URLhaus Database

You are currently viewing the URLhaus database entry for https://fisipedia.com/ebi/lm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415484
URL: https://fisipedia.com/ebi/lm/
URL Status:Offline
Host: fisipedia.com
Date added:2020-07-20 19:28:05 UTC
Last online:2020-07-21 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 19:30:05 UTC to abuse{at}choopa[dot]com)
Takedown time:18 hours, 53 minutes Good (down since 2020-07-21 14:23:11 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21INV_OW6615274328MM.docdoc 610576af7dfbd57bc54cede047748ec6355fd2122f6820ee76c1ec17967126fbVirustotal results 27.87% Heodo
2020-07-2130441364.docdoc ced32d6bf400cc3bb59aa1929efa4c17228064153ca0615288fc1fefde35f11bVirustotal results 27.87% 
2020-07-2132093687.docdoc 9053508e8b2272bfa74c8eadba7ecd45a1db50cfb3aa841015dc626c3e13e85aVirustotal results 26.23% Heodo
2020-07-21BAL_94552979.docdoc 974a9bde6fa374685e63b50d21dd8254256dd8f6418d9d65e208a465a0141f73Virustotal results 24.59% 
2020-07-21DOC_YKIOKXMZTCCH.docdoc 8f5c9735c5189f1b809aba58ae06fa7432eaff2ca15ec97d918d82dc6082a69bVirustotal results 24.59% Heodo
2020-07-21IO5799229330YC.docdoc 281280ed257511ed8f8f2b291a83ce2978bc6e6f14c52ca9ce10540c70cf0605Virustotal results 24.19% Heodo
2020-07-21DOC_SM5578136047NC.docdoc a77f0d09a07d8f85b737d25216501b343e22c4e04a6f88b16dc1ab9ea1b2a222Virustotal results 25.00% 
2020-07-21INV_KK8XNAAHHG7.docdoc b1a935c9a64f8a2191e613e696c6df7a5892c608ec14c6f72c3459c4a62f2865Virustotal results 25.42% Heodo
2020-07-21U_OA5533217753UV.docdoc 3f65143957146edc136d123a62507f50497de812d31cf82785b88dc67c7f4792Virustotal results 22.95% Heodo
2020-07-21INV_08902753.docdoc 6ea128ea049d2ebacb539514c677bb05791d9844046f47e6e1e3dc783f2942fbVirustotal results 22.95%Heodo
2020-07-21REP_EA1224667613NB.docdoc 003110462b096556a9d96dca0472feaa2dee2edaf6d8d0e179dc08a8a8f2b775Virustotal results 23.73% Heodo
2020-07-21INV_RVX_070120_WTH_072120.docdoc 24008d212916e04542b1f308917ce152914fc98dea21a3ac690999db725ea0bcVirustotal results 22.95% 
2020-07-21BAL_6882777970963181.docdoc 9560e6e3b0d652ebeb93460213b2441adeda06783b641d59101d2cfe2c227307Virustotal results 22.95% Heodo
2020-07-21QW_9374758198.docdoc f2e0593ca696ec36f6b813e857b8fe6741252d7b65df42e5e16bb3c80bc7a90dn/a Heodo
2020-07-2187793241.docdoc 49e7f3d18db1b3402794fa15a11d36c41d2857d4a668834b6178d0c739e2f821Virustotal results 22.58% 
2020-07-21PO_07212020EX.docdoc 59e827ab690ebe0398ef2409db0e89fd63ebe9c9a198ed0cd9febc218813f6a1Virustotal results 22.03% Heodo
2020-07-21IFT_070120_HYI_072120.docdoc 2786a95d643bf9b6c90e2940c4387436c45e5bcd4f88746449713a6abdfb5c51n/a 
2020-07-2135159600658.docdoc 252e3f0055225fdaaf98be11f4b12f61d98b7311d4aa43aaf9cca4de02b07a26n/a 
2020-07-21INV_AMAZYEDW4BUTE5ZH.docdoc 660ff4d3124a99db58894556a3461eda17393ca94c27e075185e72536eb6735en/a Heodo
2020-07-218330004402433723812.docdoc fc2bb7719f33ff249113e3c05c4b2b6fdbc99190e250b3073295e271c553f0d0Virustotal results 32.26%Heodo
2020-07-21BAL_UTG_070120_NWU_072120.docdoc d604f20c04d25e448176ddfdf3e01865091590cdf5f2cd2c42eb9af7cf41c718Virustotal results 33.90% Heodo
2020-07-21FILE_QR9364940041MY.docdoc 53b9a409018adc25ac26a608d9fae417659211d8754dbf7f07c3e4710a026774Virustotal results 32.79% 
2020-07-21BAL_53553204.docdoc 6c9bab65f28ed13d572adc91a1af99d0862edc49891f2ffa643423c75a0cc4c7Virustotal results 30.00% 
2020-07-21INV_Z65YCKL28504L8.docdoc 41239e9448583b6a09ec8574d34295b254dec60348e219d0a1355467c3ab37a4n/a Heodo
2020-07-21BPW_070120_PZK_072120.docdoc b5956950d2004aceecfee887e4d5435b6d7cdc6d13a6655cb5d81a7f7425555dn/a Heodo
2020-07-21REP_GXU_070120_QQX_072120.docdoc c9d9cfb4d6f95d66b6480f5dfb60edf7b0c4581895b68dbf25a830f9006b2d3bVirustotal results 31.67% 
2020-07-21DOC_68817133760.docdoc 2c03fc75fe3490e41923ce263321de82aca6656dab7a4d95ce7334adf39a04b3n/a Heodo
2020-07-2101701972.docdoc d6c5ff0dea2cbabf074ec5c1f7ca759925d9f469a37d4265919edf2414c60d5bn/a 
2020-07-21PO_07212020EX.docdoc 9953004cdba2aa71a7552b41ec9b4718f1fcf03abe1589629ce524746cece259Virustotal results 30.65% 
2020-07-21SQ5860332659ML.docdoc 926e68ce8e0ae5b9d2e935c1fe517533b3dc8cb4aa2250b0fa6ec86af0d78220Virustotal results 27.42% 
2020-07-21BAL_XGZ_070120_DFH_072120.docdoc 74fdca7126b9d049956422f500ca2a0257fb7956f385a45c6b5c36230fd3a2a5Virustotal results 28.33% 
2020-07-21BAL_DJ0080330993GD.docdoc a6c8655af8c96aef402f4853f9c71b907adc45a533de7e3f9a9517aee1b43c0bn/a Heodo
2020-07-21FILE_SEC_070120_SYT_072120.docdoc 46e68edbdc3dd2b5e70179a93d4f788074fa29e649c64063f636ee4e37c42fbfVirustotal results 28.33% 
2020-07-21N_2TQS8296.docdoc 229710df49bb17b78fae2414fe4ff138609fdbbe410dc297f49d8b7bf10ad109n/a 
2020-07-21BAL_URB_070120_FTC_072120.docdoc cff09d732ea9fe1f128dc29bff9f5d5d8ff78ea22eadb52fa4b5b8d7c056928bVirustotal results 27.42% 
2020-07-20V_QC5816982299OE.docdoc 5ef34d47ef171a2b5cab01782a4a45d9a12f01d70dde381936b6975ca93dfad7n/a Heodo
2020-07-20LAG_070120_OIN_072120.docdoc f532fcd4387475d48960a5f0863e003f7eba0281354728bf832162a0ca5673fbn/a Heodo
2020-07-20DOC_PO_07212020EX.docdoc 49f90436f418a86b0f4e55e14bcf74793954cc90596ad08dfb6355a1e50a8f27n/a Heodo
2020-07-20MU9342950008BR.docdoc d94cea8ea634ed8d8de82348acb5c417260d48a0f2b559531624b67f776c660cn/a Heodo
2020-07-20INV_PS2536897522AN.docdoc 86dc2706e8cf0a78688e5a503d6e8db55275a7ec3de655ec33a9db2f6ffeef57Virustotal results 29.03% Heodo
2020-07-20INV_11497815.docdoc f073a991092d0dc2ca2d7308e64b58992ce0cb00fe5da928b65b58530c10e7a9n/a Heodo
2020-07-208034512305818395.docdoc 4ec7f2a0359b740dbbc849705f2856818bccc8fafa5a2237fd79640e61423255Virustotal results 27.42% 
2020-07-20V_NV7538598864QQ.docdoc a6ce3b9c522d36ac4e91cf8e2cf1581bc9d7e6548f1e66ff998e11662f6894cbn/aHeodo
2020-07-2017418141.docdoc 148aa06dceabdc99c7588bd48277867f3d0528fcf04463562707fd66f953045dVirustotal results 27.42% ZLoader
2020-07-20Z_OO4289607049NF.docdoc d076c294bf588b7c9f8db6b5f35a63758c5710feb5920c263ceb77a501bb9133Virustotal results 27.87% Heodo
2020-07-20BAL_110849363880.docdoc cfb6588d9181a97aa1f93b2b9f8af82134836e916938a80a217cd03fe4294811n/a Heodo
2020-07-20AAF_070120_EMD_072120.docdoc 401dadd7c1211dae181b8767949d274790aa4fb72e78a3d57ae92ac2cf925da8Virustotal results 27.87% 
2020-07-20UR3877449499CH.docdoc 8163146178e6d55057843fa5f0da1b851d049bf802aea69b44aaec7352be33d4n/a Heodo
2020-07-20TUOF_14992068.docdoc 33c897cc3c1d11687231644af13032e24358c594f4b484a7040a3eeecfae7145Virustotal results 27.87% 
2020-07-20JW_05679553.docdoc 0acf607beb7b1d944c892c27acd49b254a36f39059812903c9d8bcde71acc6e5Virustotal results 27.42% 
2020-07-20L_GES_070120_BKK_072020.docdoc 70fd23e6a829661f7fe775e5b73c20b09a4dbeb5b97648d0851dde0591a3b304n/a Heodo
2020-07-20ZX_PO_07202020EX.docdoc 8811f4498f1b1d8729556a61a5683ce20c4270a64ee5ad0223185110adac5f2cn/a Heodo
2020-07-20X_PO_07202020EX.docdoc f479686dfc59c7e2cf8607ef958b067288d47d2de6a92db1b0c1268b9862f42bVirustotal results 27.42% 
2020-07-20P_PO_07202020EX.docdoc 69167697c3c077b3ca6449ae55750d1712c20bc33196537fdbbe05e463aab195Virustotal results 27.42% 
2020-07-20DOC_TNH_070120_DKU_072020.docdoc 1e146c18d65265b27e23f9ee84a8f1d20c046aa76c30ed386710a10cb0da2960Virustotal results 27.87% 
2020-07-20PO_07202020EX.docdoc 9ea223e9251e17c155c00e320f9f1008c6872573da7a16d524213225ebec9addn/a Heodo