URLhaus Database

You are currently viewing the URLhaus database entry for http://dfggggx.xyz/wordpress/U4D18LZoezNvPyFV9w3wB4Rx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974509
URL: http://dfggggx.xyz/wordpress/U4D18LZoezNvPyFV9w3wB4Rx/
URL Status:Offline
Host: dfggggx.xyz
Date added:2021-01-22 21:09:05 UTC
Last online:2021-01-27 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-22 21:10:08 UTC to domain-contact_ww_grp{at}oracle[dot]com,network-contact_ww_grp{at}oracle[dot]com)
Takedown time:4 days, 7 hours, 20 minutes Bad (down since 2021-01-27 04:30:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23DC3A6ULC2YPG3RO.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-23TQQZRQ7X5X1NV7H.docdoc 33c3b2856eefdb51dd0d8798ddaeac57d3a1b63fe1cf86732f08d2cc5b1b851fVirustotal results 52.38%Heodo
2021-01-23V1NXB7.docdoc 57d7ff4664c6bffcb350211f1d9cbc272747c201c3c784fcfbab0f49c986f53en/aHeodo
2021-01-23349UN7SJY2TV.docdoc d748bb7a8d447b8bbcbea5a3d20a404351c3ea3dacc3f332a41f44f138be5320n/aHeodo
2021-01-23Q2WE7QUTU.docdoc e7ee687cd06e406cad317080de4ba7a41dc9bc8ee8f8a35c76003488b502dc5dn/aHeodo
2021-01-23WVLHBOL60XJIH20.docdoc 28b78d04a0fa5ba6b6c3504f9d9a7664f16710d02d2e92be72e97f03ae3a690dVirustotal results 53.23%Heodo
2021-01-23FVM9ZBTEH2FQ.docdoc f967919221798935016821892199d1eaf45960045a79bf0ecb89297edf4d4cfcVirustotal results 33.87%Heodo
2021-01-23KR39SPXD.docdoc e3a0c8c17306e77db4fca51970cd0372508a59234fb62ae5e0cc6656e1fa5595Virustotal results 52.38%Heodo
2021-01-23CRKA9ZXO.docdoc 343a9444d82311b35e225e7f819846eb81890d285f051585d33692e2d78fb73an/aHeodo
2021-01-234JNYU484L.docdoc f44e4ec9321617fcdfcb91fa516a2c17f3d14fe21ba167f0db47e448fd37a0bbn/aHeodo
2021-01-237QDIEF1VAG33.docdoc fe303e9b7b33de110864829b531bd9a586c93da165ca271358192edb57722988Virustotal results 33.33%Heodo
2021-01-23BZNLWH13H1.docdoc 02e4aa3af6d4d0a6c3f5965922f7ec76cc4302e17b7ca1c2f28601ab53f76be9Virustotal results 53.23% Heodo
2021-01-23ALJ336VI2XW4YRA.docdoc be26736f51aaefad6e9e969237302a4aed11d4990cc40050c7fae379688d1e82Virustotal results 52.46%Heodo
2021-01-23HRXA7W3TVNKGGHWG.docdoc bda05c4ef660a15d781f9d7c44415a119d2137f46a63b124b6a154e382ad7fbaVirustotal results 52.38%Heodo
2021-01-239ZT4OLYB.docdoc 24093743cc1b5882bb6b43c3712d06a13dad73e41f2c95f44d71286d515a1120n/aHeodo
2021-01-23MIR2CMYZERZTPO6.docdoc ac3a231f0035c95d710e53ec6dd86a4a915dc23b12238c4d118e7c2b656cad2fVirustotal results 53.23%Heodo
2021-01-2387QR3PTIRICB.docdoc 422c84eb3c0a25bf5ea4c23eb23b048c1ff8f1dda0510c84362dc30ab3fab6d7Virustotal results 52.38%Heodo
2021-01-237QZVIAPI.docdoc bbefec31ea0c2301e8202d73acf49ca0d72f4a3b80b6a81836e49b1591d3d78cVirustotal results 52.38%Heodo
2021-01-235D6YCY.docdoc 0d95efeb799d69a27255270804aa8efa5e91cd71b55943e37e88e772c961bca2n/aHeodo
2021-01-234XA1UXUS3HR.docdoc cb4aaffb479ed567e1cca60bdb16fe0ede6ca520f16b1129e28eae589d6f37f6Virustotal results 51.61%Heodo
2021-01-23L5BDX7EJMIMC04J.docdoc 70243026bc064de134f68a08e53d203939580d1dfbe011360f72a5df0132fdf1Virustotal results 49.21%Heodo
2021-01-23F2PI77BQMEHS.docdoc e621537a061ede5d0f947fecfccc7e9568fbc21942c2b64801138b227e4f23e4Virustotal results 49.18%Heodo
2021-01-23WALI5J5TV19.docdoc ac612e34cb415fcaf5c0ae462ed0e4efee5897879ee434b80354b39fe34e9317Virustotal results 50.82%Heodo
2021-01-232I1YG9YWHCIW.docdoc 3b8c1a7288a8940c4785141389d323f7949b9639ca7821ebad1fc2182a2acf58Virustotal results 48.39%Heodo
2021-01-23FQYC6UO.docdoc d926e60d6b78f6b07a61842aa31c25077849e0921bbb8c454900a6b1447427c0Virustotal results 34.92%Heodo
2021-01-23992D2NV7PXVLYYWD.docdoc d24e032bf95e95b0c1325688cb50b3eab851e90b9350f1a031668dd2bbfac3b6n/aHeodo
2021-01-235R9U9L38JE6BWTPP.docdoc 56e78f5aeb76d3b2002f79b51c0344a1bc95e0c171a56f5e7bae43028543e1cfVirustotal results 48.39%Heodo
2021-01-232PE9ZZJESFMF3X.docdoc 20b1f1c932f9ac88685c65ca2ed2d57ba42e6cc5d643c567fbff933e64e09797Virustotal results 48.39%Heodo
2021-01-23IG2UPQEG0JQ2AY.docdoc 1e6cf8d2575be1847bd2c4e53b2686b8346c940c315c68f3dcabe5fc53802dd8Virustotal results 46.77%Heodo
2021-01-230Z5BH77ES4.docdoc f241cc6276c27e057b1caf39073c1aaf230cd54bf6ecfbd7e08ec9bc0ff9a83bVirustotal results 31.75%Heodo
2021-01-23HDM4ZLOM4DZNM.docdoc f34429ad75df699dbcc635b6afcd91b52756fa1d34dce852fead86e0c7eea37fVirustotal results 46.03%Heodo
2021-01-236IP8F31F3X.docdoc 04d66ed2d7e82444ce4d2b8227f03b6612a55e843e3ef434c01c93b65f10ff04n/aHeodo
2021-01-234E9I7N5UN.docdoc d5da4dc5a6a3fc416aca8ffbfaa3b6cb18a1efd11b94eb7f40a584fd96813f8en/aHeodo
2021-01-23F4AN1F4H0IRY8A5K.docdoc fa5a2480a61176d9ef8d383ec2a77a0902bd417188b64418d1920e74505ffc1bVirustotal results 43.55%Heodo
2021-01-22IWWQNM6W.docdoc ca558091c68ff2e4fc47b90cb98ed6e1eccb1f6362e8dc9cf47d91c5295b1b13n/aHeodo
2021-01-22LTT5K7IE6BGCKB.docdoc 42468a0f13eb23891636d001f932b9b706f4e43f2bcc3bb417f89ea79e8f7415Virustotal results 32.26%Heodo
2021-01-22FVEKSJWL6BN6M.docdoc 25eae8684f15cff80197f955eff7899e81081b1d9dd37eb92f62d7bb8bd796adVirustotal results 47.54%Heodo
2021-01-221BM6J2.docdoc 58679381a46d62f343527eddb0e188a30184ea770eac5182c427ff13ec75412cVirustotal results 44.44%Heodo
2021-01-22SC9TPOILWB51B4C9.docdoc 6776f53efed3f91af5955bfaf11f47dbf6fcf5b5a419e1bcc5a29fb89a61ea49Virustotal results 40.98%Heodo
2021-01-22H7SMD0.docdoc 42152c466701b05f7fdbc32e290f3cd236d53f2a4a6e212bc675183e4a2eafd3Virustotal results 45.16%Heodo
2021-01-22R2P3FRJ86KCYGCRK.docdoc df60461aab62bf09077b67a5fd122fa46ed22f8a8d184035786a7ee3be961927Virustotal results 45.16%Heodo
2021-01-22IDK1RNDVN.docdoc dda4d5d6a43a16422b43d2303fca26fdda00b3b7836e9aff4ddbdd19442d9697Virustotal results 41.94%Heodo
2021-01-2220VBYMC8AG.docdoc c82d9f636e5557e336f7590d7012768bd8060c6ccbe44a3a5c1c2e3976c62b3dVirustotal results 39.68%Heodo
2021-01-226M33T1537WN.docdoc e86d93199f2f416bf5dca9a736c5bdbac4ee3989ab0f04baad2c7e0066316e72Virustotal results 39.34%Heodo
2021-01-22VA3K7H52.docdoc d369edd4ee295fafd1231bb5d370fff75a48505360a64708bce6418c7f2974a1Virustotal results 38.71%Heodo
2021-01-22B7NNGMGH96O77C.docdoc 5baed32dcd265a53a8f5f4182bfa79336ffa1acc17f1ab71e8387529a82b10cdn/aHeodo
2021-01-2298XX480PD0KI8YRW.docdoc 26e5e6911e1f51c17316418cb81c5e699c0f986235871bc9e8c1c473c6109655Virustotal results 40.32%Heodo
2021-01-22SNIIS7IE.docdoc dda31bb204e2a3207fe515d3d1952604f010c2b3bfad0df8a1b33e7b4bde2b94Virustotal results 33.87%Heodo
2021-01-22JMEI92C020380F.docdoc 912f6f38547eca79cdd2f66b1252ac5b777f454c8d4da059d319ca9a42d1cf24Virustotal results 37.10%Heodo