URLhaus Database

You are currently viewing the URLhaus database entry for http://www.leonardoenergie.it/media/DOC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294016
URL: http://www.leonardoenergie.it/media/DOC/
URL Status:Offline
Host: www.leonardoenergie.it
Date added:2020-01-21 18:29:04 UTC
Last online:2020-01-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 18:30:04 UTC to abuse{at}oneandone[dot]net)
Takedown time:5 days, 14 hours, 2 minutes Bad (down since 2020-01-27 08:33:01 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-2377265754350.docdoc d4f1b135d2430ecc746f26bd913fc8d48042688545015a108dfab66a626f0231Virustotal results 32.26% Heodo
2020-01-23V_OY6972444295HB.docdoc 117f7b33ee4c808e1243a19d3ab8d42453e08025bace2d7c83380338b2536965Virustotal results 32.20% Heodo
2020-01-23REP_0358678776693250164696040.docdoc a7da95cc5af2d5b4e1d2b4e16f96007855b5783f4383c199878f2230aaf11453Virustotal results 32.26% Heodo
2020-01-23DOC_VBP_010120_OTG_012320.docdoc cf2fe16a0d0101749fa2ac31cb91adc8205d42581f02e0e908b59ac63022b42eVirustotal results 28.57% Heodo
2020-01-23ST_YB8623140135SD.docdoc c902819826aded735fa4ea8025d726e7b868dbee374343fde8e6b5a3fe6733e0Virustotal results 28.57% Heodo
2020-01-23PAY_PO_01232020EX.docdoc 57f80688fb69b44c38dc1526796d523074e95761263f1c762f83cbb491b369a6Virustotal results 28.57% Heodo
2020-01-22FILE_QR9K0JXEWGGKTX.docdoc 62fb677b5e795566ed8b06713d070488a08cffaccd527993f327cb931929ea2eVirustotal results 29.03% Heodo
2020-01-22B_92085076.docdoc dffb42ea57c043aca8e41355f4baf0ff45ec83654f981d6bd259c54e198fe28eVirustotal results 26.98% Heodo
2020-01-22M_2219EB4LLDRBS.docdoc 0fed8a6d0f31e05943d5e786c31313260f8187f838e8ee21b42c285e41df16cbVirustotal results 28.57% 
2020-01-22DOC_84221843.docdoc 9756dcc678b46451f83fdfda2c1b587c0c0ed23f343a60636bf2a41683f15f20Virustotal results 28.12% Heodo
2020-01-22IL5821484889EB.docdoc 029a4da66373c2d80f8fee96003625ebd06c2b83c393bef59b51c5393a4299d1Virustotal results 26.56% 
2020-01-22INV_AHX_010120_RFK_012220.docdoc a193e2f2fe4f55fa7c412e2bf224298e532479d7ad19ca82e0cc094876a9938fVirustotal results 26.56% 
2020-01-22FILE_RT3508493994QA.docdoc ab600b906dee873222585e34ad20f43a3eb8dbc281f88b10eac0e7ed4b8f6f8fVirustotal results 28.57% Heodo
2020-01-22REP_24347890.docdoc fe59a06ef130c4867a0157637787f5f27f438d47a80dc122e37af7b38c4c5d0aVirustotal results 32.26% Heodo
2020-01-22SW_QZP_010120_MUB_012220.docdoc b18ee7bab2367dfe0c69c571bcf87a1b22b78f302ac77bee61c0abbf6157d3beVirustotal results 32.26% Heodo
2020-01-22FILE_E8TOWO7B9W4VVNL.docdoc ebb3e82c46e200da1e1dce1ab9cd5fca846f0b54284f5dd3d879e05910038350Virustotal results 30.65% Heodo
2020-01-22RP_6284032182100185.docdoc 2e5f9f296d5addeabf6f8caa5e1e989363265c1ca3cba2201a933e734bcf8635n/a Heodo
2020-01-22INV_71576280.docdoc c4b215a59659e1c91fffadf971f2d9f6a0865a757e23c4ded707e894927c7837n/a Heodo
2020-01-22MZM_CF5854143737DL.docdoc 78ccf76669f5a2bee9b21435419ae9a674d35c1e68a75f44f943b9c71ba7c41dVirustotal results 26.23% Heodo
2020-01-22DOC_PO_01222020EX.docdoc 2060f7df174027271307cce5c7a8ec61c05546b084780a80186d00fc343a2b0fVirustotal results 27.87% Heodo
2020-01-22BAL_RHDZJJI.docdoc b62d1ee80d790d1c37f54508f9797ef7816b3d8f0461b78255604d1429667672Virustotal results 28.33% Heodo
2020-01-22FILE_09911703.docdoc a85351653bf9a0c8c76db9f4c1076418ba4fface5c3a7f373d29186bf46732e0n/a Heodo
2020-01-22ZF0741752567GK.docdoc 38787b38f9ed7908075086f02ec866791014775637c563d31e7926535cfad02eVirustotal results 20.97% Heodo
2020-01-22SW_PO_01222020EX.docdoc 4608dceeebae9faa5e9e2416bee85509b67e80af4422fb61baec34056ada48d8Virustotal results 20.97% Heodo
2020-01-22JBL_010120_PUS_012220.docdoc a0855eab3940a455dc8d9abb41fe9a44d09eb1153e79da6e813565d5dac82f24Virustotal results 19.67% Heodo
2020-01-22488811405829485890.docdoc 8bb40f94230c4779d38d4849765d3c668b37c66d257ecbf89fe76f042c850958Virustotal results 19.35% Heodo
2020-01-22DOC_WP0YB7ZR82QF4CSU.docdoc 6321d13c864a5af9a0a39e72120db0999714232489e7bf8461b8a795db19a222Virustotal results 19.67% Heodo
2020-01-21REP_36881618.docdoc 73ae92b67a773aeb211f7520d6d98ff0b4f01babd23ad51535129e1c09c78e97Virustotal results 21.31% 
2020-01-21REP_01529372836009231919368.docdoc afc71ff2f950fe201610ccb3658ecabd28277de445f299d235048e06bb3c02ben/a Heodo
2020-01-21BAL_MJ0N0QEA7F9AY82N.docdoc 4a5b9b9742ab79ec97f03a713d79186193ea89fbdce64cc486bdfeb117c7e7bfVirustotal results 19.67% Heodo
2020-01-21PAY_OI4950713424RQ.docdoc 1b7b6aadbc97da71c335724f63be656d8123a8ab1633f93a53e990242787660aVirustotal results 19.67% Heodo
2020-01-21INV_4238413531035131680.docdoc b27efe734620499ff72dafb2bd9cf0650ea42d6b08f670e80149d1a7087d4f51n/a Heodo
2020-01-21RP_MRB_010120_PQZ_012120.docdoc 12b9836506df01396c7e36e7646aeefb19efbaaf8d1e9353859a0d8bbcb90792n/a Heodo
2020-01-21REP_CIFDXF5L73PGB.docdoc 850a227a26caa8d810a76432900e0aa8cca0c4c1e8859d2c8d5a2e6b6dff4d32Virustotal results 19.67% Heodo