URLhaus Database

You are currently viewing the URLhaus database entry for http://tipografiagandinelli.com/wp-content/Overview/s68qbnp/hlfj-92464584-7213762-winnw769-6ujhi5dg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:266315
URL: http://tipografiagandinelli.com/wp-content/Overview/s68qbnp/hlfj-92464584-7213762-winnw769-6ujhi5dg/
URL Status:Offline
Host: tipografiagandinelli.com
Date added:2019-12-10 18:47:02 UTC
Last online:2019-12-20 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-10 18:48:02 UTC to abuse{at}as29550[dot]net)
Takedown time:9 days, 16 hours, 5 minutes Bad (down since 2019-12-20 10:53:54 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-12FILE_5O9G71825.docdoc 09e2673e664ad716ca50798fa70dd206fed9e2124f3245368ec4184436fed6d6Virustotal results 33.33% Heodo
2019-12-124L94DLYJ0OMF6KV.docdoc 9807713eef9ac31e93927eea37306b5adb7d2e157c3456609761b04172199e3cVirustotal results 33.90% 
2019-12-12FILE_PI3631459264AN.docdoc 6c15e1f42e55df32b1f5f5ca6adb1c4bedfc94e9299ecfe5b002d3d2d26e6dc8Virustotal results 32.79% 
2019-12-12REP_85468390.docdoc cff32aabadb00a262da43020076071c2918d35ae60a189fea613041bad5711a0Virustotal results 30.00% Heodo
2019-12-12O_27289998.docdoc de6662c946d502bee251e2dabcd64f8c31f8a8f31898c3cce8cc80b78a138781Virustotal results 31.67% Heodo
2019-12-11NC_IUBL1L46UD.docdoc 9109c34eb16979c38a6aa2bebd742801259ca667f521533d14bbd20b193a3bdeVirustotal results 37.70% Heodo
2019-12-110432225417433257643332.docdoc 8c608970f8fd886700d5e2629d2d63ab5bf57939a2bd5ffe65bcad8e86738bd2n/a Heodo
2019-12-11REP_QZJ_120119_WXT_121119.docdoc 2f7dd66e97d56ae195b4ac8aa493d3730a49448ff27e92083687f4724f0493daVirustotal results 31.15% 
2019-12-103LHUPP3XT.docdoc 79980573c87918e781880976d396cf833f330ce4e2939f607a928df75e925503Virustotal results 29.03% Heodo
2019-12-10FILE_71953794.docdoc ff2610993c76b123af8cd144b9b21dc40732c30083b8d49efb40c42b840c24a1Virustotal results 30.00%