URLhaus Database

You are currently viewing the URLhaus database entry for http://www.lerasole.it/wp-content/multifunctional-resource/open-warehouse/xdr-u1vzy4sx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427014
URL: http://www.lerasole.it/wp-content/multifunctional-resource/open-warehouse/xdr-u1vzy4sx/
URL Status:Offline
Host: www.lerasole.it
Date added:2020-08-07 06:45:13 UTC
Last online:2020-08-07 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-07 06:46:05 UTC to abuse{at}linode[dot]com)
Takedown time:8 hours, 50 minutes Good (down since 2020-08-07 15:36:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-07Arc_20200807_SPS1742.docdoc 9f3d4befc75b49a5e090558b5cf953d5da87bfac56db564bfdde1d36d6ad7b74Virustotal results 25.81% Heodo
2020-08-07Mes.docdoc 5080eb6df265a19a54691328b412d3f78cee2e6e21284f98c03a973300334a72Virustotal results 26.23% Heodo
2020-08-07FILE 20200807 PJ010343.docdoc bb249753b6fd6220b43602a1122cd458d29055d3e37603c1a3a1e2f21a81366eVirustotal results 26.23% Heodo
2020-08-07DAT_9479767.docdoc afcb2dbd3d6efa8401aabfea9622280306122ecbd80ca129f6930db9b4b87dbfn/a Heodo
2020-08-07mes.docdoc 15be7667cc3b8d6445b3b4c245f2befdcf7a96e438a771828ca1ed6c12682670Virustotal results 26.23% Heodo
2020-08-07Inf 20200807 Q824.docdoc 11a879a7d8dec97462c1c9185051ef6a793dfa91fa064697aebc8e58839b888en/a Heodo
2020-08-07file_20200807_UHD357298.docdoc b584a5aebf9d1ad385649f724d7889be3f925dbb7a40ecce452d88f63462e44cn/a Heodo
2020-08-07Rep 2020_08_07.docdoc af8ca0fa1d9fa19974e76b3491741aec5421ff068ac5b8fcb364b9fa30edb3ccn/a Heodo
2020-08-07doc 1276076.docdoc 382174823a7c36d512b36fa77c017170465f34034a645db3517ca6de6e902aaan/a Heodo
2020-08-07FILE_20200807_291.docdoc d55a2e0971027bd30b6722f6827d6344f1126b7f7ba6c04a91179b881ca6e98aVirustotal results 25.00% Heodo
2020-08-07rep 2020_08_07 T663312.docdoc 83199c3a1bbb38134c3c906319e4ac997003f912f7858649a8a6222d475fe002Virustotal results 30.00% Heodo
2020-08-07ARC-2020_08_07-W740.docdoc d21fb5ef05cc6d7375ad67529c3b74d7111dff2fd9a11ce6944a25e4dc2463c0Virustotal results 27.87% Heodo
2020-08-07Dat 20200807 935265.docdoc e607f47e569464c20dab9a92af7033ff8683097da7c6015fa4ffce255ad7bd2bVirustotal results 39.34% Heodo