URLhaus Database

You are currently viewing the URLhaus database entry for http://backdeckstudio.com/NdocmzzhTf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:9974
URL: http://backdeckstudio.com/NdocmzzhTf/
URL Status:Offline
Host: backdeckstudio.com
Date added:2018-05-14 18:40:05 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: cocaman
Abuse complaint sent (?): Yes (2018-06-11 10:25:39 UTC to abuse{at}siteground[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-06n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2018-05-16INV990907432918947832.docdoc 2c4ddf18e72385c69ca425f9a89f65bcf0fffb367ee6adb0315db0874c4a3a5aVirustotal results 18.64% 
2018-05-16INV53934424790.docdoc 30031fb352b8c753ca5aa8756a67435f19f94046fac589724d2a41fd162012b2Virustotal results 38.60% 
2018-05-15INV262529316199.docdoc d84eee4e637944017ad294d50e66280cd335f2b9e44745877d585d133587ab3eVirustotal results 33.33% Heodo
2018-05-15INV00649042082137.docdoc 7d013c71ea22af7b40f6628262ba76f0d5bc152bbfe3c7086ecf8c5d810a0446Virustotal results 28.07% 
2018-05-15INV17609933107522.docdoc 7f5604e8ca4dc2153f2d94aabbecdbc27e0fe66b78701e2d52192bebcaf426aaVirustotal results 24.14% 
2018-05-14Fwd: ACH form.docdoc 1d151ad8ed9c850f4b2822598e9a4fca72b33c6f332a6140221d53d3ccbe4b40Virustotal results 27.59%