URLhaus Database

You are currently viewing the URLhaus database entry for https://serviceclic.com/wp-includes/attachments/xKGDeh1KQTxw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:625279
URL: https://serviceclic.com/wp-includes/attachments/xKGDeh1KQTxw/
URL Status:Offline
Host: serviceclic.com
Date added:2020-09-29 22:19:08 UTC
Last online:2020-09-30 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 22:20:38 UTC to abuse{at}hostinger[dot]com)
Takedown time:11 hours, 44 minutes Good (down since 2020-09-30 10:05:29 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30Arc-2020_09_30-K71077.docdoc 540c085bf41d7ded925345f785582459e99ff1125a0400d9e6b151676fcc5f6dn/aHeodo
2020-09-30DAT-20200930-3743.docdoc 3b7c744c1ce6fed0e44750032b24ce1e651586ac1b2e01d815796e30a2aaa9ban/aHeodo
2020-09-30MES 2020_09_30 659.docdoc 9849bf91ef029b6a492bd6c1b39b888e264d7b14a1574d64502706cc65d51576n/aHeodo
2020-09-30FILE_20200930_AO071.docdoc 25b7f727f0f1e44dc0b90a12f28264418053fc308ea16c0050ae887a1db7d5abn/aHeodo
2020-09-30INF.docdoc 173d3683f3f267d179bd0a2861ce23edcef457430364fac577f89dea9c9950b0Virustotal results 20.97%Heodo
2020-09-3017352NF_20200930_KIX5768.docdoc 560d243b886163bf8799f1980448da2bba89ef24b99028c48b3687a710a80fdan/aHeodo
2020-09-30list 2020_09_30 DQ2863.docdoc 591579fba418bcc6bd1fc4bb4a299348db435c11b203cd049b17c9830f211087n/aHeodo
2020-09-30MES 20200930 CBO609816.docdoc 22f844a158ab002c4375f2234f5a539f0b1b5199f33b442d4869765ea22ca27aVirustotal results 47.54% Heodo
2020-09-30S55293_20200930_TZ505.docdoc 892d8f9cfb26bae3277304d3396027dd55d0899e78181a1431bb43e29dd3e857Virustotal results 41.94%Heodo
2020-09-30mes_20200930.docdoc 643a118d94807a21df75a7aede93130326ac04ce84a10d9fa67b1f5f87d3467aVirustotal results 39.34%Heodo
2020-09-30302844_20200930_804968.docdoc f8b2d066f5a3d657edb1544f9df31a9a7b3121c5c14ddb1b96b50ddd69b44c22n/aHeodo
2020-09-30rep_2020_09_30_FN97454.docdoc a3aa47fd0e69bb9abfdf3263e13b7d854f23cc07579e8e294a8930e6498d6143n/aHeodo
2020-09-30FILE 2020_09_30 GL199.docdoc 1d44cd8c3d04874dc41108bc844eb637f657064927fc28927f68c95fe596bcaaVirustotal results 32.79%Heodo
2020-09-30UNTITLED 252985.docdoc 1b7ae75c0843e24188c16e98283ae53b2d5d441a3149a30eae0eda9db7781220Virustotal results 32.26%Heodo
2020-09-30REP.docdoc 0cbe205dde93631435eaf136feea1e35c86b49f20a0067c26fde038b48e2d725Virustotal results 32.26%Heodo
2020-09-30UNTITLED 20200930 94567.docdoc a87836e6fbf70862d74980ad32f16b6dfe157bcea1172817e7235764aae0c4den/aHeodo
2020-09-30File-S91671.docdoc 541afbe8b457f589a760cae7ecbf5d520a7f1ecb81bf9d2e2f5ddf90cad8a418n/aHeodo
2020-09-302159-WWJ2587.docdoc b89e3c01c95337c6976cfdbc20163b4375eb1a0a76a87335e891fcd932c361d1Virustotal results 30.00%Heodo
2020-09-29arc 2020_09_30 G7697.docdoc dc873a463b8cbee41eb8683d98db5a331553402391ba1c16e664c7034eb1acafn/aHeodo
2020-09-29765AX 2020_09_30 DFT0712.docdoc 9a24d61f24a1211065b986def505c02b66a94f2b1cbde8fc6ef868391c24d4f3n/aHeodo
2020-09-29list_2020_09_30_BE981.docdoc 349dd2ac63132716ea7360223fd038575e1b7144925c60d87589880fbd488670Virustotal results 29.03% Heodo
2020-09-29FILE_UD396.docdoc 2e0fc31a6ff8f20507c6979fa9b5be9e11f13d424e2962ec30f1fc596c069898n/aHeodo
2020-09-29Dat 2020_09_30 G141.docdoc 87687f422879d033f49c258046d04d4456ca8476353a750ba425c6642d61d3f2Virustotal results 19.35%Heodo
2020-09-2991232677_20200930_298.docdoc eeb152640a9662420b865da4ac765f66469ebd7aa3568a51b62e286ce5806435n/aHeodo