URLhaus Database

You are currently viewing the URLhaus database entry for http://greyfoxchocolates.in/wp-includes/sites/NTXc6akEEjE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:720440
URL: http://greyfoxchocolates.in/wp-includes/sites/NTXc6akEEjE/
URL Status:Offline
Host: greyfoxchocolates.in
Date added:2020-10-19 23:49:05 UTC
Last online:2020-10-20 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 23:50:25 UTC to abuse{at}hetzner[dot]com)
Takedown time:6 hours, 14 minutes Good (down since 2020-10-20 06:04:36 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20inf_N79566.docdoc 485440711ff60c647e6fc7bfa85ab4859c06bb56e354f108648a3904231a33a6n/aHeodo
2020-10-20File 20201020.docdoc d0923c979ad2de7a491d0cff4e1b2f09b69154baed8b56cfa7246b898b000f23n/aHeodo
2020-10-20inf_254221.docdoc cedcb3350a54345fd4bb23b7b9d5fc753bf7bcd4dc5b37c6c4b61291bb3dcd01Virustotal results 50.00%Heodo
2020-10-20434YUI 20201020 D2927.docdoc 3481523719c66d648c8519ec510a81d054cbaa903c5ae60b4ac642a20748d587Virustotal results 50.00%Heodo
2020-10-20File 2020_10_20 JWI996.docdoc 193df1dc2f0c0e1a9f636ebe31c7e5f6c1a9f2187aeb7f7aa815e7ba3a2e5188Virustotal results 47.46%Heodo
2020-10-20doc 20201020 ARP33102.docdoc 6d63f7d30ff007d1360e127c4a2cee72fc09a3493b816699a052d38b48f1ad0cn/aHeodo
2020-10-20UNTITLED.docdoc 4d7b7e3f966e9c61fa57d5d9fca513ffd348f8e0127ae7d177c075110fad122en/aHeodo
2020-10-20INF_20201020_M636.docdoc 0a1ad6a4af3b721e5fe77a948233434553847e9de5873e433f2245cb4c3d0fadVirustotal results 48.39%Heodo
2020-10-20940513_OZG6994.docdoc 3c0ec9a3bf2ff5e49e04644d134520ea789dfdae8411093b5b9b8f18a5363551n/aHeodo
2020-10-20Attachment_2020_10_20_YOD203.docdoc b548be3fe343498e82f9fb62fe50ccb099b09df567f62a6a557a14f5d3773fbeVirustotal results 43.33%Heodo
2020-10-20doc_R344822.docdoc f8fdf9bcd696a4c06cc8579db778c097957dac41de586fbb6a8edbd70cb0cf30Virustotal results 43.86%Heodo
2020-10-20P80548 20201020.docdoc 87a7289961845b4c5d06554d318aa51a1e4fc5aeb580d9dea164398d968caf14n/aHeodo
2020-10-20Attachment-2020_10_20-827.docdoc 44c2c1f67fd38ab65b3a8424f7d5ace8c5ed6e044ee2cf9171a215b37481999an/aHeodo
2020-10-20Untitled_K370.docdoc 639663610cca6441a36141da55733332d7cc089dad3fb409b8857db78e0e6ac0n/a Heodo
2020-10-19Dat_LMH93929.docdoc f139d60eda8537275895f24b7050901cf78560a72f35d6f4c463e79d9571e9b7Virustotal results 40.98%Heodo