URLhaus Database

You are currently viewing the URLhaus database entry for http://licoresseven.com/sitemap/browse/dZ5iWo9JwSqlGPM4Pg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:617537
URL: http://licoresseven.com/sitemap/browse/dZ5iWo9JwSqlGPM4Pg/
URL Status:Offline
Host: licoresseven.com
Date added:2020-09-28 16:28:34 UTC
Last online:2020-10-25 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 16:30:04 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:26 days, 13 hours, 14 minutes Bad (down since 2020-10-25 05:44:18 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29REP-699.docdoc 3e79f14f4c08406b5c877414b692137f49a9ae3e6916d5f3d670901e85cef51aVirustotal results 40.98%Heodo
2020-09-28File 2020_09_28 2795243.docdoc 77b5804ca65e6e556bb46c4de77e34f32705f31b967c3d171afebb4bf54671edVirustotal results 30.65%Heodo
2020-09-28mes_20200928_OD18315.docdoc 197a7cb82ed5a1f79ff6f518916a55b078c32f1550af80e923217ca5b18947f4n/aHeodo
2020-09-28Attachments 20200928.docdoc afd0c4b383aa028dbaa587c9cf8ceea3774ddcaf8444409cef14df65169f09fen/aHeodo
2020-09-28list-20200928.docdoc b8fc261b2c56eb9a95e800930bbd308d181852ec7b654646539f5e3994ef8d65Virustotal results 30.65%Heodo
2020-09-28691-OBW812739.docdoc f6f12692d3d01e737fb9b7a93ddcaf4d444352fcc4755ae7d45e92df5ef45ef8n/aHeodo