URLhaus Database

You are currently viewing the URLhaus database entry for http://www.enegix.com/wp-includes/browse/sxa2izxzmoi/wfitle-4887046627-008001-85p9l0e06-airhn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:266270
URL: http://www.enegix.com/wp-includes/browse/sxa2izxzmoi/wfitle-4887046627-008001-85p9l0e06-airhn/
URL Status:Offline
Host: www.enegix.com
Date added:2019-12-10 17:47:02 UTC
Last online:2019-12-16 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002159329 created on 2019-12-10 17:48:04 UTC)
Takedown time:6 days, 4 hours, 56 minutes Bad (down since 2019-12-16 22:44:19 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-121040442533233370.docdoc e4ee3410ab7fc7a374ee9ebac3303c290ca46c432fde4e126d7a6bcfdd542f00Virustotal results 29.31% Heodo
2019-12-12REP_IOW_120119_MKZ_121219.docdoc 950f087f5d65fa8d4664c098a44ade6defe2ac841bdd2fe3ddb1ed94f28310b9Virustotal results 36.07% Heodo
2019-12-125301396183624327026.docdoc 2fd40a68f859e0611fb384083902ceb2f9fd3d2b90ddadb73dc50ea7a2b7a6d3Virustotal results 33.33% Heodo
2019-12-123054244287508652380.docdoc 39fcdb6d9bfe5a2852d82896003591334b0dede609512340e876f275b4ff36ceVirustotal results 29.51% 
2019-12-12EJ_7368293468.docdoc de6662c946d502bee251e2dabcd64f8c31f8a8f31898c3cce8cc80b78a138781Virustotal results 31.67% Heodo
2019-12-12706398016924271161.docdoc 281353f5be1adab4b3bd5be93b4397edae5d9fc5a5595fa72dbf0d7967606d61Virustotal results 31.67% 
2019-12-12FILE_NZG_120119_TBT_121219.docdoc 334e163e327ab933368bc0b747b32027adcceb1e2b6682b63311beba0b84036fVirustotal results 29.82% Heodo
2019-12-12RIU_17634652.docdoc cd9fafbae1765254701fe1ed8e741e933871c9982e881a17fca79bd8c40d8dcen/a 
2019-12-12REP_UIN_120119_FZI_121219.docdoc 7880cc42f78ce37e1603207a15bb0471e309eb5fedc7fa51abbefd09e357efcbVirustotal results 28.81% Heodo
2019-12-12964496984158591087868333.docdoc 15d655db81abf803aa22bb3129e3f12caac4a096d6ccd5965016154ee7676293n/a 
2019-12-12FILE_PO_ 12122019EX.docdoc 4721a8055b657c23bd15975b8e48f48b896edb566b8ea44c7709df8967972522Virustotal results 41.94% Heodo
2019-12-12BWVTC6W3ZK5DURY.docdoc a7feb13fcde7026f34f534d7cba0254dbaa73cd900db12319766d6eccbfd0ed0Virustotal results 44.26% Heodo
2019-12-12CX5755920411YA.docdoc e29205e0a46f1fb69ba6e6c0ed8dbb12b195e7185583aea4e3eb76c88d441907Virustotal results 44.26% Heodo
2019-12-12OH3824352486YA.docdoc e0fd2fdc26869f285127622c05a135f251e83e589e2567e1aea88c55c4bb2723Virustotal results 42.62% Heodo
2019-12-11W_PO_ 12122019EX.docdoc ba8a46dbbb037ccf3e0a61a8586f83dab16705872f382c5535d25789f4bfa0cdVirustotal results 42.62% Heodo
2019-12-11REP_494742431392.docdoc 85118d674a99c1775c9710cec5e80f0a336484100c6be9208a129f8b60d017f4Virustotal results 42.62% Heodo
2019-12-11REP_BU0460371862BB.docdoc cedec09a05fcc90ba1bf5b84f0a2b0ea2f384029fb3d280a67442d359d3885efVirustotal results 38.71% Heodo
2019-12-11PO_ 12112019EX.docdoc 47095efb545a3e750f0e188d92fac881e98477bf6f4085b64dd64bd2f2cfb93cVirustotal results 39.34% 
2019-12-11HE4918795388XQ.docdoc a13264f95b1eb3d0145e1a2c7406e2c176bd66071d5121075992b1d712e753a3Virustotal results 39.34% 
2019-12-11REP_85321485758335.docdoc ce74e6d5c2375c3da3081f688225762fc61ce5f3181d4cfc2b517ac4d991bfc8Virustotal results 39.34% 
2019-12-11FILE_PHD_120119_YPQ_121119.docdoc ce9418b561864d7c255df7ad7d281a844d33343319a65aa4adc964b27c66cffbVirustotal results 33.87% 
2019-12-11REP_4T27RSTTV.docdoc 5b509684825da89a4b2b9fbec5b19d91c46b461f40263753e0cb5e8a493c58a7n/a 
2019-12-1101756335.docdoc fd7dc893434af1ebadb16503d302d46d256311b3fe4d7b93456f9bbc2030943cVirustotal results 27.87% Heodo
2019-12-11QCL_120119_XTH_121119.docdoc 2e0838a8b30aefbe23c45954f5bc35d663e7be2ca00f246b6bf735a6d5efde21Virustotal results 25.00% Heodo
2019-12-11DOC_XJN_120119_UOQ_121119.docdoc 90348b4d3ac94dbc837178f28d608e0d5f841267ac43e98cfa355e8973c34896Virustotal results 49.18% Heodo
2019-12-11VZZ_0RR1YLUDU68TFSZ.docdoc 8dd7c6b4d5989ed2ea37f47794ed5d21811086a5c0d5691fe698cb8589a073ffn/a Heodo
2019-12-11HGE_PO_ 12112019EX.docdoc 1a15dbb9573d4715318740a3d2a70ae5fd0d3ed5d3f349dd68ff15fc8f65d3f2Virustotal results 44.26% Heodo
2019-12-117298999204352417814317.docdoc 7dc82afc58fb81a256c24db77f61c5f95de8a9792502edc42fc84692572fcd97Virustotal results 40.00% Heodo
2019-12-11DOC_01926857.docdoc ececa128a027e4dcbd41d97bc3378c242a9701e8c583b0587b867621efb1503dVirustotal results 35.48% Heodo
2019-12-11REP_PO_ 12112019EX.docdoc d6243cd4386a6e018b061500ad3427b907875fe62b1277ca8f18e53c476ff57fVirustotal results 30.65% 
2019-12-11PO_ 12112019EX.docdoc 4face44e712880190ed46611d9e2c94b7fddc704e8580accb2f4fec0e02692ddVirustotal results 31.15% 
2019-12-10REP_RPW_120119_IYF_121119.docdoc 95ea8af7b6daa10fb5d0b502c3ef0b00ebabe9dc3ea809fe677b9bead870b93cVirustotal results 30.00% 
2019-12-10FILE_INW1JHJJZD.docdoc 993cc455bb335be039181dd68dc3a3a3055ac4538fe1322cf56707fd280561c1Virustotal results 29.51% 
2019-12-10TD_29167021.docdoc 44fbf4ea9f5e37e0eb42081211baf00263af7403ebb3691ba77e977bc488da4cVirustotal results 26.23% Heodo
2019-12-106429031273927722853.docdoc d2a37b2f1107177ff1ab49768e740e747144aedac86323f227b880201ba486c1Virustotal results 31.15% Heodo
2019-12-1046385128.docdoc 4d0b04d5fd9f057a17038dba0d821088dcca2d2cc2607388b74e98f6a4ba1783Virustotal results 29.03% Heodo