URLhaus Database

You are currently viewing the URLhaus database entry for http://comunasiriu.ro/comunasiriu.ro/sites/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:588325
URL: http://comunasiriu.ro/comunasiriu.ro/sites/
URL Status:Offline
Host: comunasiriu.ro
Date added:2020-09-21 18:21:10 UTC
Last online:2020-09-22 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 18:22:37 UTC to ripe{at}netserv[dot]ro)
Takedown time:21 hours, 51 minutes Good (down since 2020-09-22 16:14:33 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22DOC_8PE65VQ3D5.docdoc 6b58f3d639dbfd3f04c2534bac10583c7e2d0ba1e88ef31ebe443fc18f409a76Virustotal results 46.30%Heodo
2020-09-22REP_AC5955552214PD.docdoc 8d49090e5ad1ca487645e8dad8b6e90d267b4a7f5d4cdf4d9c4441d969f088caVirustotal results 45.76%Heodo
2020-09-22OX6042771517YE.docdoc 57ba4b4fdcb75beec5d6d63154dfda3510f28ac094da0ca819dd8677ca37a924Virustotal results 42.62%Heodo
2020-09-22Y_XU0899265245US.docdoc 49a1ffaa1b08021d92dd0139fad4b585e8b601c2ca7c74eca69ea9f3ff06ad79Virustotal results 40.00%Heodo
2020-09-22MGI_090120_QKQ_092220.docdoc f574d141e50f5f004b6d5b2932ce746ef012404c5bf46933947ad0ce3b397665Virustotal results 40.98%Heodo
2020-09-2223461684.docdoc b014c2416d9b6457a33a1c69cb00a1183b6342db10f39dd9b9ed3ce8b14e3be8Virustotal results 39.34%Heodo
2020-09-22INV_IW9550938338YW.docdoc 9607e3321e8b588ead936b5c46607981cf642a9a5abc9a7d1d0f7474dea3b6faVirustotal results 37.70%Heodo
2020-09-22WCES_PO_09222020EX.docdoc 76d7ce6a12f4c9d03615c5255b79835bb2cff27e86deb3cb790932cdca164ac7Virustotal results 32.79%Heodo
2020-09-22INV_45CPDN72IWM63LM.docdoc fb7120cd04c6c488c5a564bb24d9d155389d7cb8a0293e552dd385110bc6ec9fn/aHeodo
2020-09-22INV_37001240896597949080364.docdoc 9e25ce36733cb087f13b4a1c744a28856f2e1e878782893ac18e682ad0f2e842Virustotal results 32.79%Heodo
2020-09-22LA_EQH_090120_CFY_092220.docdoc b664feace8781e7ad1ed550dc5f1a66b77b73f75228c1898a1986b67fd543477Virustotal results 33.33%Heodo
2020-09-22FILE_JZD_090120_FBZ_092220.docdoc b9ae26c8fc56943d82223a7d3c26671f4247a42d3d56fc25a455217cb84674b7n/aHeodo
2020-09-22Q_35400564.docdoc 09354d76c301e3e65f29aceb76a3bbfa8cd5bc590010a3eaf044b7050c3e61b1Virustotal results 32.20%Heodo
2020-09-22B1SII34L.docdoc 0489a6b94e2c6206bd2730cc32c8f873d1ac1af2ad02bdb69a77a8078460741cVirustotal results 32.20%Heodo
2020-09-21INV_NZZ_090120_YBL_092220.docdoc f032da6342ee3da2b15c96ea27035574335bf6c5133bc03871bba1958206d66bVirustotal results 31.15%Heodo
2020-09-21INV_UCI_090120_YDS_092220.docdoc 6aaa5d1200a0ddb1900acfe0f5b79eac2ce5b928d30db37c4f21e43cea55d69eVirustotal results 32.20% Heodo
2020-09-21O_SPI_090120_WBC_092220.docdoc 0b406d237fa37888f1acd0ffc4b59577ffd5e45b792a835c2141483e2206ce9cVirustotal results 30.51%Heodo
2020-09-21O_GCJL9JWNH2.docdoc 74c1fc2f43a4a426a9f4ffbc4738e6107d95009d67a202f0c8a2a1b80ef60937Virustotal results 31.03%Heodo
2020-09-21PO_09222020EX.docdoc 5bb3e05266ae1854d7bd5732eface0a2f45a896e99c1d0ae15f6e70423b2a2d1Virustotal results 32.20% Heodo
2020-09-21REP_X2CND8ULSYUDR6W.docdoc 04b6915557c386d4219e56049dca6eeef6f30b41f45fb525d36977e248fbf4ecVirustotal results 31.15%Heodo
2020-09-21XWH_002102368153793.docdoc b0c1e64b3b04df99668587d56d89c513ced13de50d8596e1d49a2eac66c96049n/aHeodo
2020-09-21DOC_SQE_090120_EFQ_092220.docdoc e1e28e6b69d9f4ccb1171262803787c1c468b9b27924012d88df127d9aa1b480Virustotal results 30.00%Heodo
2020-09-21LVK_090120_XVD_092220.docdoc 778a7dec2a3a0d2021406e3186ff559dea78e4a07678dbf5619e3cd6d7d8217dn/a Heodo
2020-09-21REP_KU2397782042IH.docdoc c19dd05cf11f244d0b2189ff9b5075a190c1a64d8c65dd5f47a65e3bb8c2b869n/aHeodo
2020-09-21PO_09212020EX.docdoc e6573ea6cfe0bdb4f9b3d43b7b68207d18fb492c9ed35aaf6bee52d0d681a9ddVirustotal results 28.33%Heodo
2020-09-21INV_42534646169085441.docdoc 82db633a79ef7fe836d666e7da62a23e424e40387e257c949fdad5990b6d9e04n/aHeodo
2020-09-2168714408.docdoc 6ca00f6d839ec9a1a0d786abef71fce3d2d88018968bbd427a8e2d25f6099c57n/a Heodo
2020-09-21REP_OUV_090120_EJI_092120.docdoc 2d6a5431e61158153fef1258729585f1e960289a985c131147dee0f8918b40f0Virustotal results 27.87%Heodo
2020-09-21IA7394111934AQ.docdoc 3ab0702a3d820e15619e9125350d5275da998abed6d3231e31428a8443a2b604Virustotal results 27.87%Heodo
2020-09-21FILE_12532081.docdoc 1e0ad6475aad3deb28ea9202c57b64589fd3638b15484a6f614fb7ae4879f071Virustotal results 23.73%Heodo
2020-09-21DOC_WXQ_090120_VON_092120.docdoc b28378e6974a53507bdc9ccccae320e4998c79966ec3a03aa0fbbdd5465df93bVirustotal results 24.14%Heodo