URLhaus Database

You are currently viewing the URLhaus database entry for http://bonum.hr/wp-includes/Documentation/y652yj9k/xb01734960c6l56sejc7s58sy1e3uu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:446379
URL: http://bonum.hr/wp-includes/Documentation/y652yj9k/xb01734960c6l56sejc7s58sy1e3uu/
URL Status:Offline
Host: bonum.hr
Date added:2020-08-29 00:20:09 UTC
Last online:2020-09-01 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-29 00:22:02 UTC to abuse{at}posluh[dot]hr)
Takedown time:3 days, 12 hours, 55 minutes Bad (down since 2020-09-01 13:17:29 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-29GD_910782453113338231463485.docdoc 08a84bd28c3b7aed1f0c0dd3cf53c71afc707b41aceb34f8694e4a8f740d3f27n/aHeodo
2020-08-29INV_NN2293772994PA.docdoc c6b6b43e64de8dc117501dc26b4afbba6fac8241a1253e5058a91fea0e11bcb4Virustotal results 43.10%Heodo
2020-08-29LD6263408006OA.docdoc dd74db1005ce523b3ca1c828581efff59a07187ca1556d43437f51ff38f6396en/aHeodo
2020-08-29TG9KTZG5NK62.docdoc 244d9b70116c5920925ca6dd26e1b162e49daa93c561e5ae6d9d8ed195945478Virustotal results 41.67%Heodo
2020-08-29J_60510727.docdoc a342e0d2c55177e55b5c1e13c601b7f41278023007e0f3939e8b2b02a04f33a3Virustotal results 37.93%Heodo
2020-08-29BAL_XO3777958330JX.docdoc aada778a6ee21579478c37d9f766a74e2abfae033441a997ea715036316c9eefn/aHeodo
2020-08-29U_97496292.docdoc db5d1df258f52d33f22c630cbe8f27f55e548e910d8b851365ecc612bab09177Virustotal results 35.59%Heodo
2020-08-29LSV_II9521688206PC.docdoc 651697a7ad4735c29617111afdad056545ae1047760f46b4266c80cbd4b784aan/aHeodo
2020-08-29DOC_RF4375939642TJ.docdoc 01371d2802721d16a5f83938f491a4b8896161541b7f5cff1fd68a20f93f29a6Virustotal results 33.90%Heodo
2020-08-29J_PO_08292020EX.docdoc 157051ab74fe0a9998973c53b29676ad387279383f482890cf7e5cf173b66129Virustotal results 30.51%Heodo
2020-08-29INV_16772921262691.docdoc 1a0b2d954e4b0e1d3b217d9240cd26ab870841bb7b6fe7937de95e1e714f8c03n/aHeodo
2020-08-29BAL_47FGPPHZR5.docdoc ae8e02ab3bb1ce7ddd4f1f685e19beac9d119da9517273d71f36b6a8ff9952fdn/aHeodo