URLhaus Database

You are currently viewing the URLhaus database entry for http://stayfitphysio.ca/wp-content/eTrac/bduizij7y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272127
URL: http://stayfitphysio.ca/wp-content/eTrac/bduizij7y/
URL Status:Offline
Host: stayfitphysio.ca
Date added:2019-12-18 22:39:05 UTC
Last online:2019-12-24 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-18 22:40:03 UTC to abuse{at}hetzner[dot]de)
Takedown time:5 days, 12 hours, 10 minutes Bad (down since 2019-12-24 10:50:52 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20OR7017971007TQ.docdoc d7a8ef9d0298ef9f91d22b8c22ad5d94a62f5266f0d0134dd66c0eae013d801cVirustotal results 35.48% Heodo
2019-12-20ST_9319049348204.docdoc 73e0e1bf7fcb823cfed34dd9fcd5ada1a006f8f0fc06b5e19bd581819cad12d6Virustotal results 32.79% Heodo
2019-12-20REP_5ZER1W1.docdoc ff44d7e57d982446732789b554c9013020210e60a893de71d4d1406bf054e8a8Virustotal results 29.03% Heodo
2019-12-20REP_54384183.docdoc 572a62274c754bdba9d275f4f613b632ebd558b826eabaf5182ac07de09ea80cVirustotal results 29.51% Heodo
2019-12-20SW_78251227.docdoc e8ac62a0e0e1eadff780cb1324a70ce03be311bb33d7c7bc69faddc1c7c2cb37Virustotal results 30.00% Heodo
2019-12-20I_967642196426804917946584.docdoc b046a2ba49a570e7aef80faec6efc50d4a8a1bb8cefa7563c2e424c5dff662c5Virustotal results 29.51% Heodo
2019-12-20DOC_0910838541188783719185.docdoc c19e4f9564e304e11d679ca37dc75ab35b3feb1f6e63df36add9dc12cc43e6baVirustotal results 27.87% Heodo
2019-12-20FILE_87001020004762528.docdoc 118c66d3e9b8ca9c08ffd48c868218db3fdd2eb2f4938b1d293e9e38c783182bVirustotal results 27.87% Heodo
2019-12-20PO_12202019EX.docdoc 8f62870ed7ba3a13c0f2552e3789de9221819090622393d8f689e7af17a42ebeVirustotal results 24.59% 
2019-12-20VT4171253913SM.docdoc b3a7213579f74c678d6fd8c9258ba534a06e009c01418ef2b4ceb40a2c85aed7Virustotal results 24.19% Heodo
2019-12-20ST_JRZ_120119_YTW_122019.docdoc e4bba0d01cbf6f796e53cffedf881a3285eff0426d344221ae144ac4cea10679Virustotal results 26.23% Heodo
2019-12-20ST_OX8044505791IV.docdoc 17cd2a4af3f45b3e45b10b4845fb6f7d07bd602e4d665d7a444a2e8505ad8817Virustotal results 25.81% 
2019-12-20FILE_KN0956381760WU.docdoc d3fd6f753f0bcd2229739ebe8d3f3670c2aa78d467b59bd782cb167daa41601bVirustotal results 36.07% Heodo
2019-12-20PAY_E0L8WBN.docdoc cfb0cbb56627739ba234e9269d51ffb4a8b5b96ecffef88cd1cd54dbb2230622Virustotal results 35.00% Heodo
2019-12-20INV_12446413.docdoc d4ba52d9d0bafa44d2f58ed37b6da8bb06cec304debfcded6063335cf8bcd452Virustotal results 31.15% Heodo
2019-12-20ST_4467794010631268790368.docdoc fecd749716a57e87ee47765a5c72b1a5c50fe8a8695a722aea8fa89537aeb30cVirustotal results 31.15% Heodo
2019-12-19INV_IG4MJ11QD40P7.docdoc 6826c59647d2f2f8b375cd6927990c2d49b7def8ef5ef3e9527de760c9c1e998Virustotal results 29.51% Heodo
2019-12-19YS_3258384075680740303143701.docdoc c7bfcf3bfc977d6c1d531a4130b95272b14fa81257fb70cab743b8437a731647Virustotal results 29.03% Heodo
2019-12-19LYWPP5QZ9MGUU.docdoc 993376fd645a2166d8334370bdb297ffd0cad9d79b562ffc9f9aa8daef5ba80aVirustotal results 29.03% Heodo
2019-12-1978688145056817174590552.docdoc 8bdd8549703961fea334d73b51eec33f047efce2f623f1ab43826595d7d0e5f2Virustotal results 31.15% 
2019-12-19FMJ_120119_UZC_121919.docdoc fe2df8c2f00264ad3e9114ed7ea45812d76bebdb5d780a5970aa559975a7ae4cVirustotal results 26.23% Heodo
2019-12-19FILE_KV3235471975AH.docdoc 7cb2aa92217f3090d559ea14541ffee7c4c4234cb1f7626ae797310c978928d1Virustotal results 25.81% 
2019-12-19SW_98411405.docdoc ca4b646ee0c1045fbbeab7b0af0f7ed8fbf605d06f98fe979fdd23ab8987699fVirustotal results 27.42% Heodo
2019-12-19D_487679223.docdoc 7c220378cb3994b0fc701621095ef8de8bce2fd46a87910fb0e228ed8e095d39Virustotal results 25.86% Heodo
2019-12-19BAL_29GKEH1IPRI6PIR2.docdoc 856db418ae86d091dbe54c6f710d19e8ea0da98981bb21d959bf50db97393154Virustotal results 28.57% Heodo
2019-12-19XRB_120119_DWJ_121919.docdoc 829263c831f1b2b0cec4218df826504150f2b0c15acb1a72e09300d5cf23c115Virustotal results 25.81% Heodo
2019-12-19ST_DCZ_120119_ICN_121919.docdoc 76ad8bda714caf5e9dfeaa9282b6022f72df193a5d34137933807c31dd31d473Virustotal results 22.95% Heodo
2019-12-19INV_38512426.docdoc ea8762cde8721bcd9d366dd2c0cae94ce0ec0f44a624b76335c464d49d368d96Virustotal results 22.58% Heodo
2019-12-19PAY_253ATTKJ5.docdoc 71f19dcc7fd3480cc2540137e1495b376eba753530886e1651bf8cbc12033153Virustotal results 22.95% Heodo
2019-12-19INV_MR3551498794EW.docdoc dfde887979e2a371477ada84d0cecb56737421b00cb048f0186ab16146f11fccVirustotal results 22.95% Heodo
2019-12-19DOC_4628736812263800209.docdoc 054ec81afedb1cfab322fcbe581c6b685348077a413e6d689a709a86328f6d01Virustotal results 20.97% Heodo
2019-12-19V_6804693264.docdoc dc19d868cbfccec6608b904b7220dd1384fe24e6137be714af752d6c5c86725fVirustotal results 31.15% Heodo
2019-12-19466802019555.docdoc ec2cbbdaa442e182f9375cf3860d8ec64897319a62aca277d9f3c2cc5005d888Virustotal results 31.15% 
2019-12-19INV_PO_12192019EX.docdoc eece617e68c6bd59cba0abfe3a92b1bd28f333ded755fdeecdf32aa5d9369d44Virustotal results 30.51% Heodo
2019-12-19L_PO_12192019EX.docdoc 5858055c94e91c3d9d3c04d19ec5f4b2e741b26353926166833f40ccf4e4373fVirustotal results 24.59% 
2019-12-19ST_72760466.docdoc 89a22bd587f2bc9df2709648106e06157480b6fb980ae4e779da1fc76038fa08Virustotal results 24.59% 
2019-12-18DOC_JE9230082186BN.docdoc 2f37a55acc32e7d59e31d6c98effdc3171e447d51f5aceea59451fe493461b9eVirustotal results 25.81% Heodo