URLhaus Database

You are currently viewing the URLhaus database entry for http://roovers.ch/wp-admin/docs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452424
URL: http://roovers.ch/wp-admin/docs/
URL Status:Offline
Host: roovers.ch
Date added:2020-09-03 13:24:06 UTC
Last online:2020-09-30 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 13:26:15 UTC to abuse{at}hosttech[dot]eu)
Takedown time:26 days, 11 hours, 7 minutes Bad (down since 2020-09-30 00:33:52 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-25DOC_MU8134251705MM.docdoc 61cd59ff294c4182db774060c07b523fe5c3ebaa2678666cfac6d6f94094aaefVirustotal results 68.97%Heodo
2020-09-03REP_5T9AUVXYNVOCW.docdoc 5409880fabb9de24e36672731b1b476ef1c2082fe37e29bb338234ba6b7b1815Virustotal results 23.33%Heodo
2020-09-03D_71946094479021553.docdoc ace15062e2fc2ddffcccb9d8fbbff16098fd1bc75df09872b348e88477a29436n/aHeodo
2020-09-03REP_IFN3TG4DHG93E2U.docdoc 60dd3f4a133e10595239d79547e9f71805c2964f5c3715cb7c4d3e288b7029e0Virustotal results 22.03%Heodo
2020-09-03REP_56083213.docdoc 1f6bddc9ff487e35f1a1961922465830f538914af66d1cde543512522b507ff3Virustotal results 21.67%Heodo
2020-09-03PO_09032020EX.docdoc 192196a1e2ffa9b3df114933a8cf502c0295683ccab476164fd550c0516b0ae8Virustotal results 18.37%Heodo
2020-09-03INV_00017971882.docdoc bbb3e007c16c05c191d8e46391c8faabf2fec9e945d104f4179e4f31cc364cdfn/aHeodo
2020-09-03U_5138250770120640792735.docdoc db3090327dbef7e8bb3596914086ed8fac2133441237928f69b74ce4981f6a2bn/aHeodo
2020-09-03BAL_0388057296.docdoc 7b5836662cba4f5fe9b0f77dfc795736f639e2a412e9ba770e1fecde78b55e7eVirustotal results 38.33%Heodo
2020-09-03FILE_R1VTQ13TJ.docdoc d8363d508ccafbfd2dd1890c45f8da5dcb47d70f3cdcff9bbc4007c52735a959n/aHeodo