URLhaus Database

You are currently viewing the URLhaus database entry for http://maservisni.eu/zipimport/sites/0xlh3ow9sqes/q2hfk-05961455-10056287-mp45tcd81i-tbte2bm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290450
URL: http://maservisni.eu/zipimport/sites/0xlh3ow9sqes/q2hfk-05961455-10056287-mp45tcd81i-tbte2bm/
URL Status:Offline
Host: maservisni.eu
Date added:2020-01-16 23:26:10 UTC
Last online:2020-01-17 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 23:28:04 UTC to abuse{at}svethostingu[dot]cz)
Takedown time:9 hours, 15 minutes Good (down since 2020-01-17 08:43:12 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17SPFIGYJQ2.docdoc 01803cd4cad276de7bde227f5eac222a512d1cdc85252fc4c34d23c36296fb05Virustotal results 20.83% Heodo
2020-01-1705371276.docdoc b5ac425bbd42f1b2ed152ff5780b068beed93876115fb53c98f459235d0543acVirustotal results 41.94% Heodo
2020-01-17RP_01318568.docdoc cab5a457395c329bad38f329fe4d098cc23a094dd70ab7f4af0d5a34f6643349Virustotal results 41.94% Heodo
2020-01-17ST_AK1096926434YA.docdoc 534d37a11e695ad6fd5b23ac1a8cb87571a5865e5651f954e3fefbf355ac737aVirustotal results 40.32% Heodo
2020-01-17SW_021443906356.docdoc ab93bc28a4a2dba3db6e1c25750476a6691de8988744db041f23d9d5c16e03a5Virustotal results 37.70% Heodo
2020-01-17DOC_LX1162465675YE.docdoc 2ef30359fa19b8295e05830296af78c6c2326d58fa4425b89cc5fad87b12cd45n/a Heodo
2020-01-16ST_48522054.docdoc 6ee6672922a39e1823a595982b95e4a7eb1ef427499ef320bbb747464f562b92Virustotal results 37.10%