URLhaus Database

You are currently viewing the URLhaus database entry for http://anizonehealthcare.com/wp-includes/INC/9GuiD0Ix3Dj3EJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:624586
URL: http://anizonehealthcare.com/wp-includes/INC/9GuiD0Ix3Dj3EJ/
URL Status:Offline
Host: anizonehealthcare.com
Date added:2020-09-29 19:05:35 UTC
Last online:2020-09-30 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 19:06:26 UTC to abuse{at}phoenixnap[dot]com)
Takedown time:22 hours, 45 minutes Good (down since 2020-09-30 17:51:27 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30list 716158.docdoc 0c8d831dc603899f7ee798ed2307feb57bd13b252196a509a1b3aaf7a49a4ae5n/aHeodo
2020-09-30MES-2020_09_30-1186.docdoc d170d4853313c3d42e35cf2c19593158ef3d0bb0070faad32f65ddefabed67fcn/aHeodo
2020-09-30Arc-KMC939166.docdoc 070f607b4f349149ac149bbafca3314d4fdc3db65a0a3fc158b564f77d9ee460n/aHeodo
2020-09-30Inf-2020_09_30-1851094.docdoc efb4167bc0cff354c12bf008da6ffdd636d608141a89d9c77f85c40b28dcd31fn/aHeodo
2020-09-30Attachment 20200930 55284.docdoc bb859c1cdc55c8efda32c573ecc7e09c0692cf12de6a7c4bdc300e6e86456782n/aHeodo
2020-09-30Rep-20200930-WR011.docdoc aa5f51ed04026aad5af58f4d5ef9ab31771b70fb02bd536162e5ae19f6e3531bn/aHeodo
2020-09-30765508_2020_09_30_TID23192.docdoc 56d9f5c6f3b9609d176a3be72d243dac0ac9d0fee05660bd26fcee9d4e2d2b55n/aHeodo
2020-09-3025976 06850.docdoc 2e596652391370bfcf5e776a4379dd5061fcb4441200889c726c34ea6207ee9bVirustotal results 20.34%Heodo
2020-09-30Dat-20200930-217189.docdoc 3f2f431d2beac9bbfd418526316247a6127947dd8f0219adc6b281e6ac3cac38n/aHeodo
2020-09-30UNTITLED-R6080.docdoc 82581c6ad4b432cfb2c3782851f3838d3bbcd11897cacec6fe66f0453d0251ean/aHeodo
2020-09-30file_654000.docdoc 2fbc53c50b9b33c49311e11a41aa64660b305c9c7d4a4db3986c59a1a77696a8Virustotal results 22.95%Heodo
2020-09-30inf 20200930 3376221.docdoc 1ae8b36b40fc24a515c6c73306a3e899b9784f226f103177825e027f536f2b41n/aHeodo
2020-09-30FILE_20200930_561.docdoc f51c36573e26e1e9e468817539defd6c9ed614f8a76c9a2432664baaaf3cdfdan/aHeodo
2020-09-30list 2020_09_30 725.docdoc 6a8fc6ea0a16a349b6127200b4c1398c112a6251339536b6e0c034c035cb5eceVirustotal results 22.58%Heodo
2020-09-30mes-2020_09_30-168780.docdoc 9a188064a2a9086199f61142baab865667e9293f4147c5d5fbdad9f33a9435a8n/aHeodo
2020-09-30File 20200930.docdoc 2bc311aff7d90ac42c818d1850c8eff0fca326e6c334899f8041c63a59753465n/aHeodo
2020-09-30arc.docdoc 6532e0b5e7e0a65864bed3ff6ee62581be8b76f1d35bff0e9289fc95b851a992n/aHeodo
2020-09-30Attachment 2891887.docdoc d68f7a17ddc794e99447927fe7bfc0b7245f8fa2730d64c3f3996445853192a8n/aHeodo
2020-09-30Arc-2020_09_30-05885.docdoc ea0313fd5620c355be450cf83271f033601347eed4e661eddef0fbf152e5808aVirustotal results 22.95%Heodo
2020-09-30UNTITLED 2020_09_30 AWS988204.docdoc c00ad151d1825f27639994f1a506ff8fb76d8cf3460cac3eb8351c1caafa8b71n/aHeodo
2020-09-30arc O9230.docdoc a0105d00c8554ccf45329bf8b6f502eb63dd0e844edfcde8e2bd0c6000c9e708n/aHeodo
2020-09-30Rep 2020_09_30 02237.docdoc 7d295d64ccbe51777d0ddead2fa213c37017ce33adfc3ab35ed81d988315f756n/aHeodo
2020-09-309073-20200930-9078531.docdoc 85457cce94346f14602525c4c114a035aeff9de80b2d25f2cd7aee042c5477can/aHeodo
2020-09-30Attachment_WPT2828.docdoc ae08f6ca3d49c7a6f89007400a01827f8fa1e32ea4d88e4e38ff705f70c810ffn/aHeodo
2020-09-30UNTITLED 20200930 CZC7364.docdoc ac02dd4f0106b2f7e7b97558983f04377892dd24af1c4babd3cb13a1ba81d7e8Virustotal results 20.97%Heodo
2020-09-30FILE_568.docdoc e750318c6f5ae04efc1b912fd250a9bdf7c83ce3289a31f303d03bc0e9e4b11cn/aHeodo
2020-09-30LIST_2020_09_30.docdoc bc1a1a8828821a74c104c0e49dc6a8456e2d89c4f2af71491ea5136f93460561n/aHeodo
2020-09-30file_2020_09_30_33299.docdoc 8ef1fe169003bb04c8f9c01d621a69d1ea9fa127df3d9c2baae8c97f6d955cfan/aHeodo
2020-09-30Doc 2020_09_30 051.docdoc 4b795f3870e608b6c61e4a7757d87deb5525949aadeb15393e2b83cb4b34e618Virustotal results 47.54%Heodo
2020-09-30DAT_Y668.docdoc 9514f8559ebc3346ee2ad8a0dc066f680f456064bcb9dc07a2b528f14293d522Virustotal results 46.77%Heodo
2020-09-30REP-2020_09_30-HM388666.docdoc 3bdee9fdd814363fa073be396eda19d9242d4bfd82702110dff7564d61ef4a8eVirustotal results 46.67%Heodo
2020-09-29Mes-20200930-L886.docdoc 9a24d61f24a1211065b986def505c02b66a94f2b1cbde8fc6ef868391c24d4f3Virustotal results 30.65%Heodo
2020-09-29Arc-20200930-9316382.docdoc 349dd2ac63132716ea7360223fd038575e1b7144925c60d87589880fbd488670Virustotal results 29.03% Heodo
2020-09-29Mes-2020_09_30-502.docdoc 2ce2a7979c53158a0e7454224e6755704290a5a16a092aec69088da9eb3571a3Virustotal results 29.03%Heodo
2020-09-29707 2020_09_30 HA63228.docdoc 08c3a51969b9ccfcd46ad14ef1a7599a798c21e693a582ac6d8f449f77f4fc09n/aHeodo
2020-09-29INF-2020_09_30.docdoc 74f26e376ef3b8ea6b3b9d1599e98182897725563fcf69a3ae86f502acc7cdabn/aHeodo
2020-09-29Mes 20200930.docdoc 7b65d8ab639b2e52bf89d1991cd330f6290b79269e2699b295b134f62689d29eVirustotal results 19.35%Heodo
2020-09-29Doc_2020_09_30.docdoc 4d320a36571c9892b7730fe7903d3eb8a96dd16575194e01c8b202f77930f86fn/aHeodo
2020-09-29file_S797.docdoc cdbc3d9af98086634425aa8705246094a3b602fd00a7f35717208a55a4da2144n/aHeodo
2020-09-29doc-2020_09_30-WKA54313.docdoc dc37c6a8213875ada2f9dbe9a76ae223105ef7407b221f2b9a8741b9a114bedeVirustotal results 21.31%Heodo
2020-09-29arc_20200929_33851.docdoc f02b188278d31f5c4bf69da19d42c2dcdc5f9724d5de56c4b6255732d6d6393dn/aHeodo
2020-09-29Rep-603121.docdoc 9441c64607ce749604dff7e3f2080dc43eff5cf59ab51c17e8e276ae8f9a24d6n/aHeodo
2020-09-29rep_JQ63187.docdoc 42bb540219be5cfef273134bfd225b2beda1edfcff945b3448e19a7ae8e982c7n/aHeodo
2020-09-299482ITA-20200929-X8918.docdoc dd1c623f20ca4fdf67cbe53d85b17d13c54f068c21886add6d7295f5dae8aaf6Virustotal results 17.74%Heodo