URLhaus Database

You are currently viewing the URLhaus database entry for http://tsk-winery.com/wp-includes/sendinc/service/question/en_EN/03-2019/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:161721
URL: http://tsk-winery.com/wp-includes/sendinc/service/question/en_EN/03-2019/
URL Status:Offline
Host: tsk-winery.com
Date added:2019-03-19 01:34:31 UTC
Last online:2019-04-12 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-19 01:36:16 UTC to admin{at}itools[dot]mn)
Takedown time:24 days, 19 hours, 16 minutes Bad (down since 2019-04-12 20:53:06 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-12Secure_message_8227992654.docdoc d8b58f7a0298951ea482b26a302054ccd85179b3f34c3023f6481780dbb70295Virustotal results 58.93% Heodo
2019-03-19Secure_Email_file_183859139.docdoc 948e90c7ce98dca2d57cb92e1cd52467eae923246771c86285317df8ea76bae7Virustotal results 27.12% Heodo
2019-03-19Enc_message_620187292.docdoc feb5f90b505c63edaf38330efa3b54550fe8146569592d0e52ef971c0f1929d9Virustotal results 25.00% Heodo
2019-03-19Encrypted_message_68029705.docdoc ae95978f84168442841da9be86225a83fc17aabc3361c157c34f4593e58028cdVirustotal results 24.56% Heodo
2019-03-19Encrypted_message_765634361.docdoc 9ada632cea755555f9d32f936bd04d161efdc6c32c993a303a025140a19fd3d2Virustotal results 24.14% Heodo
2019-03-19Secure_mes_3327122126.docdoc ca3984297cae7d45ee87c611dd59ccc8546458a528d0784448fd5fce6d911393Virustotal results 25.00% Heodo
2019-03-19Secure_message_1075003532.docdoc 176f875872456a1d333a105674b18bb606a67f55a2c5ad42ff0edc778b3e93b7Virustotal results 21.43% Heodo
2019-03-19Secure_message_39540860.docdoc a5b1ea5db4e3093d3ff099173c2c07e48ee6954a2dd52eb3ed11540bc7ee9471Virustotal results 18.64% Heodo
2019-03-19Encrypted_Email_file_3364119747.docdoc 7779d56361bebca314ef8fe367e6ab52ea79db14223b7e7cfa867f8a82b26b32Virustotal results 15.25% Heodo
2019-03-19Enc_message_257366329.docdoc 82782034c6c1f7a99e934e67c9a1d38d96b77bd5623956e2ed6859958f70f789Virustotal results 16.07% Heodo
2019-03-19Encrypted_message_5137644982.docdoc f3ee70dc667237feb241f911c215de5470b3eb852e37d57d9a74c8027889d0fen/a Heodo
2019-03-19Secure_message_061730350.docdoc a3828e61f94f16dba98523490ddca4c422526fe4da34472ab0335a10b259ef95Virustotal results 15.25% Heodo
2019-03-19Enc_message_360361645.docdoc 6c0627c54252331fad4ba98a05b07bf5a766f344a1276c4ea5b48908f6c1017fn/a Heodo
2019-03-19Secure_Email_file_4640346049.docdoc b4468d5ea5a9078d2a98e26f442d265fe2b2417e790ea67c91ab9ccd8aaf2f1fn/a Heodo
2019-03-19Secure_message_0054368569.docdoc 66641aec44708f5c4ff38cf102254c574487204af55dac3a696808b1619c4d57n/a Heodo
2019-03-19Encrypted_Email_file_267779809.docdoc 0fc6fb99897612d01736a5f71f7e7ea7409126c8f44e001ea948b259cefb8a09Virustotal results 17.24% Heodo
2019-03-19Enc_message_19043177.docdoc 4beb24584ac6a064ccbd3b6e764c90acac6354b2b6ca7f18d915246fa53a6ae4Virustotal results 17.54% Heodo
2019-03-19Secure_Email_file_141347663.docdoc a01da91df3781b389b71dabd91e8707363cb3eeb1db8c4de6b54be5d7f800125Virustotal results 17.24% Heodo
2019-03-19Secure_mes_804795749.docdoc 248ff1b212ec4bfd9372eabd30c6270f5d1b47386bb9741b357bba419c429d29n/a Heodo
2019-03-19Enc_message_09630514.docdoc 016049e77b1a74d07adc295bfe41264e771f4e6683f898236dc3b08e4f2eaebfVirustotal results 17.86% Heodo
2019-03-19Encrypted_message_84075297.docdoc 345263e1b1b35d1829180408d51db483c983ed5474648d32c44ff5f244ada45dVirustotal results 17.54% Heodo
2019-03-19Encrypted_Email_file_34952701.docdoc 3f36c2ed4d364734e6f09afb5fcb2501bea3f611dd7e5f4d55896a94fe9b7015n/a Heodo
2019-03-19Encrypted_Email_file_44241057.docdoc 7d1e0078cd3d171100cfd73644f1082fb7244d21f88121b0e973815021d74d56Virustotal results 34.48% Heodo
2019-03-19Secure_Email_file_061555999.docdoc 80a09fae3a1110bac776db5d9d2d8ed08fa8c1de96ee2f67d1d3169d085b8150n/a Heodo
2019-03-19Secure_Email_file_9203841821.docdoc 8d714d316d5278c294748d8d2256b397f7156518fec58cc39ea10684c4bffd0en/a Heodo
2019-03-19Secure_message_88538467.docdoc 752efd5a5b62949ad2732fd552ae98f64eb365a59a230607b6c6fd86ce6fdd88n/a Heodo
2019-03-19Secure_mes_614408383.docdoc 5605f91d538079fcfc11d81ac0bdb5dc142481cc476abc4a59943a448ed26fe2n/a Heodo
2019-03-19Encrypted_message_2390256532.docdoc 47bc07d8020c8f7016776be5bcc441d5890d98a9327b32abffaf5a2a86f4ef26n/a Heodo
2019-03-19Encrypted_message_541916589.docdoc 8757addb018953afa081a8043da70de34570038880431d7ae2f28037d724de55n/a Heodo
2019-03-19Encrypted_Email_file_714715018.docdoc 080520eb95bee943e54bb4f96c0875ed21c30eace81fd97b13f85a93a292abd1Virustotal results 38.33% Heodo
2019-03-19Secure_Email_file_0201736766.docdoc 61b551ab0c2047d59e01bebed81556c2cef72205c0b3ef98dab829383de4baa0Virustotal results 27.12% Heodo
2019-03-19Secure_mes_409150127.docdoc 33211ae2b277dedcc5dd61f6bdeb1ce8edca74f4746d3477ae95e24a39645f5bVirustotal results 36.84% Heodo
2019-03-19Secure_message_16090193.docdoc 7c7ddd7bd3762fb34953fe5b8ba0a6de4a373549abb6b1eab3f7fb7890c7f279Virustotal results 31.58% Heodo
2019-03-19Secure_mes_330654713.docdoc 04bc07b69f3958f3459e5f6e243255c41d09e641e4a55817620edbf49f3b05ffVirustotal results 33.90% Heodo