URLhaus Database

You are currently viewing the URLhaus database entry for https://blueswifttee.com/wp-content/report/zrdme98n/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:493731
URL: https://blueswifttee.com/wp-content/report/zrdme98n/
URL Status:Offline
Host: blueswifttee.com
Date added:2020-09-14 10:13:04 UTC
Last online:2020-09-14 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 10:14:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 29 minutes Good (down since 2020-09-14 12:43:40 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14REP_9840332978417788099.docdoc 44dd298e5761ecfbf28b770c3adc34854679aca9c88565aef9e0f7d426749cf9Virustotal results 24.56%Heodo
2020-09-14DOC_AWQ_090120_ZYS_091420.docdoc f14c6bc62e459f57fcbf3044108e087966c7f90e706b655248f9707410094bccVirustotal results 23.33%Heodo
2020-09-14W_BSY_090120_USS_091420.docdoc 11cc4036d50f7e705e15ad8d6b14813b0f328d9e14d31aa6ca51ba7e13fd4f4en/aHeodo
2020-09-14BAL_OGB_090120_DEO_091420.docdoc fdd3d83dc6ff712204b45d9dd5b04ccecce3d2dad4f20e24867c2737c3379081Virustotal results 24.56%Heodo
2020-09-14K_OCMT9RYKXK92D9.docdoc 33fdd2105c6792ea0096f87c5be02c0a4077e059d550eae962c72be773a41bacVirustotal results 23.33%Heodo
2020-09-14DOC_MEKMY3PMTI31.docdoc 86499f4888585de10a1b85f63ecf6af52670ec0819b7387470d9d2b2f5610ae1Virustotal results 25.00%Heodo
2020-09-14FILE_5LPH5VIWM409R1.docdoc 813835e555a57244f759ea1f03dd32d05bc472af33d6ed3c4ff22fc850798fe3Virustotal results 24.14%Heodo
2020-09-14INV_PO_09142020EX.docdoc 4248b1beb0bf8d0caa595316529c99e3a8511af5fc8c72cda777b837ff22c8d6Virustotal results 22.95%Heodo
2020-09-14H_9EX0SIDJGR5PAQ.docdoc d27caae7e1449d09d45bda155faf668fe51d33a672d9522522d7571bb1aa5a79Virustotal results 24.14%Heodo