URLhaus Database

You are currently viewing the URLhaus database entry for http://excelr8.co.za/wp-content/available-disk/guarded-cloud/41580747951266-YEoA4VRtpHhPaC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429697
URL: http://excelr8.co.za/wp-content/available-disk/guarded-cloud/41580747951266-YEoA4VRtpHhPaC/
URL Status:Offline
Host: excelr8.co.za
Date added:2020-08-11 21:09:35 UTC
Last online:2020-08-14 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-11 21:10:04 UTC to abuse{at}a2hosting[dot]com)
Takedown time:2 days, 17 hours, 10 minutes Poor (down since 2020-08-14 14:20:57 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12REP_2020_08_12_GW37824.docdoc 50ef5d0b0b7a0a0854a2bcf084cf61dca7c50050f555e23a4d4bf3e23a37a96eVirustotal results 28.81%Heodo
2020-08-12Arc-2020_08_12-NX814177.docdoc 02fd4f173197311ebd535d86f831bf279a030eac5d9ac5b3c6faf80c02efd8beVirustotal results 27.87%Heodo
2020-08-12doc_8060778.docdoc 08e063ffd684f75a775f7dc074dc7ff0c06ed18b48ac1c1caaf8adb80363b9cdVirustotal results 51.67%Heodo
2020-08-11FILE_2020_08_12_6172.docdoc 215dc1b22108efcdd066fc117c1a8aa3e86d4c0bc38bcfc5210977c9b7b97264Virustotal results 49.18%Heodo
2020-08-11FILE_8608.docdoc 593a1eee983e1c66c480fc52ce564f0ebb60c48d5cadef3f5ed4367d32f1112bVirustotal results 50.00%Heodo
2020-08-11inf-2020_08_12-I099192.docdoc 39ef7d475607c4fddb90e5b23a2d1e0466665939d1faa082763135d6b8338f38Virustotal results 50.85%Heodo
2020-08-11doc-2020_08_12.docdoc bbd11642e33e1e617f6ab68ad993a20ce9a36438c8705a2cd2df141371429cbbVirustotal results 48.33%Heodo