URLhaus Database

You are currently viewing the URLhaus database entry for https://telemarketingliste.it/docs/Pages/oN4UNNyc4hR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:597090
URL: https://telemarketingliste.it/docs/Pages/oN4UNNyc4hR/
URL Status:Offline
Host: telemarketingliste.it
Date added:2020-09-22 13:33:33 UTC
Last online:2020-09-26 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 13:34:08 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:3 days, 18 hours, 57 minutes Bad (down since 2020-09-26 08:31:54 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22FILE_20200922_B84652.docdoc 4b28c06d34e565248875bbf66d52172c0b485192dcaab8144efa61fd00fddb5aVirustotal results 45.16%Heodo
2020-09-22File 20200922 MIK510.docdoc c02f344560f245e4228f6f218c205578449c7da6d58290a4e59fe7a1fc87a1c4n/aHeodo
2020-09-22QV502 2020_09_22.docdoc 1fc10492e6d6a535c0af806d123df88468d4afefebfe28547d5c088d2cc744a8Virustotal results 45.16%Heodo
2020-09-22Attachment.docdoc 1a43cd289434ce985a6f23e3a7118384784c6b27bf423e043c0e43c32aa0fa7fn/aHeodo
2020-09-22REP.docdoc 1f6ed2ece5d580a01e3e3afbf88bebc1ecd74f37e6fd2b256ecb855d82941667n/aHeodo
2020-09-22LIST_20200922_1117.docdoc f8be92f6e72e27aee1f0edb3b42e6823fb30804713b3c34066fe75a75c4bfa5bn/aHeodo
2020-09-22DAT-20200922-S316926.docdoc fe522973d24d82334e51ac782259df4894964c0d7ac3b4090ef77bb2b734377cn/aHeodo