URLhaus Database

You are currently viewing the URLhaus database entry for http://literacy.fischertrust.org/wp-incudes/multifunctional-disk/interior-0JYPU5zn-dHwrpTRnQ5M/65881348-S6XRTu07iM7Y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436589
URL: http://literacy.fischertrust.org/wp-incudes/multifunctional-disk/interior-0JYPU5zn-dHwrpTRnQ5M/65881348-S6XRTu07iM7Y/
URL Status:Offline
Host: literacy.fischertrust.org
Date added:2020-08-19 13:19:38 UTC
Last online:2020-08-19 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-19 13:20:04 UTC to abuse{at}tagadab[dot]com)
Takedown time:6 hours, 12 minutes Good (down since 2020-08-19 19:32:10 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19rep_2020_08_19.docdoc 0049de1a4a6b1dd67a723e087f93fa0dfc155110552068650ff7e7f93bb9cd4fVirustotal results 25.42%Heodo
2020-08-19file_2020_08_19.docdoc a914138cab6d64aaf2c57366a13ebfe0ad1cb2f1821402a26a4c03e8ac8d2781Virustotal results 27.12%Heodo
2020-08-19rep 20200819 B3145.docdoc 544d30214310c30ed1c96f7efc2d67112ca152bf4e247951a277932d1afaf252Virustotal results 26.67%Heodo
2020-08-19List-4248968.docdoc 74cd6093c787bdddca5131a78f2fe3182a2b85ea646d74fa2dcedfd016bc8952n/aHeodo
2020-08-19file_2020_08_19_UN285.docdoc d54b881b142aa3ec2e3b816d4dc326d23176dee31c65f78ff9b9328f61aaedb9n/a Heodo
2020-08-19list-20200819.docdoc 91d76b351c4ea63157aba2fbee15328e674e87decb909d364c0466fe61847135n/aHeodo
2020-08-19Doc-20200819.docdoc 66915150d26a0500bee5a47eef810f6d5ef9c9a9282973f17b3e434bac5600bfn/aHeodo
2020-08-19Doc-2020_08_19-6095595.docdoc 35a575d3cc73b07a44de16fc04dbd04650ba5d4a0005028abc178ad78e1d47b4Virustotal results 21.67%Heodo
2020-08-19Arc A64742.docdoc c313812bbf729a2f67dbad9bccebb42106cf1625d5d9c8a3621ee88aff2fbe31n/aHeodo
2020-08-19Doc_2020_08_19_W81297.docdoc 1f95f1bcb4d64eabc5e073cf6fd417f2af38af4f1b0c02594f5313a162dfe6a3n/aHeodo
2020-08-19Inf-662.docdoc f04dd72e780c21c9e4b8c93008e7c679ba859a9ffbff5a9e997d387659a324c1n/aHeodo
2020-08-19dat WS3651.docdoc ff3dae4dba7055a170bde6b5cd1c62c47c680d32b65e19ea32fc4af41f8c3f06Virustotal results 20.00%Heodo
2020-08-19inf-18255.docdoc 1e1bd9b8516ba6602eafeeb65a0fd430014d63b18bb637cc352f7f55ccd80332Virustotal results 20.00%Heodo
2020-08-19Mes_I33470.docdoc 26dce61e09cc8b2d4d6d397a262348c91742adb49a51a8f062e6025e04cd5287n/aHeodo
2020-08-19REP_20200819_9302.docdoc 0438242a3ca04ab173d67a0fcf3cad13a9cfaffc01aac04ffe0050024bc471f3Virustotal results 20.00%Heodo
2020-08-19DAT 2020_08_19 366.docdoc ac5d6169036212c360d8f4232685f6664041d612f03126d5ae29a48dfdcf2d1dn/aHeodo
2020-08-19File 20200819 SM138682.docdoc 8c8c9a461837ed77d0dcfda29092e08452817660cf5a56a7e9547741960e43dcn/aHeodo
2020-08-19List_2020_08_19_011473.docdoc 003331c267448f379ec242d8b35b9d556baeba21e8b8a542eeb3886871df8d0cn/aHeodo
2020-08-19INF 2020_08_19.docdoc e9da8132017bc36f1448def9ba8b2ea44184e68bf955c08ba75f2560ade79372n/aHeodo