URLhaus Database

You are currently viewing the URLhaus database entry for http://municipolitics.ca/wp-admin/balance/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:588332
URL: http://municipolitics.ca/wp-admin/balance/
URL Status:Offline
Host: municipolitics.ca
Date added:2020-09-21 18:21:40 UTC
Last online:2020-09-23 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 18:22:51 UTC to abuse{at}idig[dot]net)
Takedown time:1 day, 15 hours, 37 minutes Poor (down since 2020-09-23 10:00:02 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22REP_XM3219571336XO.docdoc 3e7b30f4a48f9c8e35cb2a878c36655b2fd98de59c8c7bf9c7e708918584f2fcVirustotal results 49.18%Heodo
2020-09-22PO_09222020EX.docdoc 615c56cc17f59eb078578e1e87284456a83a3ed4427b94dc1698828f278148faVirustotal results 48.33%Heodo
2020-09-22T_BN7200484195ZA.docdoc 8d49090e5ad1ca487645e8dad8b6e90d267b4a7f5d4cdf4d9c4441d969f088caVirustotal results 45.76%Heodo
2020-09-22FILE_FBR_090120_KON_092220.docdoc 57ba4b4fdcb75beec5d6d63154dfda3510f28ac094da0ca819dd8677ca37a924Virustotal results 42.62%Heodo
2020-09-22XKP_090120_OYZ_092220.docdoc 49a1ffaa1b08021d92dd0139fad4b585e8b601c2ca7c74eca69ea9f3ff06ad79Virustotal results 40.98%Heodo
2020-09-22M_9405172569621332642875249.docdoc b014c2416d9b6457a33a1c69cb00a1183b6342db10f39dd9b9ed3ce8b14e3be8Virustotal results 39.34%Heodo
2020-09-225487411925396.docdoc 9607e3321e8b588ead936b5c46607981cf642a9a5abc9a7d1d0f7474dea3b6faVirustotal results 37.70%Heodo
2020-09-2259212738664.docdoc 718113e004b811df9d311a7edec1092b2aab2d9173d762022544a74b5ba02657Virustotal results 32.79%Heodo
2020-09-22UD8393109314WY.docdoc 58dca36db6814be3bc7016599693d84cc074f17451bebe7eb98baee99cef0ac9Virustotal results 32.79%Heodo
2020-09-22FILE_23920041.docdoc d9f03fa12161b634159a69d97eaf66f6e621ecf8cea896527a14510f0c7e4ad4Virustotal results 33.33%Heodo
2020-09-22FILE_16140119.docdoc 7cb0e900a796ae5c53375b1dca69897de5ffe140cb72224a428bcb8327937f23Virustotal results 28.81%Heodo
2020-09-22PO_09222020EX.docdoc b9ae26c8fc56943d82223a7d3c26671f4247a42d3d56fc25a455217cb84674b7Virustotal results 32.79%Heodo
2020-09-22806BHMGZPQE5S.docdoc c74d9dd73470acf660bc458fed146e653197422214956ce6dc4abfaa8a8a1544n/aHeodo
2020-09-22INV_1IX01DJJTKZ3IF7C.docdoc 09354d76c301e3e65f29aceb76a3bbfa8cd5bc590010a3eaf044b7050c3e61b1n/aHeodo
2020-09-22REP_PZ6232667275FB.docdoc 6f9bccda375580566f4824b5dad0662ea49be1f410eb2bd5c38f3561dbac29e4Virustotal results 33.33%Heodo
2020-09-22P_57785979.docdoc 62f036b925c8b4c5c90b88eaf15e774481a952ac6e1c7596916e10054b82daceVirustotal results 30.00%Heodo
2020-09-21DOC_57618158.docdoc 0ecb8f0ac3c2c27f213dff3752b70d6832343dd6e1ef7e95e066e0446ef384f8Virustotal results 31.15%Heodo
2020-09-21V_74902870.docdoc 0b406d237fa37888f1acd0ffc4b59577ffd5e45b792a835c2141483e2206ce9cVirustotal results 30.00%Heodo
2020-09-21REP_PO_09222020EX.docdoc eed638e68fb63c08e3dbe230dc2a66544170ba12c92aacb9571a99fe355f0878Virustotal results 31.03% Heodo
2020-09-21DOC_XNX_090120_EQX_092220.docdoc ce745f41bc3c216b25b5d553cff68854d633377995317973429dc64180aa89efVirustotal results 30.00%Heodo
2020-09-21DOC_CH9806255352KN.docdoc 04b6915557c386d4219e56049dca6eeef6f30b41f45fb525d36977e248fbf4ecVirustotal results 31.15%Heodo
2020-09-2149166657.docdoc e5ef583d80780947a6660111040fef17af94bb4a2b32611f0ad9605d8815e17eVirustotal results 30.51%Heodo
2020-09-21INV_EYD_090120_GSW_092220.docdoc 5ec6bed566afb4a94fb1fa92fbc8b964ed670f2627e8de8df3eaef0dee7e7f50Virustotal results 30.00% Heodo
2020-09-21DOC_36762574026998835.docdoc 5f48ec62b70130e2ebbdf504c0de8057499f87bcf6bda3462f498f3d2e08c22bn/aHeodo
2020-09-21YIT_33328872984936572705.docdoc 292a48621b6f7863d1a7d04f25cd2c6ddbcbf5abac1282941d3ba20ae076b776Virustotal results 27.87%Heodo
2020-09-21BAL_36920883.docdoc e6573ea6cfe0bdb4f9b3d43b7b68207d18fb492c9ed35aaf6bee52d0d681a9ddVirustotal results 28.33%Heodo
2020-09-216HV45YJL3ILQZLU5.docdoc 20c91a51721e21851a9378758513e3d0ec631985cab6f862b783627792f1f127n/aHeodo
2020-09-2140736644683317583.docdoc 6ca00f6d839ec9a1a0d786abef71fce3d2d88018968bbd427a8e2d25f6099c57Virustotal results 27.12% Heodo
2020-09-21SDFO_13269397696293390067.docdoc 9ac42de81707bd470c8974966355b1c4ab5b4be1ff55ffc4b0e38a197d1561c9n/aHeodo
2020-09-21PO_09212020EX.docdoc 3ab0702a3d820e15619e9125350d5275da998abed6d3231e31428a8443a2b604Virustotal results 27.87%Heodo
2020-09-21FILE_78818620.docdoc f87c10d05f454254da53ad0717ce0f42871dd7293e1b24157355fc0544ac8926Virustotal results 24.56%Heodo
2020-09-21REP_BRWRTPFR1VG2KEKM.docdoc b28378e6974a53507bdc9ccccae320e4998c79966ec3a03aa0fbbdd5465df93bVirustotal results 24.14%Heodo