URLhaus Database

You are currently viewing the URLhaus database entry for http://erva.hu/sites/En/DOC/44999 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:34318
URL: http://erva.hu/sites/En/DOC/44999
URL Status:Offline
Host: erva.hu
Date added:2018-07-19 07:10:38 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-07-19 07:12:04 UTC to abuse{at}hetzner[dot]de)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-19MSD774610267_2018_07_19.docdoc 67d850f7e1f04113ed3210dc98ba706783e78e91fd891a7982368ad24fb621e4Virustotal results 26.67% Heodo
2018-07-19ZNP66475130_2018_07_19.docdoc 01b5aa2c79968d4889d5c1b9873b7b09ed7ebe482a6e8048682aeac92004814dn/a Heodo
2018-07-19SCM4772516286_2018_07_19.docdoc 4ce8645f7b108c81e137e971aa4b4ebb951dea8bece41e8f34593b1d20aebffcVirustotal results 26.67% Heodo
2018-07-19ZZO561692_2018_07_19.docdoc 372b41d276a0b59449b340c13c88a8f8a9c5e40ba28835e4de50f1a46ec6a882Virustotal results 23.73% Heodo
2018-07-19RZU37100_2018_07_19.docdoc 41ba16d7b5349c1a28471125c1ddfe3a2175b1b3539d43884a45e5761c493c69Virustotal results 20.69% Heodo
2018-07-19ZC34629_2018_07_19.docdoc 425f266cf6d445b73ba99731b8c25ee8b14886f53714f3f0874f154b1827b4ebVirustotal results 25.42% Heodo
2018-07-19FEG27688463299_2018_07_19.docdoc d0c62251872aa490426febca07c9bb79fc5ee686d6278953d1a40e36ae6e73b0n/a Heodo