URLhaus Database

You are currently viewing the URLhaus database entry for https://site4.xyz/wp-admin/s2fjzyc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:587116
URL: https://site4.xyz/wp-admin/s2fjzyc/
URL Status:Offline
Host: site4.xyz
Date added:2020-09-21 15:33:11 UTC
Last online:2020-09-21 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 15:34:29 UTC to abuse{at}digitalocean[dot]com)
Takedown time:4 hours, 33 minutes Good (down since 2020-09-21 20:08:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-21X_939082371168.docdoc de262e7ac841a01fc0811e18b43ea7d4cdbd32e7c32e7c9e797ff0da640ba21dn/aHeodo
2020-09-21VMVVU7L5CVZWWW.docdoc 9ac42de81707bd470c8974966355b1c4ab5b4be1ff55ffc4b0e38a197d1561c9n/aHeodo
2020-09-21UYR28KX407JY.docdoc 4a56cc36977e419b49db6fa5eb0d8b67e62501dbb620c4f9abb24d6debf03ac1n/a Heodo
2020-09-21BAL_GW0373673137GE.docdoc 1e0ad6475aad3deb28ea9202c57b64589fd3638b15484a6f614fb7ae4879f071Virustotal results 23.73%Heodo
2020-09-21BAL_PO_09212020EX.docdoc ea13635d8fae6f813f3021e4d264e12f874aba0cadf496e53a82fdd80faf37e5Virustotal results 25.00%Heodo
2020-09-218363423036.docdoc 718a6bd57357ae4a5846096e897df2f41aaef2979454ab14492cc7c19d40760dVirustotal results 25.00%Heodo
2020-09-21DOC_JT0983167449TB.docdoc e04805dbc00956b3ba5cca341501b0653edea4c069a82449ed35ea1de79182dbn/aHeodo
2020-09-21FO_61915256570838.docdoc 9f20d4c02cc0a17cab07b9dd439952f5b036ebe4e1b1adf6bfd639386ce05eaen/aHeodo
2020-09-21REP_PO_09212020EX.docdoc f30920a67ce7cfe9432e60806e950e924a34e48196513336ca8700021da86303Virustotal results 24.14%Heodo
2020-09-21BAL_015948552548.docdoc 4a302af09a3467c26893b329b0646fc758032a20e47f1c6a9209d0fdc55d05edVirustotal results 28.81%Heodo
2020-09-21BAL_5667711142286523565605.docdoc 5bcff88fb7e7145c160caf05dd1eeaf462a13bcad2f037b87204026d0146a668n/aHeodo
2020-09-21BAL_VFN_090120_BZX_092120.docdoc 6a575ca5b22503dcf1dedcb3167a8a8a0ac67fcdfe51ce1ff906a8d2d2cd52beVirustotal results 23.73%Heodo