URLhaus Database

You are currently viewing the URLhaus database entry for http://helplifeglobal.org/wp-includes/sites/ZzFNrEZQJd7AKyLZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:618603
URL: http://helplifeglobal.org/wp-includes/sites/ZzFNrEZQJd7AKyLZ/
URL Status:Offline
Host: helplifeglobal.org
Date added:2020-09-28 19:23:04 UTC
Last online:2020-10-07 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 19:24:02 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 days, 5 hours, 58 minutes Bad (down since 2020-10-07 01:22:45 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30Mes_195447.docdoc 0a72f410fe5254890d7fa49499a305fe366a747e010e5e84cbb1e6f60c425b20n/aHeodo
2020-09-30DAT_20200930_Q502760.docdoc ce00e37ae25728419ee8bb78a1abcc5bad02bbd0dbf436d5051b7ff766f5985aVirustotal results 20.97%Heodo
2020-09-3037222410-20200930-Y577.docdoc 7464edd6b84b35d71ec4b891bd85c2918da1024f18f49f0e06192b440eb5f364Virustotal results 46.77%Heodo
2020-09-30list-2020_09_30-NU0979.docdoc ab29dfeede441ff65801a3bd6e00e12eb35038b0142cfdb133fd029ed7ec4ee9Virustotal results 47.54%Heodo
2020-09-30doc-20200930-840.docdoc 283272050a0c0d994dacc605e1d7009688c58c1f0998f8007647a9b92e8604e1Virustotal results 46.67%Heodo
2020-09-29Mes 20200930 0207.docdoc 8666706e9ee66b8e782269a6c387b2ce242c017e7507bc5d65fcbedbc021f2c4Virustotal results 19.35%Heodo
2020-09-29File 2020_09_29 791261.docdoc 15915a01d4795b2cdd261061864a25011d8856f97865e6538890f9259958392eVirustotal results 40.98%Heodo
2020-09-2833296489-20200928-337.docdoc afd0c4b383aa028dbaa587c9cf8ceea3774ddcaf8444409cef14df65169f09feVirustotal results 30.65%Heodo
2020-09-28491047-HLX866480.docdoc 672bfbd35877ee7731d1c2044f08adc0c99bb5075a364f5cf2c92a27f1424dabVirustotal results 32.26%Heodo
2020-09-28doc-20200928-VPQ15896.docdoc 0fd51cfbcba392cc2bb5b6a5f25cd2152dc138de07f14a577776677ac9351001n/aHeodo