URLhaus Database

You are currently viewing the URLhaus database entry for https://x4fire.com/css/sites/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:608607
URL: https://x4fire.com/css/sites/
URL Status:Offline
Host: x4fire.com
Date added:2020-09-24 03:15:00 UTC
Last online:2020-10-01 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 03:16:05 UTC to abuse{at}axarnet[dot]es)
Takedown time:6 days, 23 hours, 23 minutes Bad (down since 2020-10-01 02:39:40 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-25ZSOR_70921675.docdoc 8a73bdca97395b9f659104c200734008fe685faff6734fc31ce0cd575090f1b2Virustotal results 29.03%Heodo
2020-09-25104304600447654939730.docdoc 16caa36f21f51e55b03a66ef15c29a8f7054a5fad88ff372ca0bba06dc40a971Virustotal results 36.07% Heodo
2020-09-25AJI_090120_TVU_092520.docdoc 5527db4d50b16756417124cf891df4ce3d61c561eb2782f339973dc75c73390bn/a Heodo
2020-09-25BAL_ZO9804870821RA.docdoc 802f04236dcc8416e167f809dda60e5623b54d39bd04e74dd1f1db148afca2d3Virustotal results 31.15%Heodo
2020-09-24INV_6662433669404.docdoc 47e84b40c894119dda8c1abf4033b74ccdea7712d9ee871dde8360c87e7951baVirustotal results 20.97%Heodo
2020-09-24FILE_92807591.docdoc 733d8b10af3308cfd8ebc53724d8bcc6b47a2a8652e46f3dd15d87ab5ef7f123n/aHeodo
2020-09-246ENQCGTT31.docdoc 356e4701cc94b7ffbf517afeef9f5c0bbe45782f861d51859f0bf099df96581bVirustotal results 32.26%Heodo
2020-09-24VDX_94369731.docdoc c8e1fe8c16784222fdc737735ed29812a5f1721e61b75f3386fa6ea802c9b525Virustotal results 21.31%Heodo
2020-09-24S_PO_09252020EX.docdoc b77cd70861b08e97e103e926c367d38fb18c9588b70cce776fab3c7b9888c31cn/aHeodo
2020-09-246219674444.docdoc 72b9920e61919b7fc85e4427fa0bcad4d660a87904174a9f3bc2c7ae664ef434Virustotal results 29.03%Heodo
2020-09-24INV_469183663506284364595.docdoc 7b5d921ddbc165e0f75ae5769137ef1546084f5d3fad75d9304b97495a5966a0n/aHeodo
2020-09-24DOC_6346664648619996.docdoc dcffae4b2bca57b2e8b65609a127df9975ff71d81bc14a409f0058dba81ebb56n/aHeodo
2020-09-24INV_PO_09252020EX.docdoc a57fc009ab0a20443a4b85deb2d976357ec107017cceda370de28f76897500a7Virustotal results 31.15%Heodo
2020-09-2425447623.docdoc 02ef96f4a3c715053acf327bd61196658034d30887f0bb1a9769e4bfedfe0a41n/aHeodo
2020-09-24RGX_090120_UMV_092420.docdoc 0d6de09715c2540ddecff9f789615db1ea094b991d2a6417c3c086eb6e77e609n/aHeodo
2020-09-24DOC_40742477.docdoc 7ef0c540f3c535a1789981bcbe5e3dd3ba3809e8d6ef1a9745f00ccd018db031n/aHeodo
2020-09-24BAL_5594637398259194717964929.docdoc 2c9f95721bca3535da3fda89ec8fe49002a06a7fe0aa92c9dee5ad34872c388eVirustotal results 19.35%Heodo
2020-09-24TX2204740802BQ.docdoc e065d7a8263671a9d5afd66e671dd1d8cb12ccadcde39686f63b37c411d977ddn/aHeodo
2020-09-24DOC_44321369.docdoc 267834c0d23e344ce20d8814e0e5499c7f5bc32fbda08c9ebf721a3dcb2efe26Virustotal results 24.19%Heodo
2020-09-24OCB_090120_WDX_092420.docdoc f6f1cf12aa5337999c20c4cfd641254575e981ad7c463944cfe676ec92a23165n/aHeodo
2020-09-24BAL_DEC_090120_JMJ_092420.docdoc 1e8a41d3b5b66bf2151302e128b041ae3994ea9a2a0a688a098fb691a692e222n/aHeodo
2020-09-24FILE_1Y3XT92DEFNO2SF1.docdoc 32bbcef052b442f62a2fbb0c5dad498dcb779148f31f2e51d4f7a38245024f8en/aHeodo
2020-09-24PIMB_P69D4UUSGJFFD.docdoc f4cdb0cf1e18b01770cdf90fa136705d5e87332c022ec887a35615ed40f33466Virustotal results 20.97%Heodo
2020-09-24BAL_MFO_090120_KRG_092420.docdoc 8845dd7a737d5dc44971ca503bd120028edc33db789f8155a39c0651c11caf72n/aHeodo
2020-09-24FILE_078024684229.docdoc 460d4f1fa3c90d50ae0a56c6c4c26bfcd3d3d22829baef98b7ea3e9b451974feVirustotal results 26.67%Heodo
2020-09-2465302545.docdoc c84034e8688e0d58d35845c4ad72561fdedd79c6ec344ec1dc7ed759a126a7fdVirustotal results 31.15%Heodo
2020-09-24DOC_80741857.docdoc b56096621e87ab5d0c7d1a190f5c04257a84ab8e2da5d5335ae48f7759decabeVirustotal results 29.03%Heodo
2020-09-24UL6278465161FE.docdoc 910452e8c07c66c557c01772883f75fa0890c0e41b8d55b1107360949ccefc71Virustotal results 32.26%Heodo
2020-09-24J3G5XIX86EHGF.docdoc f97b2fe462e15ffbe47937e6d6ad815595fdb180d137a7ddd92f9f41e5a6b5eaVirustotal results 27.42%Heodo
2020-09-24RGQ_BAUWNGDR.docdoc fc98a386a0e52834ae5dcb93beb5aa33305f3e71cd4183a2e47c7c38d9cfeb1cVirustotal results 22.95%Heodo
2020-09-2468556492.docdoc 7e5a42a73c29e93f48c97d924845eef4cce7d6a931dadaa19068f78f4bb83015Virustotal results 30.00%Heodo
2020-09-24DOC_CJEE60FKW.docdoc cfa31ffa596077bda609cc5576b3f6218e479ddc4572a14827383aded91a7aecVirustotal results 25.81%Heodo
2020-09-24DOC_55515780.docdoc 33412abe08dc8633c45ced70426d58498a93ec1ace826525f5fb495459709ac3n/aHeodo
2020-09-24DOC_FKPD8BG85N2X3.docdoc d6f4d312b2434777abc97c10e41bb86186836a8a9a2e08b5365e301afae8d0b3n/aHeodo
2020-09-24CIDK_Y52ERK1.docdoc e5b9b4889b3cad8f0920a0d4153cab5517ce077683139476f36bc1bf91652725Virustotal results 21.31%Heodo
2020-09-2494699632.docdoc c8de91c5a698b19b834995d8d06dcfdbbd8147015a34eaf4fa99ccd6cdf012f9Virustotal results 20.97%Heodo
2020-09-24A_09605260.docdoc e009e8425fa0d5b45b611b840745257948eb8d154a75046329e7bf699f3a60d9Virustotal results 21.31%Heodo
2020-09-24L_PO_09242020EX.docdoc 9002b2aadfaa8b371cdf11d233531ba292b5dd90cc161bd7e132c3d49ce79fd2Virustotal results 20.97%Heodo
2020-09-2449981439.docdoc 3aa1d5ce7ed49ce9dba790282a20ea4768c173c06418f513522ee6d401aa527aVirustotal results 20.97%Heodo
2020-09-24BAL_73679415.docdoc 8b209e2d294b8c5b50bd83d9fd9184268ce21313f7d5876d74c7e10f48ac946eVirustotal results 20.97%Heodo
2020-09-24REP_HWN_090120_WIV_092420.docdoc e03588b5c327278e634c775b1f13c311c8aa3494cddd7aff114eab54dcae3c5en/aHeodo
2020-09-24BAL_5595862645604452502.docdoc 4d6a492ccf58a9712b96c0ce4443b1881fa7405bbda94ce7cc0a92ef06a2daafVirustotal results 40.98%Heodo
2020-09-24DC9TTEGOT.docdoc 19cb69cbc19879e5cae4e56b1d702cfcd04c72ebf8a9c795592d509a91e5a2eaVirustotal results 36.07%Heodo
2020-09-24DOC_61483166.docdoc 3b2da1783943899a3e23e20477670990adbde1f6edb9bb2e2ec1aa640c601f3dn/aHeodo
2020-09-24AK1560351795KB.docdoc c157afe5eb9208b3fe20c864292c3f7a3c1eb02486f1a6b31fd8ef0349a9f3fan/aHeodo
2020-09-24INV_EJ7974933707ZF.docdoc 7aed739ebb48064d94fa17f51816a7d3f4414ec8d578a6bde0830e844055e971n/aHeodo
2020-09-24REP_QEL_090120_ZZL_092420.docdoc 3b95077a69ba1ee1226face3a5f83a78950357b93815180ebb6b6772cf8212e8Virustotal results 37.70%Heodo
2020-09-2487W55WKI4RDKN6E.docdoc 89221a444d804e1d28751ac3f2cab050f02f3029ed849cea01f98def15afb0e5Virustotal results 35.48%Heodo