URLhaus Database

You are currently viewing the URLhaus database entry for http://faceshield4all.org/wp-admin/lm/cXg9ptMOo3eroM889jee/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:622503
URL: http://faceshield4all.org/wp-admin/lm/cXg9ptMOo3eroM889jee/
URL Status:Offline
Host: faceshield4all.org
Date added:2020-09-29 11:09:03 UTC
Last online:2020-09-29 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 11:10:44 UTC to abuse-ripe{at}hosteur[dot]com)
Takedown time:5 hours, 24 minutes Good (down since 2020-09-29 16:35:31 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29List-2020_09_29-XW66705.docdoc e4f183d90fb1ffff52cd04a42059d73ee2d9d3fe1f7403f80ff8b2ff9d07b52eVirustotal results 37.10%Heodo
2020-09-29KR275_2020_09_29_MCV548395.docdoc 4363623adc8c2dd08a6ef5b55d0c85821fb82629b809f2987d3f669080656430Virustotal results 37.10%Heodo
2020-09-29arc-PR335715.docdoc af16fa450a1498ff81000094039ebdfd9d1517f0002b86d9dfa214e1ae474636n/aHeodo
2020-09-29rep 20200929 TVP17353.docdoc 36363faaf4f9c78ef442d4f44ba04cf7e3f1bb1c65c1847492cdd10004395e19Virustotal results 34.43%Heodo
2020-09-29arc_20200929.docdoc 38b279f0aaa0e8e18af504e170e42b1fd63403cbbe5148d93639052b30e03fd5n/aHeodo
2020-09-29UNTITLED 20200929 O5544.docdoc 8adb2ad3f79413c51bb4d7e2dca8ead0ce04584f72ac03f1cfcb83b199c54a71Virustotal results 32.26%Heodo
2020-09-296830J 482584.docdoc ed8130dae0bd49af3066f45c3a331845416a6728ae51870d4c515c17ad13224dn/aHeodo
2020-09-29DAT-20200929-069347.docdoc 566851504a21da7b10a76ed1c310fd9fd54a664fa4ae91f9067bf8ea15bf83ccVirustotal results 30.00%Heodo
2020-09-29889437_5687.docdoc aef1553160a730913e114ff63310a0511bb11b89cc95e591abbe55dfc55f5098n/aHeodo
2020-09-29MES-20200929-RML93081.docdoc 235c504a271d6c34d21625ff2cea2273944ac5e054666fa3294e69c5d62e6f23Virustotal results 29.03%Heodo
2020-09-29UNTITLED-8390.docdoc 735040fdbf1b513dfe79b4c6485de58b176dba061ef76dd8a0cb42e8161551b4Virustotal results 31.15%Heodo
2020-09-29Untitled 2020_09_29 31470.docdoc 1744147705422ba1ed0be0001c21dc63732252c33941d438ee08ca97c4d8d48an/aHeodo
2020-09-29inf 2020_09_29 H003.docdoc 61fa86d57f5bd8416845fdff78646dfb24b6c8e7da232d2e88d60190b629d366n/aHeodo
2020-09-29ARC_20200929_K325.docdoc 85ba13ee16a5ff34d7cd00ef3c2b0b66b42a35a096a004ef4420420711e4855cn/aHeodo
2020-09-29Attachment_20200929_172.docdoc 7ef3f48a7d33e3c8add4458bddeac305c6a51f4471e8538420f255f3b77013f2Virustotal results 24.19%Heodo