URLhaus Database

You are currently viewing the URLhaus database entry for http://centrolegnoambiente.it/test/http:/FILE/FFDMjocqzsSfcg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452229
URL: http://centrolegnoambiente.it/test/http:/FILE/FFDMjocqzsSfcg/
URL Status:Offline
Host: centrolegnoambiente.it
Date added:2020-09-03 07:25:10 UTC
Last online:2020-09-04 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 08:40:09 UTC to abuse{at}hetzner[dot]de)
Takedown time:1 day, 12 hours, 1 minutes Poor (down since 2020-09-04 20:41:35 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04Inf_EZC077218.docdoc ef5176343779eaa99518b910aea7bc09e3f3c68b84d581e4762ede0c68729a0cVirustotal results 36.21%Heodo
2020-09-04rep_2020_09_04_L342.docdoc 74f31456977a691fa6c56243890fd997e0ed0e2793ec4b6e1df8e8a0c93a22cfn/aHeodo
2020-09-04MES-771.docdoc 0d5e301807f834486dc3a5e55e4e04056e56cb6b8a2f2136c64f55a0ba12f1f3Virustotal results 35.00%Heodo
2020-09-04104E 2020_09_04 RP20162.docdoc 20f0a0ba4cd0dac615e918dd489d36a9dbe9da8eccd28074379ccb9297f44202Virustotal results 30.00%Heodo
2020-09-04Q201 2142388.docdoc 6f31bd1153d2df05467ef71f87e24e1047404aa3db93a6b3b5308314c7cf8735Virustotal results 29.31%Heodo
2020-09-04Arc-3855583.docdoc 3b8964cde0e41b835a06f77a2d1834dac132f78cdebaf8b6e89214daf39b8752Virustotal results 25.00%Heodo
2020-09-04FILE_2020_09_04.docdoc c3afd70cc30e60c1fae7b65640d51b7159da05bab6783ad90ee80869abc39d81Virustotal results 21.67%Heodo
2020-09-04File-2020_09_04-57797.docdoc eb2264ac02ea6f6ca9efed74315f140e86357be821112bba1c3b3a1f8b70e8c5Virustotal results 27.12%Heodo
2020-09-04MES-4897.docdoc 49ec67eefb48b7b1a629efed9521bbe30dfbaea3613d39d4fff12162ea10d59bVirustotal results 26.23%Heodo
2020-09-04dat_3590.docdoc 21b9cc274053728e137bd7758073d320efc12110b9756712aa7d806b7205b1e1Virustotal results 27.12%Heodo
2020-09-04Arc_G59920.docdoc edf870edb55e5142744c18f6834fdb1518565ccaca223c5375787ae927ef4a3eVirustotal results 22.41%Heodo
2020-09-04rep_20200904_815467.docdoc d9c975b6db619552db6df9461b3c0947dbeb829698591386f2c86994a414e005Virustotal results 23.33%Heodo
2020-09-04List_331.docdoc 987e6058bcbb6e6830567bcbf092de202f9fc61bc7b1a6f282f6ee741685e442Virustotal results 43.33%Heodo
2020-09-04Attachment 20200904 U668490.docdoc 03cb9a738ad3ba7f5744d092532b2e578e9ade9b376af945fca5faf115b06c4bVirustotal results 40.68%Heodo
2020-09-04rep_2885.docdoc 2fcecf7ef769ae49ecdf3905e7c5e7aad9a7f0ac4279fe518ed0108f25a0ec79Virustotal results 39.34%Heodo
2020-09-04Untitled_2020_09_04_C956032.docdoc f1d06faa66ff49136e73546caaa462dec1fc01c209288126d019c0c688f6f5d9Virustotal results 40.68%Heodo
2020-09-04Rep-2020_09_04-Y988.docdoc d771bd380512ca62d90490660909fd428aa582bd97ee49d263deaa6334170f65Virustotal results 38.98%Heodo
2020-09-04File-2020_09_04-77910.docdoc b0eafc0cd064f11cf1aaea20c1f55afc0770f81b4a59723d453b1ea6f6dd276cVirustotal results 41.67%Heodo
2020-09-04635577_20200904_UJY0864.docdoc c9760ed3a6abb462e2d429280f83f0e912114c2b1923fa1fec74b3ee350afa78Virustotal results 40.98%Heodo
2020-09-04rep 2020_09_04 N618.docdoc 479a6416cfb665d2d0f0b6e39d11282a0d31d799d87898d50f066e8d564808f6Virustotal results 36.67%Heodo
2020-09-03Inf-20200904-Q7526.docdoc dec0fc4e4611e340eb402f29ab07769dcc51d4a2806a8aa520f4332aca26f2dbVirustotal results 33.33%Heodo
2020-09-03arc-740.docdoc 184ba331ed727480fd65743bfe0cf1489eca3b4d49b68a31b970ee96288c9484Virustotal results 30.00%Heodo
2020-09-03REP-2020_09_04-U678181.docdoc 7e3a1e6d36b83671b756096e60fc53cab42b64bdb208c976b889540d6e90bf17Virustotal results 28.81%Heodo
2020-09-03Attachments-TRN8799.docdoc 2bb99d9824b62fad58399309008db0c35224a435f3128a9f1104bae218fff192Virustotal results 28.33%Heodo
2020-09-03INF-2020_09_03-E7457.docdoc 11a48462bad54a423a4107a55186e4d10c0ec205bd1ca12673171f08fdfba500Virustotal results 23.33%Heodo
2020-09-03Mes LHQ434458.docdoc dfb1031ce56f9f39a32ed410629d9f46e753b4e0671d121c063d52a7a23785f8Virustotal results 22.03%Heodo
2020-09-03LIST_20200903_ICH79483.docdoc af81984de14d081c2a5d015a4266dd625fd7eb4153810cb71c2ba3e9dbf382ddVirustotal results 23.73%Heodo
2020-09-03rep_20200903_069912.docdoc 1695d227dfe87081d279c0a10163f9230da66348eda90255188700c874414c8fVirustotal results 21.67%Heodo
2020-09-03Untitled_N952.docdoc 1303dae3ca87ebeabf89fa7f128b36a1041846f829eed086f8533d9975990e3dVirustotal results 25.00%Heodo
2020-09-03ARC 20200903 9139891.docdoc 7a10fa5e42ffaf9baddc54567556ebe14f3b6a31b1c4cd39193fc742546d6538Virustotal results 25.00%Heodo
2020-09-03MES.docdoc b14443ae26e257ef4d41a942b378470af758b31d9c8d7946861ebb13f8f853dan/aHeodo
2020-09-03Attachments 20200903 GN786333.docdoc 8e0ae601e353b70b9a13a7fda1f70f4739bc059c0ecb33bf2d0f4e767e2a3ba7Virustotal results 21.67%Heodo
2020-09-03mes_20200903_97965.docdoc 22f195db5856009d2d9a8a6c82daa0ba4e31d3970ae907e9311cbc5c94925ad3Virustotal results 19.67%Heodo
2020-09-03ARC 2020_09_03 C180.docdoc 735617818e8d2ea0cf674f7722f0a4c73128aed869e1adffb63f34567a9d4647Virustotal results 20.00%Heodo
2020-09-03list-654.docdoc ba5d47affe10f685d8cbc505b5923e061650d9bce4d07c4083738ad27de2ae53Virustotal results 22.03%Heodo
2020-09-039683P-2020_09_03-733984.docdoc 955f576da964c0e5580c88d090c71ff4d9dfff999abc142c5e4efea6dbd04112Virustotal results 22.03%Heodo
2020-09-03Rep-2020_09_03-R249.docdoc 2f9bf5d35451e037422e2b366dc024aa5461f020c7ea3bda3212b0a354d568e8Virustotal results 18.33%Heodo
2020-09-03Inf 2020_09_03 PVN772253.docdoc 6cffaf302f33249146288f181c629138504d72143a68e3c79b67c5a9ad8cbf0bVirustotal results 18.33%Heodo
2020-09-03MES_2020_09_03.docdoc 4ea973ca28598a64c32b8e2730d1cd64bd552dae1422638aa0806b7bb527165dVirustotal results 18.64%Heodo
2020-09-03doc_2020_09_03_414.docdoc 21b54f9e86f5c5cc7386d77b189b766d1311f69089a12b40813c1d9e5aff9da2n/aHeodo
2020-09-03270BJ-2020_09_03.docdoc 36d696af7dff0bd2f9aebc78fd2630323026d8a4e56cf3307fcb02d958e4ba20Virustotal results 20.00%Heodo
2020-09-03Arc QSL118647.docdoc d7e28dd65d5aab6b17a6509ad8869ce65f0838f59de7b034f9a0ea7775a19c35Virustotal results 18.97%Heodo
2020-09-03Attachments_20200903_02662.docdoc 788c7b77559d2d0a88092ab0519e1d089d11d14ccb86c6f1a1a23f1b610de73bVirustotal results 18.97%Heodo
2020-09-03202-20200903-30267.docdoc cacf08dc29380900a46bd3ef7a8d9df051aae704102a5878816183cfe16caf1bVirustotal results 31.67%Heodo