSCGO.docdoc 9da23b3c04fcfa19a1abc9124178a69e76e95246fe1a5065bc2a0876543890daVirustotal results 26.98%Heodo
2021-01-124YD7Y0MSR.docdoc 5dc8879e45c66e6828353ae4f543d11ff810806cf4609fd4cd3f8d5e768a722dVirustotal results 26.98%Heodo
2021-01-12CMFD06FYD.docdoc 5df4b703c5848bd3bf897faba1f1142e11c95e17e720a911ade33cdb275f3e0bn/aHeodo
2021-01-12KWWE9PFVYGMQQ.docdoc b7791efd3643b52b9aaf312054b9b2e3ce70b9fc88d0a0b9745419adb1b296a7Virustotal results 26.98%Heodo
2021-01-12RBME91.docdoc 10ca32d172e5dafd7c07e4e27f6c6a24bbb6af319a78a66691b819532b1d2dc1n/aHeodo
2021-01-12BMFKKBP0SO.docdoc 1c5dadca018d0b95208e3d1b84f4200ddaf6a290df549880c032ec214e62c2d5n/aHeodo
2021-01-12D9CXZXACI5AUXBJH.docdoc b6278fa190059a4aa35b99db07331dafae707d9b30255ea5c69b1a747a386ad8Virustotal results 26.98% Heodo
2021-01-125GYYNVZDVOBSHDGN.docdoc b3c4491c50e776c893a66adb0e906344dd6d5172d724e8baa4946c5d69480bcfn/a Heodo
2021-01-12I2T1UQ4WGLKEE3H8.docdoc 1a3424434141f6eccaa646d9ea7178880bd418380f7566485521ff809534e9d3n/a Heodo
2021-01-128KTAUSBQAAP8.docdoc a82aee5b05a1f8714068bf50b59b239fd6119efc6f5759385763c2080ac69c9dn/aHeodo
2021-01-121QI7RL.docdoc df16b0f4fbe2732a39c1366407be020464b402e65344f188c7a17f6dfb0c5e22n/a Heodo
2021-01-12IDSX3UMYG8QE.docdoc 896f4bea1bcf6db54bbfe68bf6b19a004e075a9c845a9f7f8a9320e81dc26c25n/a Heodo