URLhaus Database

You are currently viewing the URLhaus database entry for http://www.emmashop.sk/sitemap/RQ3CTHF9JFJ32/http://eTrac/wSHEF1XQA4N/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:502397
URL: http://www.emmashop.sk/sitemap/RQ3CTHF9JFJ32/http://eTrac/wSHEF1XQA4N/
URL Status:Offline
Host: www.emmashop.sk
Date added:2020-09-14 20:20:38 UTC
Last online:2020-09-14 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 20:22:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 55 minutes Good (down since 2020-09-14 22:18:03 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14Arc_2020_09_15_PV3168.docdoc d99f28be1bd88f4eb8efcd54c021f9b248038aa19d71fe399be76813a24c2b25Virustotal results 31.03%Heodo
2020-09-14Doc 4276617.docdoc c53c6133584f62450a5d677c4e6b4d952099b50b10e90ed26e6a52053e476b1aVirustotal results 29.31%Heodo
2020-09-14Inf-2020_09_15-670369.docdoc 5215ec882e86e8604927d2f9da1a9ac3d0f6cb8cb2cf4b53441df2a10602bcfaVirustotal results 27.12%Heodo
2020-09-14inf_2020_09_14_WOF849003.docdoc 02c4c42898f589ca4b8505a9b02bf394ca4d4e2ddc375083c8b40342875a5bdfVirustotal results 25.42%Heodo
2020-09-14GP996 20200914 DJL3635.docdoc 06548426e927d2d19596c75a58b3dcd9cb31e0fe1090b0b24fa7d01870db5683n/aHeodo
2020-09-14DAT_509.docdoc 0aaf77ddbd6733d57e90b7a839a8eec42c677c110577bd60b7cb99d0e92371a0n/a Heodo