URLhaus Database

You are currently viewing the URLhaus database entry for http://genichesk.best/pnpze/abierto_zona/security_space/iSZuqo_48lpdKKsbt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303984
URL: http://genichesk.best/pnpze/abierto_zona/security_space/iSZuqo_48lpdKKsbt/
URL Status:Offline
Host: genichesk.best
Date added:2020-01-31 12:30:04 UTC
Last online:2020-02-01 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-31 12:32:02 UTC to network{at}abuse[dot]team)
Takedown time:1 day, 1 hours, 44 minutes Poor (down since 2020-02-01 14:16:18 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01facturacion_LQC44417.docdoc dda76af8d395dccbe545d1229617376570b747b0bacfe5582b646f42937eb732Virustotal results 38.10%Heodo
2020-02-01FACT_02012020.docdoc 98ded06497049dcada99b644c03debd4a78601917d8f6e91981708b92159c3efVirustotal results 38.10% Heodo
2020-01-31FCT_615n2q8nm507mn.docdoc 31aa38da5ba8618ab37972836e37ae1a9bfa63a2311c373625190e9aa1781f7cVirustotal results 31.25% Heodo
2020-01-31FCT-LL964487793-63610016135.docdoc 1e0d6b28c16c18d16624df7c9f21a67be46efc281b1d877b5c8d956267f7d775Virustotal results 20.31% Heodo
2020-01-31facturacion 35281.docdoc ef7f3b30b07821491e65d307e115e900200f91cfb16241e1432da4e7ea9a8236Virustotal results 20.31% Heodo