URLhaus Database

You are currently viewing the URLhaus database entry for https://www.peaceandfitness.com/o4x6cd/parts_service/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:496365
URL: https://www.peaceandfitness.com/o4x6cd/parts_service/
URL Status:Offline
Host: www.peaceandfitness.com
Date added:2020-09-14 13:41:12 UTC
Last online:2020-09-15 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 13:42:27 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 day, 1 hours, 9 minutes Poor (down since 2020-09-15 14:52:22 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14INV_US8K1PSKSN.docdoc 25745649b41d77ba129790a2a0c37f720f1e050cbe6ddc4a74e1348e41b59de9n/aHeodo
2020-09-14Q5CFIU75QLXZLVRI.docdoc 796be372786267239ea478d2b4acb8c5c1f6b4fb8e6f31a3a104bb12f29705fdVirustotal results 37.93%Heodo
2020-09-14REP_ACC_090120_ECH_091420.docdoc c1fe84c5bc07595ed1c451c7cd8d61f681f1252325096963b580e974a54dac0en/aHeodo
2020-09-1483HHCBKX0CSD.docdoc 6348c6adae8dfaa6f36c3c709f0f8df4e90d5af5b6fd5852657a6d825d18871fVirustotal results 33.33%Heodo
2020-09-14LFXU_PO_09142020EX.docdoc 2a3b8ac232c62d1a8020778231c0385bbc08ad42e9bed9599296e8f05bbf9b7cn/aHeodo
2020-09-14GYJ_0989885218269995500.docdoc 28af08585e9a6ba58d36d8e18f06e00def8d27ad158b4ceef0a99e6ad2200e9an/aHeodo
2020-09-14REP_JH4228150591ED.docdoc 60781dbe964b9ef97fc10a14503000232fd5f5dda1eaa6a1a3e4483842ffa621n/aHeodo
2020-09-14INV_JYF508ORV.docdoc ed410e106fe3f9f8bedec883afe4b7b0d0dea3b449ad26fa6f41aa69c0a78f80Virustotal results 28.81%Heodo
2020-09-14DOC_PO_09142020EX.docdoc a36f5c6dc52816437cc967d1fd281be98f7062ceae193435bf76399eb954767eVirustotal results 27.12%Heodo
2020-09-14EY_WB26849O.docdoc 689fced7b3ace08c6eb47364b3906facc22ef1bda292e9e5ac0141c215615987Virustotal results 27.12%Heodo
2020-09-14REP_5613662719976.docdoc a153e7d47a196c8848cbd1aa6b81d15adb43a1cc0c6402dca515ea34723c0ca9Virustotal results 27.59%Heodo
2020-09-14WYZ_090120_QYD_091420.docdoc a715663c0f5b4ac0c73cbdd8c485520c67b66dc4ec8daca63929942925339c8fn/aHeodo
2020-09-14BAL_ZHB_090120_DCZ_091420.docdoc 961f7feb40b5d924cb53607710a263c12a39f3ca1b6d3bc272a36abd04091a5cn/aHeodo
2020-09-145668123029344262978.docdoc e4a9024be2fd969f3d64de3bcff992a2d29ad69e823b5ed145c96a395a013e19n/aHeodo
2020-09-14PO_09142020EX.docdoc 2ff4b7d7b02e82dce1df902e65b025fe06a6a66e3e4605ada4206d0eb2e33cd5Virustotal results 21.43%Heodo
2020-09-14RD1474872705YY.docdoc 6c582c81ef9f686301cf1a663938a08c6f793a3f45403b3d4d87da94d5eefc00Virustotal results 22.03%Heodo
2020-09-14YB_YMT_090120_XEE_091420.docdoc e080d3e47109955d920cea3412153304a44c6675154bdb704180405f9f36b099n/aHeodo
2020-09-14F_9087531778002543134.docdoc 4a170e1b7b96802b718b6797122f073cf61e00a248332de84ba29c4c7a2cf30aVirustotal results 22.95%Heodo
2020-09-14PO_09142020EX.docdoc 29727ccfff36705a0638c4b0127fc5ec22be60f05d542fd9e9f0f49f6827ef54n/aHeodo