URLhaus Database

You are currently viewing the URLhaus database entry for https://itisfuture.com/wp-content/Pages/GMsKI5ftHFAsr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:545205
URL: https://itisfuture.com/wp-content/Pages/GMsKI5ftHFAsr/
URL Status:Offline
Host: itisfuture.com
Date added:2020-09-17 12:40:04 UTC
Last online:2020-09-17 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 12:42:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 37 minutes Good (down since 2020-09-17 14:19:13 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17file_20200917_10091.docdoc 2dc66566b82af7322a37d69bcd0052bfc5e454abce37b101c7b6f3d715abdfacn/aHeodo
2020-09-17inf_2020_09_17_L49929.docdoc 3335005b1d10b660afc3bdf17651f15d892145971773989d9638aec5b012a015Virustotal results 30.00%Heodo
2020-09-17mes-20200917-M113.docdoc 05ce719d6bbe09bf2fd00e9ce8c5d8a14c173ba82dd5a361d3a34c95586fe45dn/aHeodo
2020-09-17Doc 20200917 23891.docdoc 8874f9bac5677edeb906a98fd6693db843325acb9e0d081dfb83e88d6cb36f4en/aHeodo
2020-09-17LIST_20200917_036.docdoc a6284c036a3af1f33d92b1448f0b013044dd98793337296c69a4fdc7af39ae29n/aHeodo