URLhaus Database

You are currently viewing the URLhaus database entry for https://thefashionfirst.com/wp-content/FILE/qLHJ8aZd1Rt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:718226
URL: https://thefashionfirst.com/wp-content/FILE/qLHJ8aZd1Rt/
URL Status:Offline
Host: thefashionfirst.com
Date added:2020-10-19 14:30:04 UTC
Last online:2020-10-19 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 14:32:03 UTC to abuse{at}contabo[dot]de)
Takedown time:3 hours, 41 minutes Good (down since 2020-10-19 18:13:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19160-P923.docdoc f579a6044d9f764bd59abd53771cb8846744e24997e2d83e41a17a445578826dn/aHeodo
2020-10-19ARC 20201019 PE908888.docdoc 67be51a6de7a956a41d7e574bdf617701645afcdb8f0b1c43ed96f5013d60c0cVirustotal results 35.48%Heodo
2020-10-19doc 2020_10_19 VEN231354.docdoc ee4d9edb2370e384fb5f36330a42d049a086408f2c0d7b59818c8f7cafebbbc4n/aHeodo
2020-10-19LIST 2020_10_19 060401.docdoc 4846b137d8cc5dae6ed7e1b3477444bca0adc09c3c8c235c17116f513c44bf63n/aHeodo
2020-10-19List-20201019-ZM6441.docdoc 261c8e56e4c8b1ff86cd34d9d05b425dc436d6cdd661016c1dffbdaece6810a3n/aHeodo
2020-10-19FILE-2020_10_19.docdoc ab4999a6bdcd2a735d994d4243ac6dad6bb52a5224243bc771cd0156d69bf71cn/aHeodo
2020-10-1919355922_20201019_NY003.docdoc d7e862a59c86fbd1e6109ab4d845cdb9f4d400d03fc43b8d208e68e8ae0ef28bVirustotal results 30.65%Heodo
2020-10-19ARC-403507.docdoc 2d1537b6ac72b0dfda1db918152047f70c3fc53c33d2cfb9be4e86cfb34f0deaVirustotal results 30.65%Heodo
2020-10-19doc-2020_10_19.docdoc aa0ab6c31528d9364a0c06d94511e1119343d3d1bef425ce8c73f48524596e59n/aHeodo
2020-10-19ADY2212 20201019 V849.docdoc d75119e895cc84de39a3e027d94684b52a3cc73f74cd7b23a2c2a913a93a13a6Virustotal results 29.51%Heodo