URLhaus Database

You are currently viewing the URLhaus database entry for http://charleswitt.com/tmp/ivfPh-oAGLrInjWW9E64e_XtGSfFNsh-CjZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:175411
URL: http://charleswitt.com/tmp/ivfPh-oAGLrInjWW9E64e_XtGSfFNsh-CjZ/
URL Status:Offline
Host: charleswitt.com
Date added:2019-04-11 08:19:03 UTC
Last online:2019-04-11 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU001216134 created on 2019-04-11 08:20:04 UTC)
Takedown time:8 hours, 58 minutes Good (down since 2019-04-11 17:18:26 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-1148353498_2019_04_11.docdoc 778799ba6d4bd50f09c563b1a2a92fe0bc08e451a8440f0d05d3f5d84bf0114fVirustotal results 26.67% Heodo
2019-04-111648182610_2019_04_11.docdoc 29dfd15203b405688176a88ab88e9649d37b3ffa853b981c05c9687fa507aa7bVirustotal results 28.57% Heodo
2019-04-11223572846_2019_04_11.docdoc 16d8462472049317c8107d50456c017151fd485e00f5282d0f7c90d22450e2c4Virustotal results 27.87% Heodo
2019-04-11782416413_2019_04_11.docdoc 7b2a0b61f399cff8642376258f775efa0e6a41e4738f67cb325ace0cb19f5239Virustotal results 28.81% Heodo
2019-04-11049745011885_2019_04_11.docdoc ad608ce9d7e544f8fa1e7542a35dab08028121f0cb6628d5122196de6c2f21f1Virustotal results 25.86% Heodo
2019-04-1124032416_2019_04_11.docdoc 8ff871e80c34f355495850fccb410b081f5864388dbe2bedcdbb42edcb2460daVirustotal results 26.32% Heodo
2019-04-1171035718618_2019_04_11.docdoc 700233317224ddffb5758cbb56b47c96d4c64ded3c36c323166332f0844cb6adVirustotal results 27.42% Heodo
2019-04-1154400161387_2019_04_11.docdoc 1c2f5b6c9d595a323357419ca2a48ad6052d4e57b22b34fd1bcb8922726967aaVirustotal results 25.45% Heodo
2019-04-1110915411_2019_04_11.docdoc d3d78c3938d6ffc08c85615bed31fe15c138562d7166dd7cc389ee8085080462Virustotal results 25.86% Heodo
2019-04-11136327471382_2019_04_11.docdoc 031a13f8b3d2c6cc24a9ee7fdf1b46aface18643b3288023b6f7a8344467fac1Virustotal results 25.42% Heodo
2019-04-1135646342_2019_04_11.docdoc ff77e443ab3da421e88bf69322ee7f5e8c433737116f0028c8b1ac4994c4c45eVirustotal results 25.86% Heodo
2019-04-11497447197588_2019_04_11.docdoc 2ec7e8dc8b7e0eda7ec0d2721c7ec01c7b43a8ffd66351661a3b0716d139ad9aVirustotal results 26.67% Heodo
2019-04-1150046391_2019_04_11.docdoc 325c1bcff4186c22d990c7600d2daf9692071d8513dd34e534aa47133a2e461eVirustotal results 24.56% Heodo
2019-04-1197774207498_2019_04_11.docdoc 51b932181b9deb019da2419bc372f8de65534f3e9ad755dfbae7d0ec598144can/a Heodo
2019-04-1191369208116_2019_04_11.docdoc 7464e95cb2189b4fbd01993afae23f52049916dd7dd6d0f4aaa6f5a34d5df21bVirustotal results 27.12% Heodo
2019-04-11481337518200_2019_04_11.docdoc 0e93d5f23fa1f6443b5175cc7d9c042cf55b7c67f1d96f0d8a7cfba42409bfa2Virustotal results 27.87% Heodo
2019-04-1192908858404_2019_04_11.docdoc 0d361738542120899be420d3ee578f8b7699f6668b69233889b5a934d4f145bfVirustotal results 26.79% Heodo
2019-04-11261939009_2019_04_11.jsjs 5a2758a184e31e068584766b5abe5843f3d6327714e60ff4b8888be2809d2f03Virustotal results 12.50% Heodo