URLhaus Database

You are currently viewing the URLhaus database entry for http://xn--80adicyfwmly7g.xn--p1ai/-/5r/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1994260
URL: http://xn--80adicyfwmly7g.xn--p1ai/-/5r/?i=1
URL Status:Offline
Host: февральское.рф
Date added:2022-01-21 00:09:07 UTC
Last online:2022-03-09 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-21 00:10:18 UTC to dpastukhov{at}eutelsat[dot]com)
Takedown time:1 month, 17 days, 4 hours, 39 minutes Bad (down since 2022-03-09 04:49:34 UTC)
Tags:doc emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21227910258201646999.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-2147868842705477.xlsxls b8fef9073b247386d53e1eba4723994cf6300b257f2b637cb1eccead6b68904cVirustotal results 40.68% Heodo
2022-01-210840859268533355612.xlsxls aa41c47fd919bc06f4b17ea69e649032b5a995e04b81a34dafbb3f0e4e5f1e43Virustotal results 35.00% Heodo
2022-01-2111957545285.xlsxls 6f95d343a882d6e800379be638a48804dfc956537ffcc06361e1f57fa2938808Virustotal results 22.03%Heodo
2022-01-217236991849232113392.xlsxls fb342d93313da0e2fc18a3c7f799a3807147d080deefa470cb3c4eed491a2589n/a Heodo
2022-01-217116417910.xlsxls 8b24ef9d0556c1351a46d2e0eb996b21b65638c41dc79cd5b676a79bf0d18a17n/a Heodo
2022-01-2184728223519.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-2181226992525661575.xlsxls 3d14cf1ac0e948d8d736d86a089783fc5dae612426213cbead14ec631ab46fddVirustotal results 22.03% Heodo
2022-01-21005644155658.xlsxls b056a3191538792998936cef580c7cd75e9b49d40a53452f6e8dd20d5814934en/a 
2022-01-21196976188870.xlsxls f8b8104e17358beef65e6fdff2be55feefca3de5b25cc90d42f3476aa563adf8n/a Heodo