URLhaus Database

You are currently viewing the URLhaus database entry for http://www.associazioneinpiazza.it/wp-admin/eTrac/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:494860
URL: http://www.associazioneinpiazza.it/wp-admin/eTrac/
URL Status:Offline
Host: www.associazioneinpiazza.it
Date added:2020-09-14 11:45:09 UTC
Last online:2020-09-14 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 11:46:29 UTC to abuse{at}staff[dot]aruba[dot]it)
Takedown time:3 hours, 22 minutes Good (down since 2020-09-14 15:08:43 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14GUXJ_GZK_090120_QJB_091420.docdoc 6f94245cbc7d242d2ffa0fa4b3e3b3d5c9d3033df0482320fd014daba53f62e3n/aHeodo
2020-09-14BAL_UIV_090120_THK_091420.docdoc e080d3e47109955d920cea3412153304a44c6675154bdb704180405f9f36b099n/aHeodo
2020-09-14GI_68914579.docdoc 12820384810ee90b5f51be5c13e6c2a8ca47e4266660b1e3100722e4c2baa33bn/aHeodo
2020-09-1493952261.docdoc 8479daca0fc8e5a71c4658b54796c49513f4c6b45d048438213ec781db114c6bVirustotal results 21.67%Heodo
2020-09-140U8AGCI8.docdoc 3df3dbd30ceac68478a45ac4777aa409218d8ba43eed7546cd42682c95c17478Virustotal results 21.67%Heodo
2020-09-14F_156364038132828719083530.docdoc 9bd2a13b25bd80000de689abeba6e931e894f31798d57b111b8e3e4b8c784184Virustotal results 21.67%Heodo
2020-09-14ZFR_090120_TMZ_091420.docdoc 44dd298e5761ecfbf28b770c3adc34854679aca9c88565aef9e0f7d426749cf9Virustotal results 24.56%Heodo
2020-09-14DOC_JBP_090120_OBB_091420.docdoc bed57dded8f474e1685273acb47e279b76b699d0e2c44ac0f299ee924329f3a1Virustotal results 23.21%Heodo
2020-09-14INV_RL8127664685DI.docdoc 0cc20101093fe0717a459f14250ba02273813050342e588fed50e77c5b9e52c7Virustotal results 23.33%Heodo