URLhaus Database

You are currently viewing the URLhaus database entry for http://eifili.com/wp-content/aWKMvu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:416216
URL: http://eifili.com/wp-content/aWKMvu/
URL Status:Offline
Host: eifili.com
Date added:2020-07-21 18:57:10 UTC
Last online:2020-07-22 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-21 18:58:18 UTC to abuse{at}sondercloud[dot]com)
Takedown time:5 hours, 44 minutes Good (down since 2020-07-22 00:42:19 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22Invoice K54_015583629.docdoc 85f96e5cf282786ef803c7c7886284d3225a9daeecc04ce3b8e5bbd143a3e0abVirustotal results 25.81% 
2020-07-22INVOICE-W6_18199001.docdoc 7476dba24b28d2a074d7e75aea79591f98fbb95b065c91870b5a8198ab615f19Virustotal results 26.23% 
2020-07-22Invoice-M48_827121464.docdoc ee7974d011582b83c0464f15d86e55b3306961023b16ed3c195c6c1953ea5835Virustotal results 26.23%ZLoader
2020-07-21Inv_O19_1971442.docdoc d1fe2bcc5439caf2963c2bcf85af9c8b8d4451abbc4675be82a33bf97ca81f18n/aHeodo
2020-07-21INVOICE HYVM4440_1497759.docdoc 599ef65639238b841a852f756d71b9d44c5e02b6d151b6941b95c94b5e8eaf64n/a ZLoader
2020-07-21Inv-N35_793327.docdoc 112aa4be04d85780875343365b40f2fe9351e69dd4756d26a01f923251e17a49Virustotal results 25.81% 
2020-07-21invoice_X5793_211905.docdoc bdebdf81b9c2645e41964a4d14720c68258ea89382b1cee103369b6fb9a77103Virustotal results 26.23% ZLoader
2020-07-21invoice_UNZV3003_073969.docdoc 74a3c90f0a3c99e8816a94689a4cac44f886be61e0dc3f6d324a661c16c663f9Virustotal results 26.23% ZLoader
2020-07-21INVOICE_U3_940879174.docdoc 9c3f1dbdddf1aea861852243a66b3795d0cbf86a1ee36fb372505a839db31540Virustotal results 26.23% ZLoader
2020-07-21invoice-RYG655_70600790.docdoc 3bebcaf546b7a6b80b7d94610fb02a2577fdd1331ef3ed8f118677d029e2132dVirustotal results 26.23% 
2020-07-21Inv_OKW3_491143101.docdoc fa107254b6f843bb079661702c64654bcdffb1fe41fdcdd125d5d99437e15106n/a ZLoader
2020-07-21invoice_KVHE89_145716836.docdoc 9f9d6e57c9e3398ca955952e4fcf58321a7f235e18eaafe6aab3b3ddd4e88c7cVirustotal results 26.23% ZLoader
2020-07-21Inv 0032_465806.docdoc 72a76d3c5a30ccf7584528d7bd29ac47062d468d56a417063c19573496089d56Virustotal results 25.86% ZLoader
2020-07-21Invoice-U27_1326796.docdoc 6c9f7eb3f83892e735f0beedd952428a90922073dcb4f87543facad68fade4dbVirustotal results 26.67% ZLoader
2020-07-21invoice M610_034265.docdoc 6c2a7d29fcae5f7e2540918ec55d99182b613e01dc109a439f1d5710ce5de0c7Virustotal results 26.23% ZLoader
2020-07-21Inv-UZB5_3000180.docdoc 837bbc0f0c83b6a6837640d6ecda9c348ffd06a81fa4b87c7ebfc7df59b1a690Virustotal results 26.23% ZLoader
2020-07-21INVOICE-ABP8_84409487.docdoc ebf8a9a8c38f94a2fbf651cb07ad59f7f6be921f637492b72d966c0ba1b359a8Virustotal results 25.81% ZLoader
2020-07-21Invoice-FDUS2606_591907.docdoc fcb7d57d53fe5854649e2b62386272c124701478061110c83cb947a4fc0dd3c4Virustotal results 30.65% Heodo
2020-07-21Invoice-FDUS2606_591907.docdoc fcb7d57d53fe5854649e2b62386272c124701478061110c83cb947a4fc0dd3c4Virustotal results 30.65% Heodo
2020-07-21invoice ARM6_018612.docdoc 9bd09fd88355a1b20c3268d29be2308057a659c4b96c85a618409ec4b57bd45fVirustotal results 31.67% 
2020-07-21invoice UOK4_6028846.docdoc 3a5dd00ce1b9f75836d4575816fd4e49d546dfa29d24a4b5dff87b94d9b34b13n/a Heodo
2020-07-21Invoice TPBE7060_345290442.docdoc efa78601a195a5d90844411d1e045d9589a8249a71bf35b0132e17b31a412c5dVirustotal results 29.51%