URLhaus Database

You are currently viewing the URLhaus database entry for https://elriasztok.hu/s/INC/7o5uf2ypt/j-78533-3886930-6wvp3q9f9w-3qj5h6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293508
URL: https://elriasztok.hu/s/INC/7o5uf2ypt/j-78533-3886930-6wvp3q9f9w-3qj5h6/
URL Status:Offline
Host: elriasztok.hu
Date added:2020-01-21 11:03:04 UTC
Last online:2020-01-22 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 11:04:05 UTC to abuse{at}ezit[dot]hu)
Takedown time:23 hours, 2 minutes Good (down since 2020-01-22 10:06:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-22ST_WRL_010120_QLI_012220.docdoc 92be2fcb2aad1eb1092c46edfe912f2eff9f197ec751c16ddb0c22e034aa2ee3Virustotal results 19.67% Heodo
2020-01-22INV_2162376487214598998535180.docdoc 4608dceeebae9faa5e9e2416bee85509b67e80af4422fb61baec34056ada48d8Virustotal results 20.97% Heodo
2020-01-22DOC_7122814064712683609296344.docdoc a0855eab3940a455dc8d9abb41fe9a44d09eb1153e79da6e813565d5dac82f24Virustotal results 19.67% Heodo
2020-01-22REP_48624440.docdoc 8bb40f94230c4779d38d4849765d3c668b37c66d257ecbf89fe76f042c850958Virustotal results 19.35% Heodo
2020-01-22INV_70467304688172185954246.docdoc 6321d13c864a5af9a0a39e72120db0999714232489e7bf8461b8a795db19a222Virustotal results 19.67% Heodo
2020-01-21PAY_JUA_010120_IKI_012220.docdoc e7cfcc5924207c0384febd2ca4125ab12dc6c893443adf4fecf44f056f3e243cn/a Heodo
2020-01-21WX3088741776MQ.docdoc b5d3d28c7cf031aca9149a40e293973df4908b797894f03fbcb558fb2c7878c4Virustotal results 19.67% Heodo
2020-01-21ST_57639333.docdoc 4a5b9b9742ab79ec97f03a713d79186193ea89fbdce64cc486bdfeb117c7e7bfVirustotal results 19.67% Heodo
2020-01-21PAY_PO_01212020EX.docdoc 1b7b6aadbc97da71c335724f63be656d8123a8ab1633f93a53e990242787660aVirustotal results 19.67% Heodo
2020-01-21W_YE6360526935EJ.docdoc b27efe734620499ff72dafb2bd9cf0650ea42d6b08f670e80149d1a7087d4f51Virustotal results 19.67% Heodo
2020-01-21ST_58630982337571267887.docdoc 0ba2bc2d8ddd7c95e3a17870d34c390e31968ea645b5ca3c5978da28719eeb99Virustotal results 19.35% Heodo
2020-01-21FILE_ILL4AZSCR3OK.docdoc 0ac7a98f0bbf451a51cb75aa5b065d00e46c0860c7cd1c90a194e8a40a56aa93Virustotal results 19.67% Heodo
2020-01-21BAL_BD9657941550MD.docdoc 2f2a0cf5f701e2014ef05a565aab080235be85106bd630e67bb5c9e1aabefad5Virustotal results 20.97% Heodo
2020-01-21DOC_DQF_010120_HGR_012120.docdoc f8cd0ec825c89fdfbdcebefa1756132a3f4d14e798d4b8f1833de4b6db4eeb91n/a Heodo
2020-01-21DOC_22FEIO17G4JUQDO.docdoc 3fd7f5dcc627af3f5f832b508d626dfa8691089e643a00c47c88bc2fe760fb23Virustotal results 23.81% Heodo
2020-01-21ST_947165877381774.docdoc dfe2815ab27e806aa38d3a86f0c43e7aa9fca4b580604411f1d339c734d038e3Virustotal results 24.59% Heodo
2020-01-21PO_01212020EX.docdoc f17aecacb4c59bf2959bded698efef9d09011deaa526b24352fab366fa66dcf1n/a Heodo
2020-01-21L_HXR_010120_EGY_012120.docdoc 5e98531907cc57e4b1fa31b9808e8349d25ccb173af389776484b6e12e0bda7fVirustotal results 22.95% Heodo