URLhaus Database

You are currently viewing the URLhaus database entry for http://altus.lt/wp-admin/DOC/OMomc211iaacsefuPT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:609045
URL: http://altus.lt/wp-admin/DOC/OMomc211iaacsefuPT/
URL Status:Offline
Host: altus.lt
Date added:2020-09-24 05:17:33 UTC
Last online:2020-09-24 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 05:18:07 UTC to abuse{at}iv[dot]lt)
Takedown time:8 hours, 6 minutes Good (down since 2020-09-24 13:24:25 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24list_20200924.docdoc a173c80617eccbb5abd724c6c42da5355329ffc94e544185e1401d97c9146964n/aHeodo
2020-09-24inf_20200924_96044.docdoc 162b68e90f80db94074b88af43ec09ef7e693ebc8626c339e22cc213b9433b0eVirustotal results 30.65%Heodo
2020-09-24list 9948.docdoc 0fdfd0bf5a70dcd3c4f8f8c8fca5f034d855255ee1cdd4aa4e9a477ac4329362Virustotal results 37.50%Heodo
2020-09-24ARC 2020_09_24 OBK85585.docdoc d7df1764d6ee3f05cac26772758e8d876695a053080d0bdad4942f7efce97c79Virustotal results 30.00%Heodo
2020-09-24Mes-5794.docdoc fc7879543753b7bcea43eb1a48828da5340206c3787f219a7425d3e9bf2e12ddVirustotal results 29.03%Heodo
2020-09-24mes-20200924-4024.docdoc 6d9593629624074aa0ff3f5beab0843fe2fd2ff42c041e36225bdb02d33b6793Virustotal results 25.00%Heodo
2020-09-24File 2020_09_24 MW2954.docdoc 035e659d05acb9a53616292d7d331fc86c3f656b2e12becc2ca65ef6e402992cn/aHeodo
2020-09-24Untitled-2020_09_24-S3606.docdoc 439df4997262d2db8e015f7449a8b33c9bf2c8db09f8b184d69c7ad6fe968c92n/aHeodo
2020-09-24File 20200924 BH5179.docdoc f2c7d90066ac63d3c8a2d60a9c45fd32b1be782a30f661a0dc4b81881fce3e45n/aHeodo
2020-09-24REP_IMU786251.docdoc 6dbe352bb9203a1b268ab47b35f5d86b3f309a8e2595f8ece915bd547bc9c33fn/aHeodo
2020-09-24729139_2020_09_24.docdoc 424142c72a5f651cfc78a656b87c861ac6e4ad7b676e2fd65308442098e9ae81Virustotal results 19.35%Heodo
2020-09-24inf 20200924 0891654.docdoc a5264b385908654132710f245c022fec904e276133d84597ed28de163faad508Virustotal results 19.35%Heodo
2020-09-248078_JR831938.docdoc 9c73f265f8eb72d356d419aa625d2771eef70cf83a3dcea8afddd57ae216d4afVirustotal results 44.26%Heodo
2020-09-24Attachments QPJ784.docdoc 77d05388e54ffc1cf04195a80a090cb3eaa41f8820c93c4c646f4f56cb6beffdVirustotal results 43.55%Heodo
2020-09-245142_62061.docdoc cef0a21256e2c9bb654f4f7fd0454fc6dc1795f3aa95862003eaa9e5c144ab42n/aHeodo
2020-09-24UNTITLED_20200924_4796.docdoc e7f6321d905f4db566091d8d4520f4d128bf66917cc86d794f1d435352ed2899n/aHeodo