URLhaus Database

You are currently viewing the URLhaus database entry for https://scootair.co.il/agm/http://sites/pxempVaepdfp6Lg1bq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:495908
URL: https://scootair.co.il/agm/http://sites/pxempVaepdfp6Lg1bq/
URL Status:Offline
Host: scootair.co.il
Date added:2020-09-14 13:12:05 UTC
Last online:2020-09-14 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 13:14:22 UTC to i{at}interspace[dot]net)
Takedown time:7 hours, 16 minutes Good (down since 2020-09-14 20:31:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14Mes-2020_09_14-INX35621.docdoc 8014f6ab3e277e6346b2e49fae79962948c0b264e7000be259601b0b715b3e15Virustotal results 25.42%Heodo
2020-09-14mes-20200914-PA4259.docdoc 5171e0e602e27c4122239e9c7833c603beebb69bea148c5d29341990af469f55Virustotal results 25.86%Heodo
2020-09-14192160_4140.docdoc 9071af554116b7e5e92cbd63922f2d577d1fd912ed4fd121ab0762aa8b2dd589Virustotal results 24.56%Heodo
2020-09-14FILE 20200914.docdoc 707c1063c30249706f5b47d56c8d6b057f13c1ba249b6fb0a9e86fced1ccc340n/aHeodo
2020-09-14rep 75498.docdoc 3172b64121f2b22437fb59afa7124acec2dde11e932b900ab8b1e038be9f8f08n/aHeodo
2020-09-14Dat 20200914 4010241.docdoc 41a5219800a60a147e301cb5ee472f45de2130aa095d82a52fa81121b5881860Virustotal results 20.69%Heodo
2020-09-14MES_20825.docdoc f463cf4d92f75e61f9c1a076fe61975011301f50d20a575e76b350fdaabf40c7n/aHeodo
2020-09-14Attachments 2020_09_14.docdoc 246d8db0406a7eefb66059e1c8e4d1c5ea419c31bc641f11ee15ecfda9f5eda9n/aHeodo
2020-09-14Doc 2020_09_14.docdoc 85b941aa2dfcdb8316fad92e43fdb207d52a3f4429b7bc59134fa759931284c8Virustotal results 20.69%Heodo
2020-09-14inf 33476.docdoc 3ab666907d1caac6699ea16ad02a0143d9478daeabc0fb3e5bd94199cb787774Virustotal results 20.34%Heodo
2020-09-14inf SPQ347.docdoc ded78c510ee2f226da8500b08b670bf12c44a6a21089ac843e7ad8f2329fd8ffn/aHeodo
2020-09-14Attachments_2020_09_14_265.docdoc e42ab2c33e334aaa8d441b35ee6af4cfbf0b44d94e1a27383f436682592d0560n/aHeodo
2020-09-14DAT 20200914 40592.docdoc 86c0ce7ddf5c6e12b271984c7724e66b7b8db3ccc611a9635d8482bc01c86931n/aHeodo
2020-09-14Mes_2020_09_14_26748.docdoc 41ce0360c56b981277f3b2de3460c5af71bffa20f9b751ab00659847c6cabb7bn/a Heodo
2020-09-14J4690 20200914 46840.docdoc 0b783948053f5f1dadd529527bbbea3e2ed5e25f1cfa250aca3b6620aac9c26cn/aHeodo
2020-09-14List_48646.docdoc 3c58efa8a1ff50a1c91b091da3d10d88c300e014f0685c2d003132d3aa4b4fedn/a Heodo
2020-09-1489316ZQ_20200914_845.docdoc fb254543c44a1cd539f80a6ad686889e82942bde7aebada34cfe594da563ce12Virustotal results 18.33%Heodo
2020-09-14QL162 20200914.docdoc baaec5d00f7f89c68159655fef4d04a1aec9f20f1e49dcbdaa26c1e1ae9e185dVirustotal results 21.67%Heodo
2020-09-14rep 24824.docdoc 709e80f7feba536995dab42bea3297f819ef278046977ac98457c0cf63b676c3Virustotal results 21.67%Heodo
2020-09-14MES 2020_09_14 W07163.docdoc c2f5c771367f5e275d2d357f32e68a89f7086770c1d060600199b2f41cb0e16en/aHeodo