URLhaus Database

You are currently viewing the URLhaus database entry for https://attech.ml/wp-admin/8v93g9-5xa6-35561/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429722
URL: https://attech.ml/wp-admin/8v93g9-5xa6-35561/
URL Status:Offline
Host: attech.ml
Date added:2020-08-11 21:47:26 UTC
Last online:2020-08-11 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-11 21:48:03 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 hour, 55 minutes Good (down since 2020-08-11 23:43:03 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-11InvoiceLMDU81333545368.docdoc 98891f34f0962ebc73b8be9c5a37aa21ad42fea2d08629bcbf84ff00595fe02cVirustotal results 50.00%Heodo
2020-08-11Inv-0-60327351.docdoc 855f271178a061c154a5feed625773d8a02e960340dff7e0e0aedfefd40c2873Virustotal results 50.00%Heodo
2020-08-11invoice-JKQP7-97818160.docdoc 4e7dada550866484045928cef6fdd4d7ccb5d19d79febe490ed7da33d3491b01n/aHeodo
2020-08-11Invoice-KP61-138614.docdoc 19c60452fae42f6c268705bde00ef94bed83022e4969001353d14549fa028fabVirustotal results 51.67%Heodo
2020-08-11InvPGCS9800620682.docdoc baa7ec55d76e7be67f654211832accb7b7352442fefbadd3a4047e63adcc24c1Virustotal results 50.82%Heodo
2020-08-11Inv1428465.docdoc 98c981a420851abdca6108f1264153f000a93d4efb36a2df630d0fb91c63aaeaVirustotal results 51.72%Heodo