URLhaus Database

You are currently viewing the URLhaus database entry for http://avsiii.gr/LLC/FQImUuy1XBikBj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:622634
URL: http://avsiii.gr/LLC/FQImUuy1XBikBj/
URL Status:Offline
Host: avsiii.gr
Date added:2020-09-29 11:37:05 UTC
Last online:2020-09-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 11:38:36 UTC to abuse{at}hetzner[dot]com)
Takedown time:1 hour, 44 minutes Good (down since 2020-09-29 13:22:50 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29File-6940044.docdoc 6742ecfe387572b5377d9dd4a476a24c98755c2594bbf861694e57750345e086n/aHeodo
2020-09-29615739 20200929 08804.docdoc 9858af3026287de59fb6de44a3f4292c9f370130a7183c08e450b4417e8796fan/aHeodo
2020-09-29DAT 20200929 OOI4935.docdoc 98ca5617082e699b7edf525fdceb3e43d181d5907503029ea680366ec177d376n/aHeodo
2020-09-29doc-2020_09_29.docdoc 61fa86d57f5bd8416845fdff78646dfb24b6c8e7da232d2e88d60190b629d366n/aHeodo
2020-09-29REP_5810200.docdoc 8f3f64a249482b0a6dd6361950555bb3bee2b9be6a613991d66eb5e221573bban/aHeodo