URLhaus Database

You are currently viewing the URLhaus database entry for https://anythingghost.com/wp-content/plugins/font/sites/s8ouwoc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427309
URL: https://anythingghost.com/wp-content/plugins/font/sites/s8ouwoc/
URL Status:Offline
Host: anythingghost.com
Date added:2020-08-07 17:38:07 UTC
Last online:2020-08-09 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 17:40:05 UTC to abuse{at}webhostinghub[dot]com)
Takedown time:1 day, 11 hours, 57 minutes Poor (down since 2020-08-09 05:37:05 UTC)
Tags:doc emotet link epoch2 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08FILE_VK3016367301AF.docdoc 8ab91f2a161be81c4baaca43228baaaf69cf93639e942a1c618a5a4c995aca18Virustotal results 37.10% QuakBot
2020-08-0800775186.docdoc a70123a927ae0657bd4ee527c1f8c2b9e45628b8797b3487b70f9728daf13ab7n/a Heodo
2020-08-0844497047.docdoc 9767aa04e0d5fd215636a710fc84b891ad6e13826c5f54a9fb55f5deb2269460Virustotal results 38.98% QuakBot
2020-08-08BAL_8905421483832304247.docdoc 99c91d2f1ecbee44baa8f5c9f3bfc0e2d7d11b63cac8d777f6dc1dd3b1c2aaa8Virustotal results 37.70% QuakBot
2020-08-07XJXT_ZS0702884923FC.docdoc 41ef6b4c13a98f92f61c7a14e9619f68f166ea699a7ea6eee9a1bf0165512f81Virustotal results 36.67% Heodo
2020-08-07FILE_33754659005.docdoc 3fa07890f989720b75b20159381e2b658443faaa04b1befe587ce8955e5e0642Virustotal results 35.48% QuakBot
2020-08-07DOC_07704471.docdoc 6db606248d43c819a2ab538c317686648dcd10422fb5a903bd82de9335961828Virustotal results 33.87% Heodo
2020-08-07REP_FLJ_080120_KIF_080720.docdoc 3f4c381531d4604385f763850e0e32cd72c1b21b78330327c64b2da16e62e9f8n/a Heodo
2020-08-07SV1817102747NL.docdoc a88af77fd7a45cc422482f3f48ce86b8749212a9abc500571cf0c5d3837d89ddVirustotal results 34.43% QuakBot
2020-08-07REP_57KCX455DIZ6P4B.docdoc f2d8787f963d77436d9eaa615f6d0cca8218476795473ead7063334d34a177f7Virustotal results 37.93% Heodo
2020-08-073786425567993946.docdoc 647e4bdd2ba51f7dfc1c7749092db78d95b64ca550d266e025602d2437cb503dVirustotal results 30.00% Heodo
2020-08-07BAL_PO_08072020EX.docdoc 60582057db0b8b7677173d87d87d3855d5f189ebf39995e2d7ff0e138007a75fVirustotal results 29.03% QuakBot