URLhaus Database

You are currently viewing the URLhaus database entry for https://cdfairplayusa.com/wp-includes/Reporting/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415868
URL: https://cdfairplayusa.com/wp-includes/Reporting/
URL Status:Offline
Host: cdfairplayusa.com
Date added:2020-07-21 09:46:05 UTC
Last online:2020-07-23 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-21 09:48:05 UTC to abuse{at}a2hosting[dot]com)
Takedown time:2 days, 6 hours, 25 minutes Poor (down since 2020-07-23 16:13:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23INV_HI60VJDDD.docdoc ecfcada8131c01436ccd879656898e0c54347fc88b8e4c523fcfe2faa885cea5Virustotal results 43.33%Heodo
2020-07-21INV_UKM_070120_IBQ_072120.docdoc 974a9bde6fa374685e63b50d21dd8254256dd8f6418d9d65e208a465a0141f73Virustotal results 24.59% 
2020-07-21SDB_UUH6191DY.docdoc b4f865e3011a63a5b8a0da14876282d97d5144e153f8316025555d276602d335n/a Heodo
2020-07-21S5PBS0V8NML4TE6.docdoc 76f26be5906a8e19f05aaeb83beb7822cd9f6dff18f4b66782023d320e84c36bn/a 
2020-07-21INV_ET8366518601HS.docdoc 4501457e1fae31cb83a1d2818d169525f75627a017efc573932fd412e6e2c406Virustotal results 24.59% Heodo
2020-07-21G_AKU_070120_YIL_072120.docdoc b1a935c9a64f8a2191e613e696c6df7a5892c608ec14c6f72c3459c4a62f2865Virustotal results 25.42% Heodo
2020-07-21EAVF_HCGHBGIJZU4FAMEF.docdoc c1d1210982635dadb2f24475c235301c47a2929b5b3caa913ebdad6df34a0c71n/a 
2020-07-21IH2024219599AI.docdoc 2cccb5979a562d00936dba58168f63f56806a4013284bab9f2a8e84be5eee72eVirustotal results 24.56% 
2020-07-21FILE_IGP965PRR3I.docdoc 003110462b096556a9d96dca0472feaa2dee2edaf6d8d0e179dc08a8a8f2b775Virustotal results 23.73% Heodo
2020-07-21INV_RQK_070120_MZU_072120.docdoc 640aea29e90caac6bd6f05d019c7a032e67da6a1361f122e37707493f25df248Virustotal results 22.95% Heodo