URLhaus Database

You are currently viewing the URLhaus database entry for http://www.cittadivita.it/citta.cittadivita.it/crg6sz51-00834990/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436822
URL: http://www.cittadivita.it/citta.cittadivita.it/crg6sz51-00834990/
URL Status:Offline
Host: www.cittadivita.it
Date added:2020-08-19 20:05:06 UTC
Last online:2020-09-01 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 20:06:04 UTC to abuse{at}mxhost[dot]ro)
Takedown time:12 days, 19 hours, 15 minutes Bad (down since 2020-09-01 15:21:46 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21Invoice.docdoc 5efa2b73134b720b789e7a0ae1798e3a491be917db79092a8f0cb6bbcaa759d3Virustotal results 33.90%Heodo
2020-08-21Invoice.docdoc b99da0701a16d0df2895790bf84db62ee0da6b42fa8ea0c2a5b103a131d98f13n/aHeodo
2020-08-21form.docdoc 5ad1d00e81e5e6bbc93829790980fabae6eab63a8638ed9bc024a27d083ffb87Virustotal results 25.86%Heodo
2020-08-21LB4574792502AM.docdoc dfb4a0445bee97a362ee8ea96a3cb6444bc3ef4b7c96beaa5edf0508e6343c56Virustotal results 25.86%Heodo
2020-08-21Invoice 9518560.docdoc b79c89f1882c609b4abca4db5b83aace234943227d1cc9c3624f1f063d348e41Virustotal results 26.32%Heodo
2020-08-21Inv. 00923500.docdoc 0ab5e2ea8649a76f8c477a47f657724054f2795e5e8ade248d1d77a2273c9237Virustotal results 27.12%Heodo
2020-08-21Invoice 00331733.docdoc fa73c7c4709f00943c0995e1c8b64edce7bd0443e3a2fa1c4940c978d35fa794Virustotal results 23.33%Heodo
2020-08-21Invoice #276.docdoc d19e02168b132996bd96c13b98d93c3ce9076a1f1ef766b50f4e096f2d47b02eVirustotal results 22.41%Heodo
2020-08-21Form - Aug 21, 2020.docdoc 438aaef09f18c29d20a8a5a144a2ec60b59c645a3945b40f6f55c229b1efd099Virustotal results 22.03%Heodo
2020-08-21Payment.docdoc abedafc5e19de68937c53f7be30c1b392975062ba9a11d34a991ca703cd3c578n/aHeodo
2020-08-21Inv. 0678828.docdoc a4144c641d91901e22abbefc33604f1e8afd8706524f72d73dde59e468f985fcn/aHeodo
2020-08-21Inv. 85800542315.docdoc 69eab92915bca8074c0e4c4a14a6d4532a6d4162923b7c51799ae872c647ee21Virustotal results 21.05%Heodo
2020-08-21Copy invoice #281987.docdoc d5319b8e57553df961d62f963f34f36ac87341ccd45ddbfb09676b7338d87dc8Virustotal results 20.34%Heodo
2020-08-21Invoice #7109.docdoc 6f69eecc69ca89716c536b2effc57f04fe5739e38fcb08dcce20d16efa1d382eVirustotal results 20.69%Heodo
2020-08-21invoice #31160.docdoc ebf536cc3ab147667e77823b5feaa2f72da1042d653ad11a26298800a7a86d77Virustotal results 19.64%Heodo
2020-08-21invoices 40282 & 1909.docdoc 4da5e980866878da930be670800361fd6b9b6ec73983dd60cdba9eb29bd09ab6Virustotal results 22.03%Heodo
2020-08-21Invoice #151.docdoc 1c8f1124a4ccfc01bfc51367aeeda6685df4fc2ffc245deca3430582af9e816aVirustotal results 20.69%Heodo
2020-08-21Invoice #6193384.docdoc bfa9030c4923b22a26ab343f17ace0c0b90cb5a79c02e635937d73b994c50b42Virustotal results 18.64%Heodo
2020-08-21JUM-080120 YYRD-082120.docdoc 1379c04142852211fa0a0fa5b67d4f96ec3109824d6c39002d6691ffc2c7b9c7Virustotal results 20.00%Heodo
2020-08-21August Invoice.docdoc 8ffb84f76b863917f3ef52c3c75dfa70bc77599b7deb86067b43c413c8ff681cVirustotal results 20.00%Heodo
2020-08-21Payment status.docdoc 13d2079b2caabbd56dc776517810d9dbf355138869ff3030314e9f4905e68192Virustotal results 18.64%Heodo
2020-08-21Payment status.docdoc da6cfd72a982796c23b85856bdad5e44b0a6b35b120440b1be740f5424b3dffen/aHeodo
2020-08-21M-080120 TDOU-082120.docdoc beb57be5d7b7a5323ead5a11721211e06b8ea9dc1318680473c33d71fa1a34dcVirustotal results 20.69%Heodo
2020-08-21PO# 08212020.docdoc 847717b8f4573eabf8736def4405be87f319a2f5aa3eae17a33ae61f13c9b3a0Virustotal results 18.64%Heodo
2020-08-21Invoice #738772256.docdoc 595bcfd89190ec1ce1b6c75d8b8b2b4f924106df47bb8d5a3671dad83104d473n/aHeodo
2020-08-21H-080120 VUCP-082120.docdoc 1956596f7ed909a0c2291a2a8b6ce38918255ae87ced9b557c898972bcce4d42n/aHeodo
2020-08-21Payment status.docdoc 8bd0a1327645a9ae845837795dd708e65e529f2b0baf0c5dbc548ef787a20024n/aHeodo
2020-08-21502226466.docdoc 56e0e49883a186240907a045e8933efbbaa016d71dec86c1ae477064db00a160n/aHeodo
2020-08-21Invoice.docdoc ad61f377cd0d259cfabac17a4a874cd5dbd88b076e00680d5fb1d31706816ca7n/aHeodo
2020-08-21Inv. 0022848800522.docdoc eb65f89380e33a9b00ab3e9cbdd92770694c8174e055f420ae67d26718260e27n/aHeodo
2020-08-20Invoice #15811243.docdoc ed8f3cd480b6fef9996f65e02cc1cb3d295447728fd009032ac3838d32e01f37Virustotal results 33.33%Heodo
2020-08-20KO0380 invoicing.docdoc 3fb4829564edbb691226f1298c052a8a39087d1a99e583bcca9781e9061b4c44Virustotal results 32.20%Heodo
2020-08-20Payment.docdoc 73edfc2aba2a5e763fb0b40b55a4695a6d9e6f0069b17e693c982385b150b4c7Virustotal results 32.76%Heodo
2020-08-20INV_0848.docdoc beb2d3691a0096ad6f8d004ee7df158d8580aa530e57b2872c943df21d056b60Virustotal results 32.20%Heodo
2020-08-20PO# 08202020.docdoc a5257e575894b7fdceb18f36985ab8d6394e335b4458d40dc376703089368bb7Virustotal results 32.20%Heodo
2020-08-20Form.docdoc 5fa853ef0f61449fd95c38ca7e61ac05ab40c240e9d88e8cb0a80e9a3f8f82b0Virustotal results 32.20%Heodo
2020-08-20invoice.docdoc f25ca0039e633d20e45353a9f67a0acb290f060e311066c0c798e8cb031b0ef7Virustotal results 30.00%Heodo
2020-08-20INV_4339.docdoc acf06f69fc335f401184ad3a218aec5075641fe29bce91e0f71b698c062b3e0bn/aHeodo
2020-08-20Inv. 4207647943.docdoc 6d8877c3fe622e60ade68b560890183ab6a8f3808d4425263f61709f82496187n/aHeodo
2020-08-20Form - Aug 20, 2020.docdoc 78d50f9a994e6725152681b7a070cac90847542c838e5b17685cc21b237d7717Virustotal results 27.12%Heodo
2020-08-20Invoice 02125411.docdoc ae09a760faec9e5c8f9d147329271cb1fa3971b119943d8cc9e16ce71c8e5fd3Virustotal results 25.00%Heodo
2020-08-20INV #0027459 FOR PO #0696800732.docdoc 565a658a52901c5f0f0106f96c8e83c5bc9b0c91b259f8ece0aef34b546c57f3n/aHeodo
2020-08-208107239173NG.docdoc 722219128e30ae7a17fbcf0d24147c7713f628e28f3af2117130c95e0d75005dVirustotal results 22.03%Heodo
2020-08-20V1269381531RY.docdoc 3a9ab8d5a3d76cba944447091197434086ecae7e4ba97affdb86c17fd77c31b3Virustotal results 22.03%Heodo
2020-08-205657977.docdoc fb7cec2bb2ac4c31c65e299f198a586f5c5918f975075467063f59d48d28844bn/aHeodo
2020-08-20invoices 877 & 7457.docdoc 111c13b918e6e6cda308dc7c64d2e4ddaeed1d7dfcfd5f3e27b811cd3e22096cVirustotal results 22.03%Heodo
2020-08-20Invoice 0047962.docdoc ce4cd4d124a577ac6f489568a077a53e6745170cb71a64c5b4bcba502af51347Virustotal results 21.67%Heodo
2020-08-20Form.docdoc 700b22e0508a889751892ce66df22fe34fcf52222db541d24e6d338aa351cfedn/aHeodo
2020-08-20Payment status.docdoc 65d358d5c25eda27078f168b3fd190c5250bfdf1b58bceb28681f2535de96423Virustotal results 41.67%Heodo
2020-08-20invoice.docdoc 35cdbc32f50870b20e2cd551f4805152d7ff4c9a9977739de4036d9fe76a6e0cVirustotal results 40.00%Heodo
2020-08-20068598.docdoc b462b6985f21115db5a18167bd1701f4a2599116fe237a0156cc2cce93e96edbVirustotal results 38.33%Heodo
2020-08-20invoice #792433.docdoc c500d1d7cc11d82b241b378d7e3015d381ddec5170984b634f89786580b27a24Virustotal results 40.68%Heodo
2020-08-20PO# 08202020.docdoc 96724ca5aa5c891ca6a5e5ba740b3ec303445857cfd63cecc5828087c6171673n/aHeodo
2020-08-20INV_22664.docdoc 210f3cffbbc984d2b04c012fb54991ba7cec609aaf5d6e97c4b7715fa179a770n/aHeodo
2020-08-20August invoice.docdoc f1a7f5de80b5f75e5e52318197ab69af5a862ec92c7d2c27680503abc81e989cVirustotal results 40.00%Heodo
2020-08-20Invoice #940.docdoc 252905fc07b8d4de77b22dd1c68bba23716cb7bfbf56bae15a624f59b7e69c70Virustotal results 38.33%Heodo
2020-08-20August Invoice.docdoc a0601dc3c3afeb7471b9fe739ce24e0b476d100c3f2ee756df211888184f67f0Virustotal results 36.67%Heodo
2020-08-20V0555 invoicing.docdoc 42c878ac8d64be01ebae36247f206a89d0802d503c19e81d187ed9f1eba96bf9n/aHeodo
2020-08-20Electronic form.docdoc 3873789add951f7faaee58644422e134440be2903271725124cff640acd0ad4dn/aHeodo
2020-08-20P006 invoicing.docdoc 416a4f17b5bc066941020cd43640276363268db7cb067a8cc7f1d27c3cb3cdb2n/aHeodo
2020-08-20invoice #1753.docdoc fa10393ccc08487ee9b80a41d01c9e5e87c3c7690a74327b1b19e47f3638b66cn/aHeodo
2020-08-20INV #40742 FOR PO #0098565104.docdoc 2cceef317fac265bf56fc5819196f6a58b95574e8085a889f61ed9cd5c6c387bn/aHeodo
2020-08-20Invoice #17762.docdoc 741eedc40d043df1d8abba1e18fdeab3d276fd970087ad3b980243aba3c4878fVirustotal results 38.33%Heodo
2020-08-20INV #8941320 FOR PO #002350172455.docdoc 04a14a477cf1d1d2e5a426b932542d931d6264a101a10da26141be2752db8a72Virustotal results 38.33%Heodo
2020-08-20Electronic form.docdoc cf817564329bd4a2f3c9cdb4ce0609048d648917967fa9f9ff5c05a656ee3cbfVirustotal results 35.00%Heodo
2020-08-19Payment status.docdoc 8fef0fa03aec63f50c5f6c1b055fc5c7c90f092a2b4549ef022e6696d49c9bb7Virustotal results 35.00% Heodo
2020-08-19Inv_3085.docdoc d225f5ee78fabc34f19b2f3cce92c9ba74649bd52222615bc3c7d4301e1d174dVirustotal results 32.20%Heodo
2020-08-19Invoice.docdoc 52274ac77bd957e5400288626360e7b9fc44e218e8d61cd67dbcc1a8db036389Virustotal results 28.33%Heodo
2020-08-19invoice #3465.docdoc ebf3882fc3552ee25191b706c94ec2567d1e45467048c7182c3cd8fde34cd4cdn/aHeodo
2020-08-19INV_8052.docdoc 9271eec0c9ac0b607ce4f61e6a1af1443a1dada74751a30a1824022f5997ad93Virustotal results 26.67%Heodo
2020-08-199649228001HF.docdoc e2b049254060cf2643d248928331a6a30efdda3762f6a91a881524e30263ae09n/aHeodo
2020-08-19invoices 8535 & 50223.docdoc 1cb2ba7d956a3d1741b3a3599aa84b917cb9af9e2e9e4a7814f0bef5f2abe48eVirustotal results 27.12%Heodo
2020-08-19invoice #9392.docdoc 8d136c6149af9434f3a7334e66ae1f5a885e56429e82ff5b571a7abc0157a4a1n/aHeodo
2020-08-19Form - Aug 19, 2020.docdoc 4654ca7f802a5318152bce8edcb6ebe13663e50c1a5a10b463a7a355a52e316cVirustotal results 26.67%Heodo
2020-08-19Invoice #0205.docdoc a23ca8534d64de0d28633de7ca8c1802694a85fb66d51390b0344a3996a49480Virustotal results 26.67%Heodo
2020-08-19Payment.docdoc eac2ef6babf8ef83b1d3950d9091c0fb3c9977734c81523a9211956563a300d0n/aHeodo