URLhaus Database

You are currently viewing the URLhaus database entry for http://arezzonair.it/modules/sec.myaccount.resourses.com/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:170218
URL: http://arezzonair.it/modules/sec.myaccount.resourses.com/
URL Status:Offline
Host: arezzonair.it
Date added:2019-04-02 15:38:18 UTC
Last online:2019-04-02 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-02 15:40:23 UTC to abuse{at}hetzner[dot]de)
Takedown time:5 hours, 4 minutes Good (down since 2019-04-02 20:45:15 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-02UNTITLED_FILE_201904_L9_67-88_7625045.docdoc 5a44737ce4388ae58ef959a8aa55c51e15765b7e848942541376da9e6dd73345n/a Heodo
2019-04-02UNTITLED_FILE_V0_1-55_79697.docdoc 9e47428d488ae1e2119019285a2c5bdc6047e826d6fdffa27c987c278f144ed4Virustotal results 16.95% Heodo
2019-04-02UNTITLED_FILE_042019_N2_5-82_51868183.docdoc 2a114120c0f66e513197ae81ff3167cb7cd7e3b14b70791e0a6740eb132e1831Virustotal results 17.54% Heodo
2019-04-02UNTITLED_FILE_T5_7-34_72000377.docdoc 080d9962c714350a85fccb3886cb293a1a87b2dcc013222a93f653fa462d28bfVirustotal results 18.33% Heodo
2019-04-02last_invoice-04_2019_W0_1-41_754333.docdoc 0317563fd1c7ce48aebea75b1bbac6e69c3320e6c10debfbdf402bc3aa2d8d1eVirustotal results 17.24% Heodo
2019-04-02UNTITLED_FILE_M0_3-59_05623082.docdoc 749dea407910c04c9a4f8259b00937984e5885c5293a645a24e3fdeb10df949dVirustotal results 18.33% Heodo
2019-04-02OPEN_INVOICE_04_2019_R3_69-13_770666.docdoc 20fb659983053024ce1a08ea31a177d5f9a67b49b6155773cd9af150088ac1cfn/a Heodo
2019-04-02V0_75-26_65684.docdoc 240b33f3d8f8f20fee5239520a27ba2b7a0e2f1479466e097e543cb7f36bae15Virustotal results 16.67% Heodo
2019-04-02OPEN_INVOICE_E0_6-01_085341.docdoc 6037c07f34ea753ad6709c83b97a8489fe5443401767a1a579c8333ec3d2cd07Virustotal results 17.54% Heodo
2019-04-02OPEN_INVOICE_D0_3-20_65371.docdoc d005f5a634f8939bba1121bb5366acdbda2a2a74b4a3094979f0539be6488355n/a Heodo
2019-04-02invoice_number-04_2019_Z5_7-51_45192887.docdoc fec0121799ceccc38819fe794970070e2fa8d6191322c616de110aa191736fe5Virustotal results 18.64% Heodo
2019-04-02NEW_INVOICE_C9_22-99_32348308.docdoc b28c9a7ca9dd3a2c053b45b4c3b404771cf6dc3daefd93527f63855f83c47fd9Virustotal results 18.33% Heodo