URLhaus Database

You are currently viewing the URLhaus database entry for https://stursulaschool.co.in/wp-content/statement/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436724
URL: https://stursulaschool.co.in/wp-content/statement/
URL Status:Offline
Host: stursulaschool.co.in
Date added:2020-08-19 17:11:12 UTC
Last online:2020-08-19 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-19 17:12:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 13 minutes Good (down since 2020-08-19 20:25:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19DOC_53906269.docdoc 7feab4f1f35adcc7433afdbf4448e5b79996fbe150dfe6e0f708a6c13ce86f7bVirustotal results 23.33%Heodo
2020-08-19KMP_080120_KOE_081920.docdoc 7f3f68fc29feddc0494e2e4853b7454b5d0cceeabe5e0bcd13029c5ec301e9c6n/aHeodo
2020-08-19BAL_OYE_080120_NGM_081920.docdoc f8e4cadcb7cf38b0178a092055f3091a983b1d2a277d1a3428a75c63bd5d3b60n/aHeodo
2020-08-19REP_MA1593956980LU.docdoc 39f8850f02b807a843447f461d3436d67191f0f08709c03d32958988964b5e9fVirustotal results 23.33%Heodo
2020-08-19FILE_TIV_080120_ICR_081920.docdoc 90499b6cd235fd63115a4d18f0989f842252935038f4cadec17f85a2081b1cfdn/aHeodo
2020-08-19PO_08192020EX.docdoc 863115404bb5f48e7f22e292813820254117f2cac7a97b266e8a8fd6359557ddn/aHeodo
2020-08-19REP_1064645613.docdoc 0d9522e1c5d18866b466aa9d28546adc56ea56f6d821fdda5ab77b1285b9e0d8Virustotal results 23.33%Heodo
2020-08-19Y_38749060.docdoc 5107d73e85becfa7829813529310561cc6973e71b95c5eaa3b236646a2157533n/aHeodo
2020-08-19AIE_7040655663341426121027442.docdoc 85ed9da785c50c5f2e6cd6a5e0be76e1d69f52f6f6513c5a3fc6199c0517bdcfn/aHeodo
2020-08-19BAL_MQ9652359401UJ.docdoc 6e24d40dd2ab39e102c07369124f050fc0b0f2c103fc5acd2fcf280d8048b1bbVirustotal results 18.64%Heodo
2020-08-1955804931.docdoc 77834d629af8b45f85ec232e03fab3cf97e78e448b23fe48bc93ad6a391f3c90n/aHeodo
2020-08-19BAL_PO_08192020EX.docdoc a47b7f6d9af6602b2dac196cb0faf5414e8a3d7f94604f937e2e66f19fd17b61n/aHeodo
2020-08-19FILE_3031333292165.docdoc 2065474363cd9df4a104d020800f2f1523e4cdbb0602b68434bb6cf61b62398dn/aHeodo