URLhaus Database

You are currently viewing the URLhaus database entry for http://massagepracticetests.com/wp-content/uy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:416293
URL: http://massagepracticetests.com/wp-content/uy/
URL Status:Offline
Host: massagepracticetests.com
Date added:2020-07-21 20:33:04 UTC
Last online:2020-07-23 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002822057 created on 2020-07-21 20:34:05 UTC)
Takedown time:1 day, 21 hours, 37 minutes Poor (down since 2020-07-23 18:11:23 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22invoice_RXQU6_46837247.docdoc cccf983a34f7c09c86fb0271b7682b72d552ac4bd502e3ad2e66d791224f6e30Virustotal results 27.87%Heodo
2020-07-22Invoice WPZ1_29313697.docdoc 4ecc69d66a27fcded380c3d3d2efc6dad4189f789c784faeefa7bb8d4fea8c1bn/a Heodo
2020-07-22INVOICE-C5_4723155.docdoc 02c7fd8ed2ff395eb8c7eb3caca1e0cec299f4db7480e6d19829069ce541bc7dVirustotal results 27.42%ZLoader
2020-07-22INVOICE-I379_91760289.docdoc c679172a57262c3c69a11b8b2f0c2074c71f3a338be835c38c72557cefb2bc38n/a ZLoader
2020-07-22invoice-NNC582_28619845.docdoc 962dfcf9dbe2a5f4e39e1ad1100caa0da7d50a87928be0985eb4014a51f3ebc5Virustotal results 26.67% ZLoader
2020-07-22INVOICE-UMIM140_70729105.docdoc 57bbc36f8aa8cb407d0c50ca951d626555bce1bece1b524d00d0b0d5aa3257fbn/a ZLoader
2020-07-22Invoice-G7160_944418.docdoc 134fcf928417712824838f1dbfb546e7735361bf131324ddffe62aedbcd5f679Virustotal results 26.23% 
2020-07-22INVOICE_TKHP97_6928367.docdoc 915ef2dcbb13060e972f99c4e495f50d5fb9144271000603ebb86db379223840n/a 
2020-07-22Invoice-IZPW4803_3162905.docdoc 64904286f139771314584f5ebf505208623b941f9fbc7c36e5039edcf595d9e8n/a 
2020-07-22Invoice-VY381_649805.docdoc 59ea049ff3ab24d93029a5395073975931ffb768537ca09e45fa6bf34af34accVirustotal results 26.67% 
2020-07-22invoice-BV1424_118012.docdoc 40b8fbc9e4135de9d65f33366f01bddb05cfca61799ce403b30c092fcb421725Virustotal results 26.67% 
2020-07-22invoice_FX5151_5376066.docdoc 2a1b48f3aaada9451e14e735699dc6910a2df66a18b4f4497c7f4f6f159c8296Virustotal results 26.67% ZLoader
2020-07-22Invoice-MEQC927_816189.docdoc 85f96e5cf282786ef803c7c7886284d3225a9daeecc04ce3b8e5bbd143a3e0abVirustotal results 25.81% 
2020-07-22Inv GUP0_7161389.docdoc 6ae3ae7189628dd42bd3802615aadeb1038ba73d53ab4f1ee1d18cc170ad7ef6n/a ZLoader
2020-07-22Inv-UX7_51331290.docdoc ee7974d011582b83c0464f15d86e55b3306961023b16ed3c195c6c1953ea5835n/aZLoader
2020-07-21INVOICE-BCI5879_090634.docdoc d1fe2bcc5439caf2963c2bcf85af9c8b8d4451abbc4675be82a33bf97ca81f18n/aHeodo
2020-07-21Invoice-NN7062_92295640.docdoc 599ef65639238b841a852f756d71b9d44c5e02b6d151b6941b95c94b5e8eaf64n/a ZLoader
2020-07-21Inv_RTBH8_216592.docdoc 112aa4be04d85780875343365b40f2fe9351e69dd4756d26a01f923251e17a49Virustotal results 25.81% 
2020-07-21invoice-58_6966142.docdoc 3e48fa00d3dfee3093ad2affb99324ae8e7261f2c92fd9bc71ffc5923a7dc4a3n/a ZLoader
2020-07-21Inv-QQT052_325496385.docdoc d9238e5af649fe7ea0572f9699144985895a4c4576ebb77e0e198ea5120f4c20n/a 
2020-07-21Invoice-IX88_909928765.docdoc 88b555290b53e0369600411c472821ad9907eb147dc87e60164918aa85adc3c3Virustotal results 27.12% 
2020-07-21invoice_NRLR87_857686465.docdoc 29fd633ba82c884e342db1c88a40a28984b2cb2fc5cbb4fdd901a3c6e5850817n/a ZLoader
2020-07-21Invoice_3649_8287449.docdoc fa107254b6f843bb079661702c64654bcdffb1fe41fdcdd125d5d99437e15106Virustotal results 26.23% ZLoader
2020-07-21INVOICE-Y38_855307570.docdoc 9f9d6e57c9e3398ca955952e4fcf58321a7f235e18eaafe6aab3b3ddd4e88c7cVirustotal results 26.23% ZLoader
2020-07-21invoice_IB17_514611.docdoc 2bf992bac6895328fca415aeeee4f89aff347608e709524ad9a2f549b007dae3Virustotal results 26.67% ZLoader
2020-07-21Inv_LHB0087_3987427.docdoc 6c9f7eb3f83892e735f0beedd952428a90922073dcb4f87543facad68fade4dbn/a ZLoader
2020-07-21Invoice-RN91_00960884.docdoc eac069c2098e2a08afb43c1f5aae5878d557e5cef94096cefa93bbe0d04c236bn/a 
2020-07-21Invoice-ILQS5_64322101.docdoc 73b9d41dfe22f72b30fd91830d8b7571f3ce3f8a7a345d502e4e4b2da0d74efdVirustotal results 26.23% ZLoader
2020-07-21Invoice-DAKQ0236_063825637.docdoc 837bbc0f0c83b6a6837640d6ecda9c348ffd06a81fa4b87c7ebfc7df59b1a690Virustotal results 26.23% ZLoader
2020-07-21invoice_KYL3371_73688989.docdoc 891720d72fd445856bd0651bafd3d0780b209d1ba975ee7cc4ff2af493b0381an/a Heodo