URLhaus Database

You are currently viewing the URLhaus database entry for http://aviationinsiderjobs.com/wp-includes/closed_box/special_xFQQ_dQzrQmiGy6/95090475_FxxBPYQzPwe2dH1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273605
URL: http://aviationinsiderjobs.com/wp-includes/closed_box/special_xFQQ_dQzrQmiGy6/95090475_FxxBPYQzPwe2dH1/
URL Status:Offline
Host: aviationinsiderjobs.com
Date added:2019-12-20 04:50:03 UTC
Last online:2019-12-20 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002189424 created on 2019-12-20 04:52:06 UTC)
Takedown time:17 hours, 6 minutes Good (down since 2019-12-20 21:58:57 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20p015807no8.docdoc 0a430db8f97c853692ab17929306a7a3ac9523448c878e51c0fe7a1665833f24Virustotal results 27.87% 
2019-12-20last release-HCP190087007863-605553921202.docdoc 109da0381499feaa9d9bfa202a146781bc1777476841f0c5847015f7a6fa92c5Virustotal results 32.79% Heodo
2019-12-20adjusted-statement_12202019.docdoc d4695b412365970f3061a9b994950dfe0309bb4c7bcbdc99c384c02026faa1d7Virustotal results 29.51% Heodo
2019-12-20approved-adjustment_ABB35653923.docdoc e10256aa8460c9c6df046fee0c72c6d41130ea4ff241d3f85eb707d89b812225Virustotal results 28.33% 
2019-12-20release 12_20_2019_86E110763832.docdoc 889a682dbc3d28cad3bef8dccaf916c1076c8380ad56c008992ecf7baf32d354Virustotal results 25.81% Heodo
2019-12-20Christmaswishes.docdoc e2793baa07cbda28507c9b8e423e2506a34527d3af97f22589a23b3b7a7d7cbaVirustotal results 26.67% Heodo
2019-12-20last_rep_12_20_2019_H20516.docdoc dc98644b4039cf69b3aeca3e755ea9380f66cc906fe23126044154fd4655be53n/a Heodo
2019-12-20adjustment-12202019.docdoc 5ff89563f185b55eb05da2f55cf8749cc90c65780af138ab2f4e317a40b8b138Virustotal results 22.92% Heodo
2019-12-20final doc 12202019.docdoc 4fa69a6e2bd147fed055ce29ac3da808c8b02490daedce960863bf3bb908105eVirustotal results 23.33% 
2019-12-20I6C19274.docdoc db1b7614f7990cf6a79141f12cb65d47eae15099ee14be39f8cfee9872b1bd02Virustotal results 22.58% Heodo
2019-12-20relevant 08omq97pp7382.docdoc e7f3d38e909a25fe37d40452a07b925e8777c017e1a9cfb65b8a637c14f37bdeVirustotal results 38.33% 
2019-12-20adjusted-original 12202019.docdoc f2c96c17e9d5ddcc9566bed87b8f102d64e68b1b1482eaddee95106f34a53029Virustotal results 36.67% 
2019-12-20adjusted_16q604pp.docdoc 6e5072f64657ec476491b85f1522366eb46e5b23dac47259abe2bd34a2e7e5f6Virustotal results 33.87% Heodo