URLhaus Database

You are currently viewing the URLhaus database entry for http://korfiatika.gr/wp-content/aa16fx-dua05u-hxef/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:182927
URL: http://korfiatika.gr/wp-content/aa16fx-dua05u-hxef/
URL Status:Offline
Host: korfiatika.gr
Date added:2019-04-23 12:23:04 UTC
Last online:2019-04-23 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-23 12:24:03 UTC to abuse{at}hetzner[dot]de)
Takedown time:4 hours, 37 minutes Good (down since 2019-04-23 17:01:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-2336081550706DE_April_23_2019.zipzip e6c88b71c1818ed1367da34caa8db7b16fd0ce337594b1abe0e83cd8e3c38d90n/a 
2019-04-23729176206425DE_April_23_2019.zipzip 31570b2743ded2f48b6b44a5e41ad50a0b1acaec67e13e06258f087f0ca513een/a 
2019-04-23692721608986DE_April_23_2019.docdoc 99e638f6c4aa79656fee7ce55d9006b0d32618e4ab7126a221f21c1145d6dafan/a Heodo
2019-04-23408751459724DE_April_23_2019.docdoc a3933f110219fdc4b27bb3cc9df87a6d5ffca5c849206816c1311f2185551f9eVirustotal results 31.58% Heodo
2019-04-232890852177DE_April_23_2019.docdoc 178f9807e09da56ff02b4c72907f5cec2a567527da4ee515aa6453f47e52a787Virustotal results 31.03% Heodo
2019-04-238995625950DE_April_23_2019.docdoc 03d471048561df5ca748a9cbb38b424eb5ae4910faebee09b8182c96dfbc37adVirustotal results 31.58% 
2019-04-238336720463DE_April_23_2019.docdoc f5a6ffb607acd20063ae377d9fec4eb7e711e901ab55a70d05e3027f7173cbeaVirustotal results 31.58% Heodo
2019-04-23399217509829DE_April_23_2019.docdoc b619c40db4b3bac7a6368728d62a075a5fff1754d5949d75c0ba54a23564ce97Virustotal results 30.51% Heodo