URLhaus Database

You are currently viewing the URLhaus database entry for http://crab888.com/wp-content/Scan/dff6vtd2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273269
URL: http://crab888.com/wp-content/Scan/dff6vtd2/
URL Status:Offline
Host: crab888.com
Date added:2019-12-19 20:49:07 UTC
Last online:2019-12-25 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-19 20:50:04 UTC to hostmaster{at}twnic[dot]net[dot]tw)
Takedown time:5 days, 18 hours, 47 minutes Bad (down since 2019-12-25 15:37:41 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20REP_PO_12202019EX.docdoc 92a12f73f11db98a80600a5deefbf75ba072febc23da2527d9631633c34c4a3bVirustotal results 31.15% 
2019-12-20FILE_JU2268141240IY.docdoc df5a61979c588234e81bff857f2d437d05f484de63a4ba77b2f425709fbe4fbeVirustotal results 31.15% Heodo
2019-12-195GS3J8NZ99JGBJI.docdoc db9c24d60e35b197741ade1553584eb831f3ac5cd6515bbd62dc5a8b76ff192cVirustotal results 29.03% 
2019-12-19BAL_ROY_120119_LUD_121919.docdoc 000abb794cc3213567efcac70a36e3efe2e5b29a22083fa4c683be4d14cfdaebn/a Heodo
2019-12-19SW_RY3980684086EE.docdoc 7a2ed8fa46f8f6c6f5ebfad8d9b345a5a4dd4e8f65d8e416f2a88faa6d17d327Virustotal results 30.51%