URLhaus Database

You are currently viewing the URLhaus database entry for http://altus.lt/wp-admin/Reporting/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:590397
URL: http://altus.lt/wp-admin/Reporting/
URL Status:Offline
Host: altus.lt
Date added:2020-09-21 21:53:37 UTC
Last online:2020-09-23 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 21:54:40 UTC to abuse{at}iv[dot]lt)
Takedown time:1 day, 9 hours, 57 minutes Poor (down since 2020-09-23 07:51:56 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22REP_ACU_090120_BPL_092220.docdoc cfeb069142139e0b921f997e260a209c55d2c354c4f53a942d195ae1bcbbc69dVirustotal results 45.16%Heodo
2020-09-22BAL_PO_09222020EX.docdoc e9eef03a2437c273d0745bcc0b14df9ad8c3cb2807330029d609796172ad5d45Virustotal results 46.77%Heodo
2020-09-22VL_30816315.docdoc fddae37e61f9678e87dd4088effc157aa1c932c16c7be06fa4539a7eadb4eb26Virustotal results 45.16%Heodo
2020-09-22PO_09222020EX.docdoc 651691dcf8a659de6cc317f73356040f9fe108f7afcfcf13f037cb8ca348f061Virustotal results 25.86%Heodo
2020-09-22QG_66802302.docdoc d53df17a2862036c676e8cf55a990bfec4505f016e117d0d93bb07c274b1c4c6Virustotal results 23.33%Heodo
2020-09-22REP_64214437348090631514.docdoc 9787b45133bcc34be0a429c433382108adfb5e5d3f2636e5a2c818dea83b3118Virustotal results 25.42%Heodo
2020-09-22REP_PEUX6ZH11CO5L97J.docdoc 76fcaae92b446ead7ab43381902c83a62e16ff65b64003efbac7fc051a00f36eVirustotal results 36.07%Heodo
2020-09-22INV_335892847119490308233.docdoc 147931cd6cd520410cdfcf33828ba0741d200ea03e0ef1ca19e6537ff21cc254Virustotal results 32.26%Heodo
2020-09-22XF4502907126OJ.docdoc 3ed5e00e046ce19a840746219ff3efcd6fcc4ddd0b608e51203398bfe2360da2n/aHeodo
2020-09-22R_32705695.docdoc d937aee7869b57f5784a642a274c6c32b57ed26aaf0594e7adbbf3f980c4ff98Virustotal results 32.79%Heodo
2020-09-22BAL_KL3521581539XK.docdoc 7cb0e900a796ae5c53375b1dca69897de5ffe140cb72224a428bcb8327937f23Virustotal results 28.81%Heodo
2020-09-22REP_33526838.docdoc b47a1743a01e5885f50abb8a2bb9ad539a52c6b38e1fe97ace7c7165c384a523Virustotal results 34.43%Heodo
2020-09-22INV_4B4AGW1.docdoc c12ff20f228002fc1fd26b5e7c4dcede37847cda8ed616e187c81b2465874ed1Virustotal results 34.43%Heodo
2020-09-22BAL_VL2545494994PR.docdoc ed6598e7e6d37524439397ed78a735fe41117f47c0964cba780b5800d4eb5146n/aHeodo
2020-09-22RCST_UX4314468915XH.docdoc 9addba96a219cf69e04822cf43a65d6b7da0f848ac179d2276ef2a448ca362cbVirustotal results 30.51%Heodo
2020-09-22REP_59294032.docdoc ce04dad796a1819d846a6a981c97426c43b0943deed734991bc6780eb54ba074Virustotal results 30.00%Heodo
2020-09-21INV_PO_09222020EX.docdoc a09dd0e095d93b68eb0713e31e92eb9caee82983e99ddccdb71177216cc52f30n/aHeodo
2020-09-21HJG_ESXVNY302R.docdoc 61ba6999ffd23a0f22f6827b577e773e9d6a79ef366b3260a6b55a792c98d519Virustotal results 32.20%Heodo
2020-09-21PO_09222020EX.docdoc 86a8ee1c5f1f5ce84a8f3b31c04f51e324a47d2de0936339357ee0e9a139e0c6Virustotal results 31.15%Heodo
2020-09-21REP_4Z6RXPPMZCQWDZA.docdoc ce745f41bc3c216b25b5d553cff68854d633377995317973429dc64180aa89efVirustotal results 30.00%Heodo
2020-09-21009564705409738554291073.docdoc 539412deaa4405005d8f402fe43a5cffb4c1163e751e9cea52651a6a0f924086Virustotal results 31.15%Heodo
2020-09-21PO_09222020EX.docdoc 1ee23bc9e2a3807499d0fd736a4503235cc2d46e14429f19ff423fb2095bc38bn/aHeodo