URLhaus Database

You are currently viewing the URLhaus database entry for http://petafilm.com/calendar/statement/qh4q218454602270192tl8w9kg0258xkb5kw7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453779
URL: http://petafilm.com/calendar/statement/qh4q218454602270192tl8w9kg0258xkb5kw7/
URL Status:Offline
Host: petafilm.com
Date added:2020-09-05 06:16:33 UTC
Last online:2020-09-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-05 06:18:03 UTC to abuse{at}cizgi[dot]net[dot]tr)
Takedown time:21 days, 11 hours, 23 minutes Bad (down since 2020-09-26 17:41:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05BAL_3D7GWYV2X.docdoc 8b23e164f16ba0caed21611db9782895ac3a6a1f5b30a16e7cff6a2f8e3c3008Virustotal results 44.07%Heodo
2020-09-05F66NT42.docdoc 7813e0676b9ac895750acf882aa69b95b64a212515208262219dd072a51117cbn/aHeodo
2020-09-0509476176824640672804959.docdoc 3c64a79cdd49b1710bd9042cb9988c215e0050e9ef57e604f4679c45abcafd73Virustotal results 43.33%Heodo
2020-09-05PO_09052020EX.docdoc 7888c29713425a14d1a374dfad7e3ba568408a4c756f476461f1357fe69699e6n/aHeodo
2020-09-05REP_PO_09052020EX.docdoc d83081d1b25e45eb05f1adfa2a4cb89811fab54011eac620b3d3d83b6e59b451n/aHeodo
2020-09-05REP_BSV_090120_HZB_090520.docdoc 2e997a833026463ee1ddc2b571d97d90c94ac88cdb614cc5e5803d48b640391cVirustotal results 43.33%Heodo
2020-09-0518797759.docdoc bb9c837b1bd4fe34cf3377a063261449907bae9ffec1af75dcfbe5fd01ec9a7fVirustotal results 22.03%Heodo
2020-09-05INV_TNT67MI5HY59A3R2.docdoc f2c72c50487b631344d96edddf586d9e99c4685edb37450bade175f676504f32Virustotal results 40.68%Heodo
2020-09-05FILE_90105200.docdoc e58920e12dd5ce571200cf0e7449728756bbb8a0b43d301ea7a625b5d7755c1en/aHeodo