URLhaus Database

You are currently viewing the URLhaus database entry for http://xn--80aanufcfzcs6l.xn--p1ai/wp-content/uploads/9y95-xx2-66/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308504
URL: http://xn--80aanufcfzcs6l.xn--p1ai/wp-content/uploads/9y95-xx2-66/
URL Status:Offline
Host: рекламаплюс.рф
Date added:2020-02-04 23:13:03 UTC
Last online:2020-03-10 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 23:14:02 UTC to abuse{at}reg[dot]ru)
Takedown time:1 month, 4 days, 13 hours, 16 minutes Bad (down since 2020-03-10 12:30:17 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-13Invoice-KGXG9104_3081551.docdoc 9766b67ed693ef45b3c96e8eb73f9b13a463ae17929f7d87aa010647a8c4d555Virustotal results 54.84% 
2020-02-05invoice-BLKE5_72475375.docdoc 23bfb58c53002a4c03a4931e057316564e8ccab64975f93e2d66ceca6c73f7afn/a Heodo
2020-02-05Invoice TO5738_708624.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05Invoice-P009_192817975.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05invoice KT65_898108976.docdoc 9a6d2baf1a6f63a692b3584aecb501ab9d2c4cf6cc5e97ed5390454ec60bc466Virustotal results 26.23% Heodo
2020-02-05INVOICE 2_949662625.docdoc a2de78a3a39c2c5d3d3c617de7f83a6ee2ba59eeb411de1095a208d4b21ecffen/a Heodo
2020-02-05Inv-JFN756_636139.docdoc bac64a981e3fddb119868ac4b6c14005db9b3c64f608849911d6c08947267dcan/a Heodo
2020-02-05invoice-X2031_901727513.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05INVOICE_D2181_795769829.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05Invoice-MB84_174740696.docdoc 927609b9f9efb576a2233015595d50cfecd6d736c6fda23e8742330c6051e64cVirustotal results 25.81% Heodo
2020-02-05Invoice_BV10_834841.docdoc 3d86715a18dc19cdf1364d58ff7deee2c387cde502de5b43166a7c0d98b2a24an/a Heodo
2020-02-05invoice-926_197959.docdoc dc0402b2e8b444ac6695dd0686b697822b5c339fb556f63aaf4cb4dce9354572Virustotal results 27.12% Heodo
2020-02-05Invoice-514_39394273.docdoc fa5927f2181dbeaef9cab75616169a02fe02b41df92e598cabad444619c3befcVirustotal results 26.23% Heodo
2020-02-05INVOICE-Q4_285485.docdoc 6e6b6b51d4a9dd7f74e82c53490f95ead4a4d2a9a4adb06f1cbd991bc2b225a7Virustotal results 33.33% Heodo
2020-02-05invoice VYPQ3_265761.docdoc 4cdac2f4d63304355834be949d3daa22b6de9607436c0f5cbe758f86c05c5b72Virustotal results 33.33% Heodo
2020-02-05Invoice-AA9_163826584.docdoc 471942cfd9aa93923bc0f054e64201217913ae24a3e192919207202918c628fcVirustotal results 32.26% Heodo
2020-02-05Inv HEZ4_98606196.docdoc b9d42e016bb94271c9d10c7c68d438ead1f0078d3b0fe039da3166ed9f29432eVirustotal results 41.27% Heodo
2020-02-05INVOICE-1_8464910.docdoc 4887e700c4997ddaab9733c0dc0696a27e93eb2c02e2839119c077c2b92fd2d6Virustotal results 34.92% 
2020-02-05Invoice-41_8560568.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04INVOICE-F714_4579400.docdoc 53f5f987926ff0274559f310cd6f0893486a7b4107168dd570591b6b429fc2acn/a Heodo
2020-02-04invoice-AQST06_2712619.docdoc 0b2ca06ad6086c411fe61f2b5a791d8fa9336d920a8c39214db4c4b05e69a3acn/a Heodo