URLhaus Database

You are currently viewing the URLhaus database entry for https://southafricafinewines.com/wp-content/paclm/K08HsUN35T9L8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:626136
URL: https://southafricafinewines.com/wp-content/paclm/K08HsUN35T9L8/
URL Status:Offline
Host: southafricafinewines.com
Date added:2020-09-30 02:02:15 UTC
Last online:2020-09-30 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-30 02:04:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 hours, 4 minutes Good (down since 2020-09-30 07:08:43 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30Untitled_20200930_9376940.docdoc ce00e37ae25728419ee8bb78a1abcc5bad02bbd0dbf436d5051b7ff766f5985aVirustotal results 21.31%Heodo
2020-09-30File 20200930 22852.docdoc 7464edd6b84b35d71ec4b891bd85c2918da1024f18f49f0e06192b440eb5f364Virustotal results 46.77%Heodo
2020-09-30file_20200930_AIX966859.docdoc 32ec09ab815a3ca2d96ed124d841dc8dadc0f752aade3f0cd9ea04c51c6f1eb9Virustotal results 47.54%Heodo
2020-09-30Untitled_2020_09_30.docdoc 22f844a158ab002c4375f2234f5a539f0b1b5199f33b442d4869765ea22ca27aVirustotal results 47.54% Heodo
2020-09-30arc 2020_09_30.docdoc 283272050a0c0d994dacc605e1d7009688c58c1f0998f8007647a9b92e8604e1Virustotal results 46.77%Heodo
2020-09-30Dat 20200930 F385320.docdoc 551817b29bdd25cae481fa77c2f295a03a36b7de6c5afd9dc612ff0ded86e9f0n/aHeodo
2020-09-30List YVZ88399.docdoc 267561ab8d4856ba0064185a8d6269693f1c580b721f16db305b6a9299f5c41dVirustotal results 45.16%Heodo
2020-09-30LIST_2020_09_30_6912.docdoc 6f99b89e5bfde428715216d919a8e1dd87475900137dfbb2e07c5ba58bbb2954Virustotal results 45.16%Heodo
2020-09-30inf_20200930_VLY655473.docdoc 33477bed1839bb45bcfd3358705d97b3db5e567c2c551e666d8ac934ec20dd9bn/aHeodo
2020-09-30Dat_4339.docdoc 26979e8912dc25e20f622985b767028de865e5719a3a559353389878b9fa0b64n/aHeodo
2020-09-30Untitled 2020_09_30 YZ143.docdoc f72f43e5d32d5bf4ab91a6e04550dbef93f82764320a7403d8b59952c208beadVirustotal results 40.32%Heodo
2020-09-30Dat 2020_09_30 II023.docdoc 67d283b362bfdbb0db8f7a103bd5c1c3c7fadbb22b0cccc5b0cea1b48d1bcd16Virustotal results 40.00%Heodo
2020-09-30Mes_YHR51203.docdoc a3aa47fd0e69bb9abfdf3263e13b7d854f23cc07579e8e294a8930e6498d6143n/aHeodo
2020-09-30list.docdoc 12eacad71c2a295436f6909c437715e14ed8ab2c4c2417d845ee7e4155768b1bVirustotal results 33.87%Heodo