URLhaus Database

You are currently viewing the URLhaus database entry for https://palafex.com/wp-content/INC/qN8iZfFuw9r5fAsa/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:615606
URL: https://palafex.com/wp-content/INC/qN8iZfFuw9r5fAsa/
URL Status:Offline
Host: palafex.com
Date added:2020-09-28 07:40:06 UTC
Last online:2020-09-28 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 07:42:13 UTC to abuse{at}arvan[dot]ir)
Takedown time:8 hours, 25 minutes Good (down since 2020-09-28 16:08:01 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-28arc_20200928_MB656.docdoc e2dcc502dbfd89abcc734d23ad35f6b20ebf7fce35ba4cf7aecb716acd5d9c71n/aHeodo
2020-09-28Attachments-037.docdoc 6475756c88e423c4da1fc069bcb97909e3c18ea68bd40164abefa00cd5aa4758n/aHeodo
2020-09-289757 2020_09_28 ZJB522252.docdoc 90b5f100db7341b2495c748b065e22c02cb9851a35759168f09d015710ac2f1fVirustotal results 32.20%Heodo
2020-09-28list_2020_09_28_J990.docdoc 8ed37594d6584e0799753a477d07666bf837b8b655d82f4e66efd1b236209e5fn/aHeodo
2020-09-28Arc A5780.docdoc 05d211a76b7dfa7c4cdd3b5865e73248164464f5a97c5b3b51e0b6e06fc6fda9n/aHeodo
2020-09-28List 9404.docdoc 1f8ec4f43a822987e0d084649f52bdcc439465804a71f47c8c6a086723feb4bbVirustotal results 30.65%Heodo
2020-09-28mes-GBH8217.docdoc c41f70d35decb29c3b6e8f406423d0747fb4bdbdd66c54a01cf86567c4ce603an/aHeodo
2020-09-28Mes 7583778.docdoc 3a9ad1adfb25f584b952d1ad565b13d074f0a2b396249138449c29016187e362Virustotal results 30.65%Heodo
2020-09-28Attachment MP822.docdoc 2dea2c6adc30cf2bfecbc99581061f715ec35d2a52592359fabcc6373ae63d03n/aHeodo
2020-09-28rep 2020_09_28 8889.docdoc b993db6027f3ab4a8a0bf84b89deebe50f9b01854a5849be661ca177a6ab6b1dn/aHeodo
2020-09-28INF.docdoc 82da3daffe6bec3ea5b8a5e9897d4491d5546f3205b86d40781b14ae8428c642Virustotal results 29.03%Heodo
2020-09-28Mes_20200928_PZ630994.docdoc f82b052393cee12ae48129071061e5ec4a8847598bb634cde1930bb8e3fcb21an/aHeodo
2020-09-28Doc_2020_09_28_NC2419.docdoc 91646523a0f07719b33e85b40459fc5b5f963597e0c28b080523878c5d4f828cVirustotal results 30.00%Heodo
2020-09-28file T34399.docdoc 393a299b00878cc2ee1144a56c9a9a50d7201d9e2a6d9f88a5100e0ea644ed25Virustotal results 31.15%Heodo
2020-09-28Doc_2020_09_28_NF61701.docdoc 8b9dc4a4d093ba6512626203861d2a2f870ea4e8c403392bff15b5994284473fVirustotal results 29.03%Heodo
2020-09-28list 20200928 SOO0767.docdoc 0e0e0433ed03da08a0f5c04edc298d1fb7d169e296a5395752903154946ee846n/aHeodo
2020-09-28LIST-2020_09_28-ER349127.docdoc 7927857c4b1dcec9436a825b84c90105e6ac82cc863b74f8aa821e36645fbddfn/aHeodo
2020-09-28REP_0667.docdoc 2be4930444a8fa58818baa0167214374b9bf0fe31f99d57f232bea1aa0e2daa8n/a Heodo
2020-09-2842440441_NF2413.docdoc 50bef11268e4a6c5d13e83800177e1957fad3d991f8ceea729166bac747f69faVirustotal results 25.81%Heodo
2020-09-28MES 20200928 AG999.docdoc 79a644f95bea07a6037876d6bb87d78f3b8086d125855ab70c4e8dde6943405cn/aHeodo
2020-09-28INF_L480534.docdoc 77a5ce5a7dadc4224e8c5948cb2fbc53d3de18ce501b6e403910c8c98b0cf7fbn/a Heodo
2020-09-28FILE_2020_09_28.docdoc 724c3e38a059659ba8ae1956b91aa8fa3d064d3f56c9123e518ffd02b32b4758n/aHeodo
2020-09-28dat_20200928_638.docdoc 984e84ac950ad50b540bfd1610b17d5c9c8b78c09f0645205575be175b5757ccn/aHeodo
2020-09-28INF_20200928_520810.docdoc adb275a9d586ffdce9c11b1682d836cfd913b9fb67846c7f0e300dda34c0a9e9n/aHeodo
2020-09-28UNTITLED_143.docdoc 4569bc2e1ac13672c6927936f038ddf0e88b3de1fff148824ea53136f3aa7c8fn/aHeodo
2020-09-28Inf_20200928_RHB503.docdoc 01bd1ac3283be5ae08dec7a54aa614d97721d276b8b567a98c0fde8337c7096bn/aHeodo
2020-09-28MES_8444.docdoc 87949cd6634619957742e08d726837cd882257e0e9073ba608adaa40c5e09851n/a Heodo
2020-09-28Mes OH3450.docdoc 060193c6b16cebe604d55e60cc04c738830a56bd46316ad3ba0f5ef26bc5b806n/aHeodo
2020-09-28REP 1377639.docdoc 5f1b8f44eea91442867d766a536c262db0c65a55021ee1dc853917d32c1f1776n/aHeodo
2020-09-28file-20200928-OI147566.docdoc 513c4099afc8ef304e95c9ec465b89100f31b849d422f051a854c4a28cbde144n/a Heodo