URLhaus Database

You are currently viewing the URLhaus database entry for http://aumentofans.it/fzeb40ebo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436237
URL: http://aumentofans.it/fzeb40ebo/
URL Status:Offline
Host: aumentofans.it
Date added:2020-08-18 23:49:13 UTC
Last online:2020-08-19 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-18 23:50:06 UTC to supporto{at}hostingperte[dot]it)
Takedown time:8 hours, 18 minutes Good (down since 2020-08-19 08:08:40 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19REP_JQ8594160102QU.docdoc 14c8425a5923efb623ff5070d126d05348baaca0a46096c569a40d6afe8e0244Virustotal results 45.90%Heodo
2020-08-19DOC_ZVVB55L4TOWA.docdoc a1b39bb8e04288328a8785f48219abb0b12a2a6330e2192973405a2bf6682644Virustotal results 46.67%Heodo
2020-08-19BAL_FBP_080120_TUX_081920.docdoc 9be9c52a2ed346fcab910d6e22a065f7f1ddbb851e589a1c18e4b0577afe0e5bVirustotal results 45.76%Heodo
2020-08-19G_01267073.docdoc 9300711f5a35bc33dab0314d010f858ea9385b9b41b60e8db605a367ee901d57Virustotal results 48.21%Heodo
2020-08-19INV_IJO_080120_TIH_081920.docdoc eb3a3bdc721850d6e51b7c255e5237b5d1657ccf823f9965b2ab012da716b66eVirustotal results 46.67%Heodo
2020-08-19FILE_8867409929563927021.docdoc 1e5fdb496c17dd55dfc3e32231d286de4334d59bcc313b939202c4f8ae2abecaVirustotal results 46.67%Heodo
2020-08-19PO_08192020EX.docdoc 6ad811a3072f008affd2450407d0a37d9d45166d41c8fedc1d1e0ae2b61c77e9Virustotal results 46.67%Heodo
2020-08-196625277971657298331.docdoc 2efc148d28ccc7f78e2f598072e171cb43bd6703a0be1abc612c36f1420ec1d0Virustotal results 46.55%Heodo
2020-08-19LPE_080120_HIT_081920.docdoc 8a80d1e540897315edc7acd34b69bf1cd00ea85dbef7186b3751c5a8337f88ccVirustotal results 45.76%Heodo
2020-08-19BAL_09142937.docdoc 0e79daf2a9f00edeae140c5e513dfe381e03f54ae3fec2dae7b2bd9f005b4f6fVirustotal results 46.67%Heodo
2020-08-19OQP_080120_BRW_081920.docdoc 5b39d05fd1a75574a20fce09addb52c62b766bb08f8812b8d692936918ba780dVirustotal results 46.67%Heodo
2020-08-19DOC_81827230.docdoc 13ecb0280410d83e2d67d9f049fe85af186a0c9959c316c90f3ec327a9ab244dVirustotal results 46.67%Heodo
2020-08-19Z_GN3731134752VD.docdoc 28e4449bf2803e0d685599cbfbd23a03ac3f9a69b25f6a2669de4ce252de4073Virustotal results 48.21%Heodo
2020-08-19PO_08192020EX.docdoc 189ef09b3af0c487e840219d1b144a8022ff6940de058c276ecd313ad2771c0aVirustotal results 46.67%Heodo
2020-08-19BAL_40271922.docdoc 94fe6d0cc1723a60d8965c606027ad0283a60c1f4677cf33c8cb85fd202bbc60Virustotal results 46.67%Heodo
2020-08-19REP_PO_08192020EX.docdoc bb7514867d581af837a3d30b735e4c0e010220c3b2bee800c0217cb4e7275e3cVirustotal results 46.67%Heodo
2020-08-18PO_08192020EX.docdoc 4f1ea64903fced68d8230b8c217e089716c28221e5bb5d2f18eb6887f8d2e671Virustotal results 48.21%Heodo