URLhaus Database

You are currently viewing the URLhaus database entry for http://1069thefan.cachevalleymediagroup.com/wp-content/eTrac/pFoLYBVn7VqI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:720780
URL: http://1069thefan.cachevalleymediagroup.com/wp-content/eTrac/pFoLYBVn7VqI/
URL Status:Offline
Host: 1069thefan.cachevalleymediagroup.com
Date added:2020-10-20 00:52:04 UTC
Last online:2021-01-11 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 00:54:04 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 months, 23 days, 13 hours, 37 minutes Bad (down since 2021-01-11 14:31:09 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20Untitled_20201020_3591.docdoc b60a54ae11a2afb4fe1566bb6444e4518cd638ba7cade354005ca6ac536a9b7eVirustotal results 32.08%Heodo
2020-10-20Doc-B808.docdoc f44bf3ebe602bf2baddc136caf0d48ccacbf3737fe926efa3f3271d81e5949acn/aHeodo
2020-10-20Attachments 2020_10_20 6921068.docdoc d05f79498a7e732d0b834412b1e8989b8fa6f6aba3703c9401a6346555767fa3n/aHeodo
2020-10-20arc-Q301306.docdoc f9738b1b9f937589e4420b0e16c6cef89b503f785b4a8dd894369fa13cedc411n/aHeodo
2020-10-20Untitled-20201020-M648407.docdoc 802f5317ca24da173c91e264c8ecf7c2700fd71412a1533a1d0e316d70d0af7bn/aHeodo
2020-10-20Dat-RJ89618.docdoc 1dc9d9c96259e23a7654f8fe1a2f186fc2c035c4c46a85daff8f1660fa95580en/aHeodo
2020-10-20DAT-20201020-7702.docdoc 787791bad8fa843f9ec53df000eef8bff21e5850fa187c518e826d0ca52cc14fVirustotal results 31.75%Heodo
2020-10-20Untitled-CO874518.docdoc eaf3d04450cc7943d874b559af2cc90787f32ba36aa6cded35f2f977971fc6afn/aHeodo
2020-10-20Arc-20201020-T74717.docdoc 7dbdc3198dc7461bd96ecceed0862058b292cbabe1d82ffde2b426a5d154584an/aHeodo
2020-10-20FILE 20201020 24743.docdoc d3d4d84e3a65c176379d77480626309e1d9ab1436be744a5bcb59bb6e17e9763n/aHeodo
2020-10-20list-20201020.docdoc 2f237e6dcd0651791cf07f25839792a2000bbd0be88329c3ad129e767b780492Virustotal results 51.67%Heodo
2020-10-20REP_20201020_619.docdoc d0e1f8621980227b8293b9c8c52aeae9743b9ffefe8adab468cae79c72bd2d71n/aHeodo
2020-10-20DAT_20201020_5965.docdoc a305a0d1bc9e9768e247b2596cd9cd12dc76caddab1682164dd45460d83253c1Virustotal results 50.00%Heodo
2020-10-20list 2020_10_20 J815.docdoc 42d3de102fbfadf81bcb1be23a15fce55da7b26de0b1b744b1a2a797838544ddn/aHeodo
2020-10-20Inf-20201020-MXS611747.docdoc ec9848061726f5b7ae54e3d4cbc2cadbdac49f6a457b4f6ad695536e7be5cc0dVirustotal results 47.46%Heodo
2020-10-20F92558_20201020_6121321.docdoc eb322e13a71d24533bac0486fc957917f68ac521a57b202b19f6e0a14248e6fcVirustotal results 48.39%Heodo
2020-10-20Rep.docdoc 0a1ad6a4af3b721e5fe77a948233434553847e9de5873e433f2245cb4c3d0fadVirustotal results 46.67%Heodo
2020-10-20ARC RFB3648.docdoc 3e8d19e4337bc955ae013db74df80e9f8de66632369f3f0d6609a42135243041Virustotal results 43.48%Heodo
2020-10-20List_2020_10_20_PWC42334.docdoc 5c782213814bd09d6ff39e163a2a9d03394c6e96007fb6383df7859ee74178b9Virustotal results 45.16%Heodo
2020-10-20R6731-D39729.docdoc f8fdf9bcd696a4c06cc8579db778c097957dac41de586fbb6a8edbd70cb0cf30Virustotal results 43.86%Heodo
2020-10-20list-2020_10_20-5322550.docdoc 87a7289961845b4c5d06554d318aa51a1e4fc5aeb580d9dea164398d968caf14Virustotal results 43.33%Heodo
2020-10-20List-2020_10_20-69262.docdoc ea889debae5f58200c593fb982a145b972caa5228a56f674e21fbd99629df79cVirustotal results 45.16%Heodo