URLhaus Database

You are currently viewing the URLhaus database entry for https://elektrik51.ru/wp-admin/paclm/qtji23qvn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307160
URL: https://elektrik51.ru/wp-admin/paclm/qtji23qvn/
URL Status:Offline
Host: elektrik51.ru
Date added:2020-02-03 20:12:10 UTC
Last online:2020-03-24 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-03 20:14:02 UTC to abuse{at}ruweb[dot]net)
Takedown time:1 month, 20 days, 0 hours, 4 minutes Bad (down since 2020-03-24 20:18:33 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05M_8TDYY4EM8.docdoc 57eb57a55d7fe7c51d9a5658147f3504e9890a67231563160721924cc8894a19Virustotal results 27.87% Heodo
2020-02-05GFP_5Y3O4VJ.docdoc faedc21081745a1610af2e805463f2f03e4cde28994a053c89c45ef4857f6367Virustotal results 26.23% Heodo
2020-02-05DFM_020120_WCE_020520.docdoc 0743e291e37633881cb1e5f051f04ed6ad59a496e9a3c89c858d29627fc7bef2Virustotal results 28.33% Heodo
2020-02-05REP_2QUG7DSV031IPM.docdoc fcb570d8d855f669580ff9de27c85f2a0bcbf2563ea608b49f4bd44846e2fe4eVirustotal results 28.33% 
2020-02-05VV9366564572QK.docdoc e8172a18f6d7f0bd45a2e199d48ed24cba4c034a6268aa3312dfe6649a8b3c9aVirustotal results 28.33% Heodo
2020-02-05BAL_CGA_020120_DVN_020520.docdoc fb3a4f60f442a053e1d10374dfc474b43f272bfa864b86a07b64c3d449bc0566n/a 
2020-02-05INV_MIVRQV4AS872BHUD.rtfdocx 1c96dc2ca50755af8de45649f800c5bc8afe690dec831035e2c9c004447e2e63Virustotal results 35.94%
2020-02-05DOC_PO_02052020EX.docdoc 4a2206d2d4159ee6156bcae615a5a64d47680fd4a81a731122cb2efaf696e3a5Virustotal results 37.70% 
2020-02-05UVH_17487556.rtfdocx 40f1eaa7af43464dcc9011db3cbb5850b7306e873cb41410fa989b3f24e54812Virustotal results 36.51% Heodo
2020-02-05DOC_CFA_020120_PHR_020520.rtfdocx 16f4428608da80852d79b47755bee8fae77793ac1a89079190a004aef7675376n/a 
2020-02-05T_JZ4244738257UF.docdoc 679f8b9176955bad28be27b0fb4e17d959e8ae21f09f00aa516308fed55eb1ddVirustotal results 33.33% 
2020-02-05INV_11794048.docmdocx 8b5c629465d1e775ff08a64c17e15af3e0abedc77e2718bf8a7a700ed92c6b27Virustotal results 33.33% 
2020-02-05REP_VXM_020120_EUF_020520.docmdocx 93334a1d8242b60620644d3f16b4ab512e609bf7f63b0ba1dc5c5d2867748f84Virustotal results 32.79% 
2020-02-04L_RAD_020120_VBO_020520.docdoc 1a42a36453236c06c4592ff027a3a19d6ea01f10831412618104dac82de16ca1Virustotal results 32.26% Heodo
2020-02-04FILE_XL8129782179MB.rtfdocx d47c77d9d0def102dd934260114120e0bd5fd719e88480dda4a53342cc6701e0Virustotal results 31.75% Heodo
2020-02-04BAL_8GHYKR8P.docmdocx e7f9815f92e7cc94121a968c79606d06bac0b134593d51cf2defc641e1f34865Virustotal results 33.87% Heodo
2020-02-04FILE_LOC_020120_FHF_020420.rtfdocx 4a61bb6feeafc9168711f5de2e6d486132267d88a40ccd5dbeb5b5e41cd77189Virustotal results 35.48% 
2020-02-04REP_34420989.rtfdocx 6cf7056ab0ef95c3e0e7db2e9667532ca55ef9cd4b846c0bf1012328ee62dd7bVirustotal results 33.33% Heodo
2020-02-04INV_0BGUDHB8QU6DCV4.rtfdocx 10a4a79ef018d8594156fc6ad3dc14646fad3b07d661af9c687034c39dccf0a4n/a Heodo
2020-02-04DPFM_PO_02042020EX.docdoc 9a488725dd70310efcf93ffb12cdafec6afc75ec136bf91b5e3ecf1cd6ebc3ddVirustotal results 35.94% 
2020-02-04REP_996191190880282.docdoc 23b5a2d4a45010250ab641363a1188ba35bd619cb0135e3dd3ce645c9504774dVirustotal results 37.10% 
2020-02-04FILE_ES3427585395LZ.docmdocx f98ede027a5dea9db32a00632bbf77d91899875b2271ee9e7ccf7cac0cc2ace8n/a Heodo
2020-02-04F_PO_02042020EX.docdoc b6e927546375b3a3421f35d0c399db92beceaaf46b8981207a74ca9cb6782e21Virustotal results 35.94% Heodo
2020-02-04PO_02042020EX.docdoc ed6fe435d8858c9022bba057c44d5c167d0e3be265432ec2a6e6e7566a2b14b2Virustotal results 35.48% 
2020-02-03BAL_UQH_020120_ZXY_020320.docdoc 13ebd8cc80fe0d18140b6deec77af3ee048c4ad302fd2e43a804b2aa69529017n/a Heodo