URLhaus Database

You are currently viewing the URLhaus database entry for http://tengu.cf/wp-includes/phio-81yfm-brqfmlvjs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:162816
URL: http://tengu.cf/wp-includes/phio-81yfm-brqfmlvjs/
URL Status:Offline
Host: tengu.cf
Date added:2019-03-20 12:11:04 UTC
Last online:2019-04-15 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-20 12:12:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:26 days, 6 hours, 39 minutes Bad (down since 2019-04-15 18:52:01 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-12ACC41026228965.docdoc 2ceff8b964e28e3e3e22cb5402388d1579d1775d69e1566aa3651304db09d291Virustotal results 72.88% Heodo
2019-03-21INSTR596061044.docdoc 27c96680382ea3cd21b2e384525174c9e5f6761e7ab15e6232c11d22cfc6df8fVirustotal results 33.90% Heodo
2019-03-20FSC77079283368.jsjs 869f09c1b430433a385b4ec13a90eef4cfe0cba092a46fe71107de2f865bdf0en/a Heodo
2019-03-20US114703025336.docdoc 2d6f6c5fe5c4af44e8076f053d423de86f1d1cd62c78f8a2bd7bfed05841e03an/a Heodo
2019-03-20INSTR01856386926.docdoc 023ca21f517ae8c1dab26cd17ceb16765a6768ddb02d7bf03e8777fca53b4bc2Virustotal results 20.00% Heodo
2019-03-20ZR650191873.docdoc 211be866b21316604e53bd3f50bc502280c7b1603ab7ef7ef96c22b369402030n/a Heodo
2019-03-20PAY5774955791704329.docdoc 5b42db8d80442f5c13e700ebccef1f0ea8cb2f929a9be800543d7ad4c88c48e7Virustotal results 17.54% Heodo
2019-03-20US80710297733867602026.docdoc 65e4b399804f938a56db8a31edc7c83b4d843004e963ecdc23bac696a3491055Virustotal results 19.30% Heodo