URLhaus Database

You are currently viewing the URLhaus database entry for http://praxismall.com/wp-content/lPWCDbB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294976
URL: http://praxismall.com/wp-content/lPWCDbB/
URL Status:Offline
Host: praxismall.com
Date added:2020-01-22 15:37:07 UTC
Last online:2020-02-03 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-22 15:38:03 UTC to usmanisppvtltd{at}gmail[dot]com)
Takedown time:12 days, 5 hours, 40 minutes Bad (down since 2020-02-03 21:18:43 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24invoice-B19_7576779.docdoc 7dd53825b5d2ade36c33feb1492c3e52cd0a331948cbdb102e2098dbe2811560Virustotal results 25.81% Heodo
2020-01-24Inv-0_3226281.docdoc cf96496533c1dcd4605ebd554b8b34f756a470fa7aef1daed4b803ec64eda8f8Virustotal results 28.57% Heodo
2020-01-24Invoice_O883_722121258.docdoc 208a5a77bd5f9b43ebe1340beb7d0934e43d8f99c0b1df3451beb95e46bc2e7aVirustotal results 27.42% 
2020-01-23Inv_JNYE689_725100.docdoc 15b199f8ba35174c6082d599128c694edaf953347bc41c55212437e09f16f741Virustotal results 32.26% Heodo
2020-01-23invoice_GZO2_2786451.docdoc 7277e36560a048fc265784737613943bf13a30a15dbd425da9b8ceaab4d621efVirustotal results 33.87% 
2020-01-23Inv-LYO3_808101105.docdoc ab2546eb670ced89bcd1304b6c5477134265bbe2c08a37d2f7834597e74e9352Virustotal results 27.87% Heodo
2020-01-23Inv-GSA33_23049375.docdoc 343354c5822df99e96d6b88dc7da718785a030ba68942f8cb71584e3ddeb78e5Virustotal results 26.98% Heodo
2020-01-23Inv-DPVU6220_515338.docdoc f8a99bfbf6c324f6f76f07ae81630edabaf926a75bc2bc290abeb01d910b9a67Virustotal results 27.42% Heodo
2020-01-23invoice_WRHR6128_385941.docdoc c72dd27b499d4dea90b30a82818446418aa2fe8c1cfade8a1912d1e757a4204aVirustotal results 33.87% Heodo
2020-01-23invoice 4278_324169336.docdoc 5bf2cbdf94878b3405e8c580187b746bcfd2ca98c5350d2da89676d12347d1dcVirustotal results 22.95% Heodo
2020-01-23INVOICE-1909_20457496.docdoc f28efd022a443c710b7a21451f86673fc1f60b1d4c7a49de6f52297edb24cb26n/a Heodo
2020-01-23INVOICE-WQI0_031081259.docdoc 122db4faf80cb4bdc3aa095fb489172b079832154b7ca87a3d8f00cfd58be47eVirustotal results 22.22% Heodo
2020-01-22Invoice 1253_10766454.docdoc e82adc98fcfdb46771178d4b4aa4d672a9cb7e6250ca4d87db04c9190ab00d23Virustotal results 28.12% Heodo
2020-01-22invoice-BABO63_9366089.docdoc 3c1cc64c9babf45acdb186c3dc9689517fefa31918bdd47faf8e17878f2e43e4Virustotal results 28.57% Heodo
2020-01-22Invoice O400_855651.docdoc f3d0f1bfe76e8a822d17bd917aed62d45fa8202d1906566abf7eee43e2881994Virustotal results 27.42% Heodo
2020-01-22invoice-2882_32545121.docdoc 6318e663d8ed1530d52e0a3770b033d00fe037533ccf2e5a56e9f36a7eb28653Virustotal results 29.23% 
2020-01-22INVOICE-DM319_3320438.docdoc 8f939f8f7ffcd34c5770c7e0e4ad5e5402e962f96d6ff6483bcf57dea191f0e1Virustotal results 29.03% Heodo
2020-01-22Inv-O3565_470795.docdoc 16112020679773b9c2682048a4b732027ed06037bd4cfb25b7f7fcf10ea2565dVirustotal results 25.40% Heodo