URLhaus Database

You are currently viewing the URLhaus database entry for http://southafricafinewines.com/wp-content/paclm/K08HsUN35T9L8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:626123
URL: http://southafricafinewines.com/wp-content/paclm/K08HsUN35T9L8/
URL Status:Offline
Host: southafricafinewines.com
Date added:2020-09-30 02:01:20 UTC
Last online:2020-09-30 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-30 02:02:09 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 hours, 15 minutes Good (down since 2020-09-30 07:17:33 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30Untitled_20200930_9376940.docdoc ce00e37ae25728419ee8bb78a1abcc5bad02bbd0dbf436d5051b7ff766f5985an/aHeodo
2020-09-30Q0051_2077.docdoc aeb2040f463a73944b82179ca8dd49ea3531d9b21d9d7b837b38d6817a9bfa7en/aHeodo
2020-09-30dat-2020_09_30-N290662.docdoc 4b795f3870e608b6c61e4a7757d87deb5525949aadeb15393e2b83cb4b34e618n/aHeodo
2020-09-30File-20200930-SJ267.docdoc 6203971a2e4b246318cba558f864664aacc3cc5dae07aa3b8ce1fa6fb17d590dn/aHeodo
2020-09-30Untitled BB91238.docdoc 3bdee9fdd814363fa073be396eda19d9242d4bfd82702110dff7564d61ef4a8eVirustotal results 46.67%Heodo
2020-09-30Attachments.docdoc 23ccebb7161e48fdb44034be5f97acd1bfa117b92ee7c747f07dfcbd15d5fd9dn/aHeodo
2020-09-30List YVZ88399.docdoc 267561ab8d4856ba0064185a8d6269693f1c580b721f16db305b6a9299f5c41dVirustotal results 45.16%Heodo
2020-09-30LIST_2020_09_30_6912.docdoc 6f99b89e5bfde428715216d919a8e1dd87475900137dfbb2e07c5ba58bbb2954n/aHeodo
2020-09-30inf_20200930_VLY655473.docdoc 33477bed1839bb45bcfd3358705d97b3db5e567c2c551e666d8ac934ec20dd9bn/aHeodo
2020-09-30dat 2020_09_30 847.docdoc 892d8f9cfb26bae3277304d3396027dd55d0899e78181a1431bb43e29dd3e857n/aHeodo
2020-09-30Untitled 2020_09_30 YZ143.docdoc f72f43e5d32d5bf4ab91a6e04550dbef93f82764320a7403d8b59952c208beadVirustotal results 40.32%Heodo
2020-09-30Attachment 20200930.docdoc 67d283b362bfdbb0db8f7a103bd5c1c3c7fadbb22b0cccc5b0cea1b48d1bcd16Virustotal results 40.00%Heodo
2020-09-30Mes_YHR51203.docdoc a3aa47fd0e69bb9abfdf3263e13b7d854f23cc07579e8e294a8930e6498d6143n/aHeodo
2020-09-30list.docdoc 12eacad71c2a295436f6909c437715e14ed8ab2c4c2417d845ee7e4155768b1bVirustotal results 33.87%Heodo