URLhaus Database

You are currently viewing the URLhaus database entry for http://dickensagencyacademy.com/wp-admin/balance/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428178
URL: http://dickensagencyacademy.com/wp-admin/balance/
URL Status:Offline
Host: dickensagencyacademy.com
Date added:2020-08-10 09:44:09 UTC
Last online:2020-08-10 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-10 09:46:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:5 hours, 26 minutes Good (down since 2020-08-10 15:12:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-10BAL_RS0271502067LR.docdoc 365d24b51aae43c58665a5fca72115289aa276c62ddca2554fd016ac299ec917Virustotal results 40.00% Heodo
2020-08-10F_Y7IS228HUIJ5.docdoc 2029de9bc279faa7197afc4898bbb407f4588219be0e8332a73c917b6eaf9f9eVirustotal results 37.70%Heodo
2020-08-10KB7431056507SK.docdoc f602c49cb3a75d9e1621b6c62ecffcda74542f712afc23c222ea4460e3729985Virustotal results 34.43%Heodo
2020-08-10I_HG6729479614OX.docdoc 213ed96cf8cd6d7e21d5fc2c71f456d265c5897182451aacd9786625922b784cn/aHeodo
2020-08-10INV_38770581.docdoc 32dcbf714d1e4a6e2115f5c3fca1c57d86c33af0cfb03fac9fd86e7e2940d881n/aHeodo
2020-08-10REP_P7F4DBGH.docdoc 149576ef5ef94316d4e0db4ce478cd4866a0293878a5d8070dc4bbe6d86050b7Virustotal results 27.87% Heodo
2020-08-10OR1596103232IH.docdoc cc2e6ecf854ed69caa6e4a1000fd2e98b4ce767cf468ad73d450ea9535d95134Virustotal results 23.33% Heodo
2020-08-1096775190.docdoc c3089aae17704c9ddcc67b476b66c0a66f756ef1dad5b90062f06ec428ee5d3fVirustotal results 22.95% Heodo
2020-08-10BAL_9892866692396286551185692.docdoc 3279305c76025d9335931768dfb6a02880eebae4e37850754d311dbcb3052bd8n/a Heodo
2020-08-10INV_XY8521322756IY.docdoc 407736ca4a4bdab4ea158b768aacc22239f4c364a9a0911bdf0531d5b6857456Virustotal results 28.33% Heodo
2020-08-10REP_GHM2GD9BMW.docdoc 0a635c6914b1d696e249b62eda3f0fa60f54bbc2c24939308a6f45b0a601796fVirustotal results 27.87% Heodo
2020-08-10FILE_3567464279924.docdoc df1f8dc5bdb2922872307a97d663e7a17bf750c84e97d3a48d9f92422a7111b9n/a Heodo
2020-08-10OQP_080120_WND_081020.docdoc 4ea6035fe5de3a984945448439b050bbd2482348d9ef8927d6e8608f2970b83aVirustotal results 27.87% Heodo
2020-08-10WRV_080120_HOJ_081020.docdoc 4ef3be78e6d5e7488bfec47d05dcb528ae781bbfcccf27d5775eabaf583ec691n/a Heodo
2020-08-10VBA9ZJ5IIP3LFZXA.docdoc 137bfe09b8e8a8ed4eac1066af1808e9e6f4d720a38c8a031c7241adc8eb0019Virustotal results 26.67% Heodo