URLhaus Database

You are currently viewing the URLhaus database entry for http://immigrant.ca/wp-content/FILE/hh9T4aoowVl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:185773
URL: http://immigrant.ca/wp-content/FILE/hh9T4aoowVl/
URL Status:Offline
Host: immigrant.ca
Date added:2019-04-26 20:50:03 UTC
Last online:2019-06-10 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-26 20:52:03 UTC to abuse{at}bluehost[dot]com)
Takedown time:1 month, 14 days, 20 hours, 10 minutes Bad (down since 2019-06-10 17:02:09 UTC)
Tags:doc emotet link epoch2

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-29DOC_09566137711US_Apr_27_2019.zipzip 1c4a65ee698c798b9d4b7a43b21632039a2b1b1859f250af91791706a97e7079Virustotal results 48.33% 
2019-04-26DOC_52737743994US_Apr_27_2019.zipzip 6a48f85b0fbfd467dd2cbea8dd30ef61ccbe4dda99c2fd8eaa9bb97e95076754n/a 
2019-04-26Document_2169676792US_Apr_27_2019.zipzip 7b19e47367131bb1ca0115bb4ebe3cb2a94153e5f506839792d06dc2eefb1206Virustotal results 25.42% 
2019-04-26SCAN_0079917957US_Apr_27_2019.zipzip 08c01bbc0e5406dff46da7264d50be68fc54794258aff5fdd06d9534b70caac0n/a 
2019-04-26Document_66205610531US_Apr_26_2019.zipzip 7b503a777ea34037c9459125c5886dbadbd84ee78ea5e8135340b8f214d90140n/a 
2019-04-26INC_1006945254US_Apr_26_2019.zipzip 169ee3508dda8b9d8ade3204e21ea8439211c571f1701537ab2d4f9d8606b575n/a