URLhaus Database

You are currently viewing the URLhaus database entry for http://centeklabs.com/wp-content/CpdiO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421646
URL: http://centeklabs.com/wp-content/CpdiO/
URL Status:Offline
Host: centeklabs.com
Date added:2020-07-29 20:00:36 UTC
Last online:2020-07-29 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 20:02:02 UTC to abuse{at}mediatemple[dot]net)
Takedown time:1 hour, 18 minutes Good (down since 2020-07-29 21:20:13 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29invoice-TY2535-2883439.docdoc a051771fa572eb1ec25fb7d5a44e20a4bce5ea97589a083e7da10b00c0778bcfVirustotal results 35.48% Heodo
2020-07-29Invoice 566 33809805.docdoc 0644fc32d19fccfcc17f4c76d1f463049498e6005f7228f63aa9b88a1d17c95eVirustotal results 36.07% Heodo
2020-07-29invoice_KZB039_438910.docdoc af9d5de07f7e571202c737e34a1b5a962949f65253c1ac006aa5670b11c653d5Virustotal results 36.67% Heodo
2020-07-29INVOICER328-258723.docdoc 083fb26b679850da692f7d028b44544b22922f27cada0b307fda9d85664962caVirustotal results 36.07% Heodo
2020-07-29INVOICE-KRJ6 161782.docdoc 94518c218207a2b7282e3eebae739791b5471ea1b327268cde0bbe89eb912140Virustotal results 35.48% Heodo
2020-07-29Inv_8_62563752.docdoc e71897829455d67c03b3f1a81795720974786866c4cbcdc3b93be5cd01c9071fVirustotal results 34.43% Heodo