URLhaus Database

You are currently viewing the URLhaus database entry for http://redchillicrackers.com/wp-content/Pages/Et5c3RjJenwhKJR6mQYY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:625038
URL: http://redchillicrackers.com/wp-content/Pages/Et5c3RjJenwhKJR6mQYY/
URL Status:Offline
Host: redchillicrackers.com
Date added:2020-09-29 21:06:16 UTC
Last online:2020-09-30 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-09-29 21:08:03 UTC to alliance{at}qualispace[dot]com)
Takedown time:17 hours, 0 minutes Good (down since 2020-09-30 14:08:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30REP 20200930 9428.docdoc 0a72f410fe5254890d7fa49499a305fe366a747e010e5e84cbb1e6f60c425b20n/aHeodo
2020-09-30INF 20200930 5274644.docdoc 283272050a0c0d994dacc605e1d7009688c58c1f0998f8007647a9b92e8604e1Virustotal results 46.67%Heodo
2020-09-30FILE.docdoc e0241059c22b3f4c297b2b6d6c3d0d854d45f39af3ec08495ca2b04025772414Virustotal results 47.54%Heodo
2020-09-29Attachments 9590449.docdoc 7b65d8ab639b2e52bf89d1991cd330f6290b79269e2699b295b134f62689d29eVirustotal results 19.35%Heodo
2020-09-29Arc 2020_09_30.docdoc 004d7159e2360d1569de7849fbd5ffa3e63968d011834c565255ade18fcd54cbVirustotal results 19.35%Heodo
2020-09-29doc_20200930_FM5918.docdoc dc37c6a8213875ada2f9dbe9a76ae223105ef7407b221f2b9a8741b9a114bedeVirustotal results 21.31%Heodo