URLhaus Database

You are currently viewing the URLhaus database entry for https://wefixit-lb.com/wp-content/uploads/935213/d-577715-4838-7f8q0re-l4h0l/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294271
URL: https://wefixit-lb.com/wp-content/uploads/935213/d-577715-4838-7f8q0re-l4h0l/
URL Status:Offline
Host: wefixit-lb.com
Date added:2020-01-22 00:05:35 UTC
Last online:2020-01-27 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-22 10:38:03 UTC to abuse{at}ovh[dot]net)
Takedown time:5 days, 2 hours, 11 minutes Bad (down since 2020-01-27 12:49:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24M_44285572211324950201675.docdoc d3d298dbad1c561a71b6a7ae1a91e23ab96c945dbb2a35a71fa7e811078d7180Virustotal results 38.10% Heodo
2020-01-23DIA_010120_MRZ_012420.docdoc 0722f8049954458b37f5abac8260f73b904d3cc22b749cd8f17136ce6640de34Virustotal results 36.51% Heodo
2020-01-2324737306.docdoc 4762e1b6ca5cf30d435752cbb3c8eb3eb711463b0c11a016cf91eed941662386Virustotal results 33.33% Heodo
2020-01-23T_NT6NBY0.docdoc d744c1d20947939b65a0dfa826e7b011a996521e9aea99c7a6be5531639e82eaVirustotal results 26.98% 
2020-01-23BAL_9741739657829887512441.docdoc 3dddeb95fb091ba145a2b0705117b8ecefdcf833024674c193dbe2ccbc4c6bd4Virustotal results 20.63% Heodo
2020-01-23INV_35761858.docdoc 79950a40bf62dac08fd1adbb9c8aba2b8db0e05de9829d485ac3a51302d546a8Virustotal results 20.97% Heodo
2020-01-23INV_5644277880.docdoc 87375ae81a73bb3dc7f704b3e7e62e3e496b286fa24c145831637953f4bcd132Virustotal results 20.97% Heodo
2020-01-23J_49887928206350.docdoc 627970068806ee557b861c46c5f66f04f0985ad9caddd21dc3c8e4682108042dVirustotal results 22.22% Heodo
2020-01-23REP_ZJL_010120_KNV_012320.docdoc e50ca42cece8459c5ed1bf0713f580775a5bea5fd9384b1e5f284e52f2db08b1Virustotal results 20.97% Heodo
2020-01-23INV_77066019.docdoc 647d83a51dd9ca30738eb1e94de185675904e4174b6b346c3f56ce55599a5c00Virustotal results 26.56% Heodo
2020-01-22SW_PO_01222020EX.docdoc 074ec6f9a2776114bc1d9e2da2250b73417843b3357ada6f17a5f4b606ab9a91Virustotal results 31.15% Heodo
2020-01-22ST_PO_01222020EX.docdoc 5be3e93b04906a447233525f99dffcce0d42f3559aa4ecfb866c92b5fc7f6671n/a Heodo
2020-01-22FILE_54RSP2FW4SSY45M.docdoc a8e86ce1edef7bad9f725d8f9b127d50d0a80a4e3477a2294f61bd2be001bfc7Virustotal results 31.75% Heodo
2020-01-22RP_05619184.docdoc 2e5f9f296d5addeabf6f8caa5e1e989363265c1ca3cba2201a933e734bcf8635n/a Heodo
2020-01-22S_93492464.docdoc 37c38ddcfc7b9753b05b5653bd7ff4cc3a03afc44f87dc46f5ca51813252637cVirustotal results 25.00% Heodo