URLhaus Database

You are currently viewing the URLhaus database entry for http://www.sz-lansing.com/wp-includes/Scan/gQ4yUHQu1UeU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:183411
URL: http://www.sz-lansing.com/wp-includes/Scan/gQ4yUHQu1UeU/
URL Status:Offline
Host: www.sz-lansing.com
Date added:2019-04-23 22:19:03 UTC
Last online:2019-06-05 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-04-23 22:20:02 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:1 month, 12 days, 11 hours, 7 minutes Bad (down since 2019-06-05 09:27:32 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-25INC_42261541750US_Apr_26_2019.docdoc 2d4c029c63ed1ca1131a3ddda7fd4e66078676407a476a00ccd09d2a85c8079bVirustotal results 31.67% Heodo
2019-04-25LLC_3367887173US_Apr_26_2019.docdoc 2be2d55078be5d7a6982c89413fe4039cd65fd64f0e786481d785d726c24560dVirustotal results 28.33% Heodo
2019-04-25Document_6781947885US_Apr_26_2019.docdoc df0fb247a70c89c6562901405d16cc4d36f5052d95ecedc5b9ed5185a0125f91Virustotal results 27.42% Heodo
2019-04-25LLC_378217075152US_Apr_25_2019.docdoc ba1753410ac11859abc6237cefbfd0fc63b872fae35967326374353049918c55Virustotal results 26.23% Heodo
2019-04-25LLC_725564719559US_Apr_25_2019.docdoc 863bef93f145d590c49616b371a74a51cca7eaddb9be7b6a55d1d1ffd5f15cbdn/a Heodo
2019-04-25FILE_7302599139US_Apr_25_2019.docdoc 64f50f8c4e9bd7b196aa3d88694280da4762e02157d0f53ac68ca37e86d9e6f2Virustotal results 30.00% Heodo
2019-04-25SCAN_6499228515US_Apr_25_2019.docdoc 372935f96d1e807f4891ffdcf2319728d0247660c0d7fe44738f3b58571751ceVirustotal results 30.51% Heodo
2019-04-25SCAN_6389926129US_Apr_25_2019.zipzip b943b5a9ced960afb98b3d9dad1f1438f0cf94cbe580b7549a945b507a69c856n/a 
2019-04-25DOC_99514444455US_Apr_25_2019.zipzip 26ef3e074b13faedba8a62e7c10e950c29f8aa4e5d19ab17e87bb13854a8527an/a 
2019-04-25LLC_7916832170US_Apr_25_2019.docdoc 3d3d72d079ac4d6709a8fe663e2e3f3426e0d4e132615036c46b23038dc0cebfVirustotal results 37.10% Heodo
2019-04-25SCAN_936446441170US_Apr_25_2019.docdoc 87ab3e0ad7c910590c7b4d04a8e572906de0901846d696924351a7f79030497bVirustotal results 34.43% Heodo
2019-04-25SCAN_727970502136US_Apr_25_2019.docdoc d3c085cb5444dd3bee1f04a36f095305000b3e22f59738a4cf3b370c1d203863Virustotal results 33.87% Heodo
2019-04-25Document_69026334188US_Apr_25_2019.docdoc adb17498e7aef92a20608d0899bca2e9c61c730889b3105e8e56517bb54217bcVirustotal results 35.00% 
2019-04-24SCAN_577340634185US_Apr_24_2019.zipzip 415306f8eddc0ad0c6f8dc4415d091315aadae2770d4572038999a81c403269fn/a 
2019-04-24Document_44350110074US_Apr_24_2019.zipzip 045991046353bab14a5d6c9d69e570c4fc8e96dfac09896f3fc60a864d5dc9d6n/a 
2019-04-24FILE_8731141423US_Apr_24_2019.zipzip 65cf092e152d2a973945d6d166d65bb420bba2097499100f4ca1717fec25e1e9n/a 
2019-04-24Document_6536747523US_Apr_24_2019.zipzip 85ca6c6d00f9783fb7a81dd1e7fcc7086d62294d3c86e3d320e2e9d1f3a6cee4n/a 
2019-04-24SCAN_2818745052US_Apr_24_2019.zipzip 2222e939089003325db16554a225ce948e00b92c00b6b971bde0270f9c473becn/a 
2019-04-24SCAN_90371538320US_Apr_24_2019.zipzip 743031fb31c1bec1b61cc3f6e745e36696161ce28b9ef24a0fb2c9d9fa42b964n/a 
2019-04-24INC_725126034792US_Apr_24_2019.zipzip c525606420814b733606ec70d350df28aa70c7eb91982f56532b6404fed4a33fn/a 
2019-04-23SCAN_4974980073US_Apr_24_2019.zipzip 1dc362c946ebac623b1449099205ae1dbc2e22f9a9bc869e0d0cb980ed47fdcdn/a 
2019-04-23SCAN_0139583400US_Apr_24_2019.zipzip b940f650ba5a8e4690d38cd77c34421e57890b42141f3bff414fe1a9ad3175c9n/a