URLhaus Database

You are currently viewing the URLhaus database entry for http://luizazan.ro/wp-admin/common-section/special-yef7mqop22s-p88iisexhyib/906j-419s84v3z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290402
URL: http://luizazan.ro/wp-admin/common-section/special-yef7mqop22s-p88iisexhyib/906j-419s84v3z/
URL Status:Offline
Host: luizazan.ro
Date added:2020-01-16 22:36:05 UTC
Last online:2020-01-17 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 22:38:02 UTC to abuse{at}xservers[dot]ro)
Takedown time:8 hours, 51 minutes Good (down since 2020-01-17 07:29:13 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17847573-5594753691.docdoc c5a39e53a413699b4b2b145e631810d46fa5d66b2bac69c770f15535d3f2461bn/a Heodo
2020-01-178952.docdoc c337f30bb0849f7809a7492b21ac4096beb20d982dd2080d1879c14cd84cd617Virustotal results 41.94% Heodo
2020-01-17Untitled 30956.docdoc baff02e524a1dc5e3aa3c7d79cd378bc8c858c899d1e25e75b0c13bfcbeb48feVirustotal results 40.98% Heodo
2020-01-175137458324_5660.docdoc 50fe680f097aa4650da00941e37bf14bd1161820465c26b782073eb65052af9en/a Heodo
2020-01-17Attachment 2869107.docdoc 49a2ab600f53f77b09bf90962731f7559940c6dba4c5151d67ff9bd581082d9en/a Heodo
2020-01-168212183188_574235.docdoc f942462b771aaec7fb9e1bb8fc3eeeed0fa6c2b229eb6950b8135afa16403305Virustotal results 37.10% Heodo
2020-01-16UNTITLED 937383-0580423.docdoc 27e17b9c3166037ca7a0ef95edd730b94093f613c95f62a4e7b5bfdbedd9507cn/a Heodo