URLhaus Database

You are currently viewing the URLhaus database entry for http://wildrabbitsalad.brenzdigital.com/zxs9h/au-43j-49107/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307662
URL: http://wildrabbitsalad.brenzdigital.com/zxs9h/au-43j-49107/
URL Status:Offline
Host: wildrabbitsalad.brenzdigital.com
Date added:2020-02-04 09:43:33 UTC
Last online:2020-02-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002295365 created on 2020-02-04 09:44:05 UTC)
Takedown time:6 days, 11 hours, 57 minutes Bad (down since 2020-02-10 21:41:44 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06Invoice_Z15_53800266.docdoc e861272916ce12fbacfbbdb46258fd79bef6e8245350dce8a03459ee5f471f84Virustotal results 21.67% Heodo
2020-02-06Inv-RLGT6711_8358127.docdoc fd7c8c6cf457d1d127ee24d40ea990ccae1f8f8e8c648e61c760124a04dd4941Virustotal results 22.95% Heodo
2020-02-06INVOICE_UM488_0954900.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06invoice_16_50152150.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06Invoice-Q1594_085039937.docdoc 9eca08bea00fec73f8bdc769abf28f857d39de7d922c4d0dfd4017dc5981d2b0Virustotal results 33.33% Heodo
2020-02-06Invoice GMKK9_064535.docdoc f64c7b18189347af96b402b6f3cb3294d4dbbc7cad63748805727ac4d2a83997n/a Heodo
2020-02-06Invoice-PHJ3345_229992329.docdoc a6f19dca43628c0760f4bc6d493a9607e9d9ab713610dbd09c19d7670ee49cb6Virustotal results 31.15% Heodo
2020-02-05Invoice-JS942_8357702.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05Inv-F17_933787.docdoc 0e3d06a5758a732dcaec9fbbc4fbab77b15796c873aba5aaca14e0f6a62b4b64Virustotal results 26.67% Heodo
2020-02-05Invoice_UWP51_669572648.docdoc 4152d52f1411482170163f5c1a548319cf7bf6b6e3b95a2d5dce87a21ef76708n/a 
2020-02-05invoice INLL719_0951637.docdoc 0730eae02471503c7ab9c5f470a916f7f1578c78676c2c401ecd562214e25d37n/a Heodo
2020-02-05invoice GNL9_870085642.docdoc 710cf49cc2e88e70dca61cf80d2b6fed3cc9da29c01dc5067cc97110df25ff96Virustotal results 26.67% Heodo
2020-02-05INVOICE-8192_596090.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05Invoice-V508_3700378.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05invoice-XX655_833719.docdoc 28d1b238f050e82f7e6bcc571b0ece1a23309e7cf54fd2eb77d1d79a021fbd8fVirustotal results 27.12% 
2020-02-05INVOICE_ESM8_730913.docdoc 3d86715a18dc19cdf1364d58ff7deee2c387cde502de5b43166a7c0d98b2a24an/a Heodo
2020-02-05Inv_R584_0866167.docdoc ee932045a6cc0928256f9fd9792fb685acd23e47fc4147eb4795a6e009be1942Virustotal results 27.12% Heodo
2020-02-05INVOICE 1953_18229055.docdoc fa5927f2181dbeaef9cab75616169a02fe02b41df92e598cabad444619c3befcVirustotal results 26.23% Heodo
2020-02-05invoice PRQ466_7185221.docdoc cd7205a871273f045d8ee2a8621fcd7dd7778e062e3598507c21ffb656752721Virustotal results 33.33% Heodo
2020-02-05Inv-STKZ4_35454428.docdoc 4cdac2f4d63304355834be949d3daa22b6de9607436c0f5cbe758f86c05c5b72Virustotal results 33.33% Heodo
2020-02-05Invoice_4_429693202.docdoc 471942cfd9aa93923bc0f054e64201217913ae24a3e192919207202918c628fcVirustotal results 32.26% Heodo
2020-02-05INVOICE_6961_79082018.docdoc b9d42e016bb94271c9d10c7c68d438ead1f0078d3b0fe039da3166ed9f29432eVirustotal results 41.27% Heodo
2020-02-05invoice VR2643_570184.docdoc 25d98e7b0341be2da85f8fbbe279863673a1b0744c9773c8f6bcaa0c0666c935Virustotal results 34.92% Heodo
2020-02-05invoice-26_60362316.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04Invoice-ZG7_607405661.docdoc c01faf044c1df797bde7ae50e931236add55e532401115f33435ad6802eeb184Virustotal results 33.87% Heodo
2020-02-04Inv-UXAY83_6724662.docdoc 0b2ca06ad6086c411fe61f2b5a791d8fa9336d920a8c39214db4c4b05e69a3acn/a Heodo
2020-02-04Inv_4_032523.docdoc 41aea47e36728ef17f91fb0ed0239001ef742699f4e187e54d4e107680725a5eVirustotal results 34.43% Heodo
2020-02-04Inv_FVGD9_87253655.docdoc 541462a915468b906df031ddc535d58ddb6851345a0cc9c8c5fa680f461b58dbVirustotal results 33.33% 
2020-02-04Invoice-8968_673170.docdoc cf00a0e13bdc326ecf08bd0238ee35c3600642133c7f84f69b0434aa63bfa291Virustotal results 33.33% Heodo
2020-02-04Invoice ZQ8_132264058.docdoc b4c3990e73035881f982534ee5ccc3a30f80b58c625e28b6f68067c223589fc1Virustotal results 31.75% Heodo
2020-02-04invoice-PLCD0817_849933673.docdoc 40c57139f9fe475f5e06542c48aac3476cd943f3530f73ef44a60db380bf9e04Virustotal results 38.10% Heodo
2020-02-04Invoice-4_0802411.docdoc 904f34e3a638e5d981f17dc0728844c41378c8b8ee1f9bb7e85b614af0478739Virustotal results 39.34% Heodo
2020-02-04Inv_QWA3980_000701580.docdoc b907ec5b6b7514a2c14d52221369c5441673bdf67fdd3087b8bb2bcf9a30b908Virustotal results 38.10% 
2020-02-04invoice-WCA5838_0553538.docdoc b38620f90ec6f200c3c194fb6ec3444c55f50151f4a47cd6ff0eba0bc12a03can/a Heodo
2020-02-04INVOICE_FU648_335330.docdoc 32205c6e3940af055c6164bb249b544737778db9e0ee965daf226efedfe861d7Virustotal results 37.70% Heodo
2020-02-04INVOICE-UD1_183953948.docdoc c6f67345d51de31d968f542885d815a518e46ae16c2629694893cceceb18ff3cn/a Heodo
2020-02-04Inv-WBG6281_4249376.docdoc 8e66d9957e16b357616a30285cc04951088836af1778c63ca72ed2f7f0b48f41Virustotal results 33.87% Heodo
2020-02-04Inv-SW798_690727242.docdoc b45964630d0e45fa203f7d8cce1f41590f621b681fbc266961e277b969e2b6c2Virustotal results 34.92% Heodo
2020-02-04Invoice_I188_056921.docdoc 85b5de1da7cb008aeb94d6e2c2dc37d1b39d5410028229118428060fa4d36d36Virustotal results 34.92%