URLhaus Database

You are currently viewing the URLhaus database entry for http://fidelityplans.com/cgi-bin/2269262960819874/2MbC4DbbfCeb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:585834
URL: http://fidelityplans.com/cgi-bin/2269262960819874/2MbC4DbbfCeb/
URL Status:Offline
Host: fidelityplans.com
Date added:2020-09-21 12:23:05 UTC
Last online:2020-09-24 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 12:24:27 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 days, 13 hours, 39 minutes Poor (down since 2020-09-24 02:03:56 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22dat_B2015.docdoc ebcd92e0c8b4a39b32a927e85ba031a58e12dd9dc00b15bf1c92a1a1140886d4n/aHeodo
2020-09-22doc 2020_09_22 OV115016.docdoc f835beb865831ae2cd8c4e51c7306297bbc2fde80e0d0c7175c3ab543fae0a0en/aHeodo
2020-09-22DAT-20200922-D68655.docdoc 3a4fbf0f22071cd991a4eb2507569ee2d1e7d3042ad2b693f2f818c8e895f543Virustotal results 49.15%Heodo
2020-09-22Attachment 20200922 1807955.docdoc 8934785f5b6877f8dd468cbee3d8eb5b07b3ed41ccfbaa1fd2724287c6b58fc5Virustotal results 45.00%Heodo
2020-09-22Arc_20200922_755.docdoc 0d70d473dd82d66be63e961914b3fccdaac41677e69ee91706bb0be406144501n/aHeodo
2020-09-22inf-2020_09_22-1792871.docdoc e814569fb5be9f59f403da76ba7fa54d69f871a3fd93337a489fe6238df01276Virustotal results 44.83%Heodo
2020-09-22Rep 2020_09_22 K23248.docdoc a8193929a853df30fe24b8fab4982b0b2e0e980da1dd67074bb26ecc0c8e2ecan/aHeodo
2020-09-22Inf_2020_09_22_217992.docdoc b3bc13c79571b2cf77ab2ad7a593e512bbaf1bf61f0ac3eacb10e78e840cb9fcVirustotal results 40.98%Heodo
2020-09-22Inf-2020_09_22-HO956321.docdoc bc077632ea6bd7e0d83fe02cd1b706c078d7bdf7a18b0c1477c0c3f94d2f14b1Virustotal results 40.68%Heodo
2020-09-22Rep 20200922 39994.docdoc 89897d1c075f86847a7234b13cb4acc27b16a32f115215baef6c5d41b0f4d67dVirustotal results 32.79%Heodo
2020-09-22INF-24436.docdoc 021d815c7a498172ad0e8254073b4d9c3f83bc2f400602d64b02613e62b9fb9an/aHeodo
2020-09-22dat_20200922_80890.docdoc 264bebcec7d291b85da0a2b0a2bc5fa300b07c9612b461f7ad9f2d55dd4389b0Virustotal results 31.67%Heodo
2020-09-22list-2020_09_22.docdoc 1692576fa20b26d4b08f7ddf02890b29ee1afd8c20ae52aeb87abfbe023c7209Virustotal results 32.79%Heodo
2020-09-22list_26801.docdoc 6b4419d45974ab12fe3b7374e5821a249e8b7b426bb15389e6f70897ae85f630n/aHeodo
2020-09-22DAT 2020_09_22 03481.docdoc ddabac18016628a7b4e14df72caa0012c52af6a318df5c236615b4869b257546Virustotal results 32.79%Heodo
2020-09-22Rep.docdoc 08eddac7838ced651892ee94e145a639d010807c45f3bd00e9752dbc1590add9n/aHeodo
2020-09-22REP_2020_09_22.docdoc a817507562022f31451f066e1fa331d53cf580488007476987751c5c9b0113ceVirustotal results 32.79%Heodo
2020-09-22rep_20200922_W29595.docdoc ba2753c69b06b5198fcc5ab9d75dd5760f634a64845c40f9d1518228e8611079n/aHeodo
2020-09-22arc 021.docdoc cdf5919973d03aa5d92173567d3c3e48098f193247a8c61802af9c5bb0c10852Virustotal results 32.79%Heodo
2020-09-22Untitled-2020_09_22-60449.docdoc cbf5b0482bc2cdc04d1f4ffa6c39d4517ef6793289339305a64f7820553bdeacVirustotal results 31.15%Heodo
2020-09-21Dat-20200922-CDR11813.docdoc e555220f1fea5978ed71dd48c9b80f989ba259d12fed9b96cb8692e21a706971Virustotal results 31.15% Heodo
2020-09-21ARC 20200922 LC526360.docdoc f2936defc5fc2976c78eb875870a7e003a079975fdeae34fbc2a652f0b488ba5n/aHeodo
2020-09-21arc_2020_09_22_6776083.docdoc 49a768f22fd648f24523668ac5359d7496d4ec78072f12f3e65138eb3e54f94cVirustotal results 31.15%Heodo
2020-09-21list_2020_09_22_G782682.docdoc f58761d6abe3ad15dbd476209b0096437914904488af5c5be9aeeafa6d598a6bVirustotal results 30.00%Heodo
2020-09-21UNTITLED-2020_09_22-71070.docdoc a8516766300b452a46b02941f4c26fb6b396ca990d85f6e0b7f660e2c3129e05n/a Heodo
2020-09-21arc_20200922_1507.docdoc d15ee7beccb032c7bb054749f3921d769bfed37f38a5a877ff005aff025fe4b9n/a Heodo
2020-09-21LIST-726409.docdoc c1fbade9d5f7c2b5705288400f77ce167e2f71ae4bda087c52e2983d2dffbdf2n/aHeodo
2020-09-21Attachments-20200922-532.docdoc 9c45d673d87c9821c5a3f9801e5c0db6a1b24d57541186e603a80580f63e4276Virustotal results 26.67% Heodo
2020-09-21Attachment_2020_09_21_R894.docdoc cc422106d6dd2c41a70e946a117c310587b1beb090c9366c0122801bdbf0ab0an/aHeodo
2020-09-21File 2020_09_21 5363515.docdoc 29a072fcb55a3231d48a7dcd2c01e5e71d3feafe5481f97c769e8f238dc2afa5n/aHeodo
2020-09-21file_2020_09_21_Y29612.docdoc 356b82eeebe4eebc57579bc3932589783542b3b169a2f2c85dfa0c78fddb7ac1Virustotal results 29.51%Heodo
2020-09-21LL802-20200921-KO079693.docdoc 012c334db958a84f1f475fe44c1a86195a783c7701b6aadeec5c06b539158fc8Virustotal results 29.51%Heodo
2020-09-21INF 20200921 7166267.docdoc 817dfa0131f4686e1849deaf26ff7ffe1f5b2eb30526bc09a6753ce13185f502Virustotal results 26.67%Heodo
2020-09-21file 2020_09_21 CY910061.docdoc 716299f97023ee3e7f0a20ad1843ee7284684da8a503b9031fdaf0aac7e81671n/aHeodo
2020-09-21mes-20200921-HE609.docdoc 61eb0d422b0465e3df0a4d5167d820688c9b0435aa4d28b8a09cf216487399afVirustotal results 28.33% Heodo
2020-09-21File_BI9939.docdoc 06ff769ddd838638dd933879a8a930aeacbcae74bf6df79aa7c9899d90222eaan/aHeodo
2020-09-21Untitled_L376.docdoc 1bbe375d43a1851674a41be075244edd766ebcb1e62ca831450f11202cac82d1n/aHeodo
2020-09-21REP-2020_09_21-Y731.docdoc 1c1d6a7d2690d01c33afbde392a68bb12a53fd56aeaef85282b81661b0b06ed8n/aHeodo
2020-09-21mes 2020_09_21 PJ912723.docdoc 66cb8b7e3c4085898b6efb2c9b2d39cb3bd28f6fab85e83e70b4e9a3f441a22fn/aHeodo
2020-09-21inf_MRM3516.docdoc 3d53561b3bf1124d38edeb67519a5abdf7951c6ff3abe5918b8458b5e9f94453Virustotal results 25.42%Heodo
2020-09-21Doc_20200921_412.docdoc 70e273a60af8784db64021a4c41e0f4963ee67a02c0c3c1deb8aacbf74149a39Virustotal results 23.73% Heodo
2020-09-21dat_20200921_QW405975.docdoc 70dbc4cb021488253faec5d8447c680d8bf7285fe74e0728c0c8051719877104n/a Heodo
2020-09-21Doc 94646.docdoc d6b49fd8cd1ae8ef8187df86ab91bb6b2b0c19b4025834915102eb597a04e0c8n/aHeodo
2020-09-21Rep_93758.docdoc 1c207d713f338bdd9388fcbf5a62faf0bf73c0b4a555c1734b63d521952fcef6n/aHeodo
2020-09-21Untitled-20200921-90595.docdoc be9ecab012cc1458f1122eb7bea407629129263e22b0606c4c68046b82f55edeVirustotal results 23.33%Heodo
2020-09-21INF_2020_09_21_76097.docdoc e61511eb24b3cf59eacc8ee628d014e14b62fa3e2b8e041dc9a6a342db373472n/aHeodo
2020-09-211497081_20200921_ZWA543.docdoc d8ecaa9d0463137fbd29b7b0e44ec8225fd3fbc3d41a2734fce53ee0f7ae69e4Virustotal results 24.14%Heodo
2020-09-21dat_20200921_941846.docdoc 2b2348aa673f017c233082d9588e34d488754ac4e2aa9b3209d2079d29c7ccean/a Heodo
2020-09-21MES 2020_09_21 OUJ979.docdoc 603a954c14863f0d507744dc12a79e66e12df3a802cfb33e3cf52e5d4965c68bn/aHeodo
2020-09-21FILE-2020_09_21-361.docdoc 006eb3de7c7d6ef36973d365810c036529acdcfeb2f53c7b8d9d3f36231d584en/aHeodo