URLhaus Database

You are currently viewing the URLhaus database entry for http://sodano.ch/images/protegido/s4zs7zqot_wzz9ub3_recurso//khgu3kf0o_aa5t5pif0k/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:419891
URL: http://sodano.ch/images/protegido/s4zs7zqot_wzz9ub3_recurso//khgu3kf0o_aa5t5pif0k/
URL Status:Offline
Host: sodano.ch
Date added:2020-07-27 13:43:07 UTC
Last online:2020-07-27 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-27 13:44:02 UTC to abuse{at}mail[dot]metanet[dot]ch)
Takedown time:5 hours, 31 minutes Good (down since 2020-07-27 19:15:27 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-27ARCHIVOFile-7/547034.docdoc 8df3948dfc46fa0168ed7803a28dc400cb4f23dfff43c3ac553b832c88e962b9Virustotal results 37.70% Heodo
2020-07-27DAT-27-2020-042629.docdoc a88def160248a9f1c1004c02d418deca1f2ebd8f47ef454e401c7a414de4685bVirustotal results 37.70% Heodo
2020-07-27FILE 072020 2-873582.docdoc bfb47d299444268850ba81fe8405b0e67bb464edeafdd2256da8b407c7c631c1n/a Heodo
2020-07-270321 072020.docdoc 3026d2a170c300a107ba8fc93c4a30219dbd9e888abafde4b08adf098416b010Virustotal results 36.07% Heodo
2020-07-2777566594 072020 49-65257474.docdoc 9425930e1da8f5bb9e2818f20871cf3407541762830a5b65bb5e70e3af742061n/a Heodo
2020-07-27Adjunto_2707.docdoc ae69c4051e695f733aed8ab179413093ab05a7c85409e95847968da5bcd9fbd2Virustotal results 35.48% Heodo
2020-07-27Adjunto-2020.docdoc 156df3a41550c999f475e13ac003b4a08360431dec19035610a316382ee375d9Virustotal results 35.48% Heodo
2020-07-273041492-072020-XOI_677186.docdoc a8ce509813334e27d35525994ac3fbd22d52463478668d4437cce2a566c21e62n/a Heodo
2020-07-27Adjunto.docdoc 66ad126d0fa0435c277daaa539681c21f579cf4382009490c7b27d791f042648n/a Heodo
2020-07-27Datos-2020-421_2531345.docdoc 498e50cfaaaf63fbc5ad3ffa6a356c3fca03b7d613c8cd8511c2e2bdc7813071Virustotal results 34.43% Heodo
2020-07-27MENSAJE_7/40935817.docdoc b76c0070bb4db2128b1580cd09ca0f2f9e41146f965d2d4e05cb1761849bf280Virustotal results 34.43% Heodo
2020-07-27Arch 2020 FF_79143.docdoc 6c5324c5da5dcfa7d42eeab7d5a2e985853f1a06b186abe833296d75d13c9e5dVirustotal results 35.00% Heodo
2020-07-27info_2707_2020.docdoc 0a479543609c0a5dfd9da512221616a307fb608be96c70898e17e94481ede16fn/a Heodo
2020-07-27ARCHIVOFile-072020-498_449708.docdoc 4dd5a0637ab3d098e490efcc2433eff42f086213f059c19049c5e22448f0677eVirustotal results 33.87%Heodo
2020-07-279369-2707.docdoc de34730bf5943304abaabfb1fe0f313a52b5336f8e3f514aedc7626ce2952b45Virustotal results 34.43% Heodo
2020-07-27867661 2020 071_224866.docdoc 433d6bb838d6c2b28b8ef3a372f22d9c88cd35ab4ae071fd7d922554d8abbeaen/a Heodo