URLhaus Database

You are currently viewing the URLhaus database entry for http://blog.sigma.la/wp-content/invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415500
URL: http://blog.sigma.la/wp-content/invoice/
URL Status:Offline
Host: blog.sigma.la
Date added:2020-07-20 20:08:04 UTC
Last online:2020-07-20 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 20:10:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 19 minutes Good (down since 2020-07-20 21:29:36 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-2058403672783990.docdoc c028e2c1213a4c43078359cb154f286208df885c287a011ff2a2f1f4e2115265n/a 
2020-07-20DPR_070120_GCD_072120.docdoc 4fdba539896383e37ec2383fb569df4f17395dd40115ba8caba62127b7ebe949Virustotal results 28.33% Heodo
2020-07-20BAL_17452796.docdoc a00bd0c41a60173a7d02bec198e21b3be8ce018289a2120a48b3cea32160de78n/a Heodo
2020-07-20FILE_TP5098640609ZB.docdoc 6f07729a0d38233363651ce3760f506ded756ffb5010218df70d03bba767e7d5Virustotal results 27.87%Heodo
2020-07-20TUKG_86991745.docdoc 021aa9ae780b058779de8a93eb224c78e1d856ebd0bf6a3de8810e1b20e88f7fVirustotal results 26.23% Heodo
2020-07-20U_DQI8DLQ.docdoc f479686dfc59c7e2cf8607ef958b067288d47d2de6a92db1b0c1268b9862f42bVirustotal results 27.42% 
2020-07-20YFU_070120_LFO_072020.docdoc 8895dd40aa0da4cf1f3087db7cb003067025c7baba71478699d849d2f419d172Virustotal results 27.12%