URLhaus Database

You are currently viewing the URLhaus database entry for http://freesellers.snolias.com/wp-content/zE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429719
URL: http://freesellers.snolias.com/wp-content/zE/
URL Status:Offline
Host: freesellers.snolias.com
Date added:2020-08-11 21:47:03 UTC
Last online:2020-08-12 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-11 21:48:06 UTC to abuse{at}ovh[dot]net)
Takedown time:18 hours, 6 minutes Good (down since 2020-08-12 15:54:07 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12Invoice-043-51578158.docdoc 414fc538cb963c4536c7fb1f90c7b953d2481601dbbc6f17a9f97d9b85a4edd5Virustotal results 50.82% Heodo
2020-08-12Inv-5187-672454.docdoc 2f20ed3e86d25bee2fc86cfef8577a1392ff6573b368c48c7611b7215f15323eVirustotal results 53.33%Heodo
2020-08-12Inv_1145_2284973.docdoc 49f84ff8599ef44db2d0ee39c6a82739d5a9d663c0b011960b67747dead85d57Virustotal results 51.67%Heodo
2020-08-12Invoice 8850 925127115.docdoc a2b1d13fc111d276dc837aa2c6e155e9aa2944ec66d9133932b1f183cbecad32Virustotal results 52.46%Heodo
2020-08-12INVOICE-DGYF095-79210172.docdoc a9dd0c1dc51e0d6deadf4a1cbd8ad39e41c1ef2ff8f222bb877a3590bbd5439en/aHeodo
2020-08-12invoice-DCOQ61-75425990.docdoc 25e3c7f92b7b6c4d2a0bf01c2e0375ff93d1547ce1ac973169615136f290835dVirustotal results 49.15%Heodo
2020-08-12Inv-XVDT77-034933.docdoc a3c27802860cdc8195b53a7a9a0308f67c631bec4c450329dc8421a206c65d08n/aHeodo
2020-08-12Inv-EVOU120-311457.docdoc 644d19b28f8eb49ad2929b4c9685442b9bc7121929f330c6a7e0d117fdf2462fVirustotal results 53.33%Heodo
2020-08-12InvZDI19772340.docdoc c57f8830d597b05f0dbf9031092be52ed1ce11f9f75f530bfd698f46f624901an/aHeodo
2020-08-12invoice HCW51 075095.docdoc 252a44229413353042efc9846e4521a6c230832832d0d7efd0bb8b2677026afbVirustotal results 53.45%Heodo
2020-08-12INVOICE YOW4 207980959.docdoc 6e9b1ad824b0bc35792a2ec92fabb0456af70c654e99e5f6d0067903f3c771ceVirustotal results 52.54%Heodo
2020-08-12invoiceBTK6428493382.docdoc c9a3637927d6c089d282b7e5f89be7e0269eb7fd1e823cefe8844e25153f2cd2Virustotal results 51.72%Heodo
2020-08-11INVOICE-VK7-861266.docdoc d1ada929c1d864f25ddf89d90029767d6c3b46a1bcd2f20cc967703c3d84bf5bVirustotal results 50.00%Heodo
2020-08-11Inv-054-6984461.docdoc 96c6a329f0da6f8cb3e414f2bde2a0084912d8de0f46d04f69f613f061c0ccbcVirustotal results 50.85%Heodo
2020-08-11invoice-XJT2738-493935.docdoc cbf6ee8e987a618ed4bbc8efb689fab62d912808ce3d959106e7697637d3a217Virustotal results 50.82%Heodo
2020-08-11Invoice-ZSUC3543-605566840.docdoc d73d3d4008607aa85da7da86d829db51efb32444af68f33a88a957c15e3dc7cbVirustotal results 50.85%Heodo
2020-08-11InvoiceM39449165206.docdoc ba9a8497f8d62ce6e51e23f89f045998e57f187f7b8b9ff3168e5289d1758e80Virustotal results 50.00%Heodo
2020-08-11INVOICEQXW1490258048.docdoc cbb857ef4e6a3fd6c97835111cd57faa9a633931718e00486d9d6ab47dbc88c0Virustotal results 51.72%Heodo
2020-08-11INVOICE_C260_72537121.docdoc c45b228e93af0e566d2bd17f6a59f923a95517fb7eab92217995375cba5ed65cVirustotal results 49.15%Heodo