URLhaus Database

You are currently viewing the URLhaus database entry for https://sleepingfire.in/wp-includes/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:516370
URL: https://sleepingfire.in/wp-includes/swift/
URL Status:Offline
Host: sleepingfire.in
Date added:2020-09-15 15:21:35 UTC
Last online:2020-09-15 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-15 15:22:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 55 minutes Good (down since 2020-09-15 18:17:31 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15FILE_31420786542566925.docdoc f733f45dc6ca4e5dc9d01f6bc3909048c7c04b203738baf9f96b4a5566c16a7eVirustotal results 31.03%Heodo
2020-09-154401496010.docdoc ba34bf775daa42ec9022cd46e6fc17cc035d968b15fd48a74a765e88acaec39aVirustotal results 30.51%Heodo
2020-09-1598868711.docdoc 920c6c5caca9705a67c7133db7edb7a9c9752f138bf9e2ce372169cca625b083Virustotal results 31.58%Heodo
2020-09-15FILE_FSU_090120_EUS_091520.docdoc 7183f98072abf96cb52a8cb67e459b8b465d6c544910b75267689dd7b3db059fn/aHeodo
2020-09-15BAL_PO_09152020EX.docdoc f52574630b28b46badc771430bea7ed4811951b7ac44b12af4cf6497f1afff4fn/aHeodo
2020-09-1534462011.docdoc bf726f4ccf307b79f32d968b3ec5145392bd3237ccf42905e75fa215cac2a476n/aHeodo
2020-09-15SF4268518941AU.docdoc 444ecd76408121efb70dedd5886e0d2042b0afcd9ad85a940eb6e027f7651082Virustotal results 30.00%Heodo
2020-09-15DOC_5726448879148980907.docdoc b7ea96d53b3ad1f4a6fd6ca60dfd5a4dcf1808bc7d58791a0d4c08ca5493744bVirustotal results 30.00%Heodo
2020-09-1550647911506407949297.docdoc 45add26a1868ac12bd1c2d6f44460f28a1e211c19c70cf4bb5fcbf2414ae2006Virustotal results 28.57%Heodo
2020-09-15FILE_342555069810252718555.docdoc e9d84f8bb530dcd12e764fcd7cb4515afc278f4de31a9a0f7ae4350ccf5da29dVirustotal results 29.31%Heodo