URLhaus Database

You are currently viewing the URLhaus database entry for http://sushiclass.pt/wp-includes/INC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:716997
URL: http://sushiclass.pt/wp-includes/INC/
URL Status:Offline
Host: sushiclass.pt
Date added:2020-10-19 10:00:08 UTC
Last online:2020-10-19 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 10:02:08 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 hours, 36 minutes Good (down since 2020-10-19 18:39:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19INV_ESC_100120_LBS_101920.docdoc afacbe2b36a27b864ffaf4cc60eae312d6a7080c4a0822e29f8fb23b5019636eVirustotal results 37.70% Heodo
2020-10-19XPH_100120_SDL_101920.docdoc c7b747cd1c60fa173fa3466e99337863d3e4552c315e3b2a1f284f6293bc8e46n/aHeodo
2020-10-19DDXUXW29U.docdoc 2381e204a9cc635b37ddc61e910b65f0d3d1f88e5d4de3e221d344df7b965c16n/aHeodo
2020-10-19BDG_100120_PEX_101920.docdoc 7b965f905779d5a9c63dfa9a9baa9f55e48901bbc7924510b0e8e2c4b21b257aVirustotal results 35.48%Heodo
2020-10-19INV_MW3111344275VX.docdoc cfeb18e60913b48ee28948d2fc7770a7292d72f0f42e0c16a6cb1d8a0526fa23n/aHeodo
2020-10-19DQP_BP2951191666YA.docdoc 0f285c8cec726ec8916046cfaf44c2d719e8cfa93755432761f93f101b81d10cVirustotal results 33.87%Heodo
2020-10-19K_MH8376103915ZF.docdoc d8ca4ead51d79a8893ccb65e58b265f40a3781139e1a65cda7d61387678801cen/aHeodo
2020-10-19FILE_IOR_100120_CWX_101920.docdoc b109e971441a6457c8cb7412fad8764b8c5dd8d97098844356f40a32393a3e1bVirustotal results 31.15%Heodo
2020-10-19KPEW697ZY09UVOT.docdoc a863b80f05038941385d809148546aa22fc71eb2b14ce02b78f40470e718a6a9n/aHeodo
2020-10-19BAL_PO_10192020EX.docdoc 3f046626d961cb82a07beec8983b8b401e9998ad3bcf832856f6c562ab1f7852n/aHeodo
2020-10-19PO_10192020EX.docdoc 3cc91108bd9d95f641996cfbde558f3ef6f6e02cd25106217a2d6dfab9da1f30Virustotal results 30.65%Heodo
2020-10-19DOC_QCT_100120_RFB_101920.docdoc 7b2a837b94b8761ea01368995d772ef3dc242cbfd37be21d0b4c3e8da46f6053n/aHeodo
2020-10-19F_618093803340869.docdoc e073f07f9088110a389e50314ee391ff0b82bcf678873d348cf51f6a830dba48n/aHeodo
2020-10-19INV_1W8WF3Z5.docdoc c4a82a8cbffbb0e1398e3429b37d9adda018c824d1c0235ddf77c8bd57efd334n/aHeodo
2020-10-19S_68896752.docdoc 07791b0eccfe13208ee78ff72fd3ac33c1a67844e1dec69224b1870629aaa738n/aHeodo
2020-10-19REP_PO_10192020EX.docdoc b25d126a1c1bb22993ac8165ecd2492e6dcf983d5fa89b4faaf33c6fd8a5ae2en/aHeodo
2020-10-19BAL_SJ5849863873YJ.docdoc 73ad1a097ae639ec4766a9089db90689d021da8fc07958f6b386bbb32042d324n/aHeodo
2020-10-19PO_10192020EX.docdoc aa0236ae4db1c9739afd7a54e78f7c138a289c6afe0f67d41280555fc12dccd7Virustotal results 27.42%Heodo
2020-10-19P_PO_10192020EX.docdoc aaf1a1ed7d6a708dc047f1f570b8e8f75a0bea3df69adeb6a8caaccbdc86299an/aHeodo
2020-10-190AO05G3SBI.docdoc 5fdcc53ae3fe9f5fca66a33e39cc2856109c5c92819ce2a269aa372834f5311bVirustotal results 27.87%Heodo
2020-10-19DOC_DH51FPL0D0OVQ.docdoc 1b7098a327e8aa8f05b2c2983c9f9978af7848e0b8fb22ae4a42ca7bbae89347Virustotal results 29.03%Heodo
2020-10-19REP_PO_10192020EX.docdoc c8933fa30cb9059adb0928da2eb0d8709f509dc36de9dc781a18014a8a87c01cVirustotal results 27.42%Heodo
2020-10-1971934138.docdoc e7e4dbaca136efac09b7a3fa373d6ee232ce5985c5c94c3f26cdbec937188eb0Virustotal results 27.42%Heodo
2020-10-19DOC_55467386293650152673.docdoc 8b6ca8391ed8ef93dc90944194677586fb70e6d442a539b37edffcadec3c81d0Virustotal results 27.42%Heodo