URLhaus Database

You are currently viewing the URLhaus database entry for http://petlele.co.za/wp-admin/invoice/u5pvy8z43v-097462/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:720928
URL: http://petlele.co.za/wp-admin/invoice/u5pvy8z43v-097462/
URL Status:Offline
Host: petlele.co.za
Date added:2020-10-20 01:33:05 UTC
Last online:2021-03-19 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 01:34:15 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:5 months, 0 days, 0 hours, 40 minutes Bad (down since 2021-03-19 02:15:08 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-06DEJ-100120 NNYF-102020.docdoc c98b10dd0c1f3c8f5f8021a58fe80717e1b31b1cd2e86ca536e828b1a2ff3e91Virustotal results 69.84% Heodo
2020-10-20Invoice.docdoc 19aad5040fee8a81772e4326aa715f5fdfa438971518f212a8a8a8f96bf9ae1fVirustotal results 51.02% Heodo
2020-10-20Electronic form.docdoc 9d08e7c389570de57d78a8cf91e14d9c814ec46202b241acdcea2d9dcf7c427fVirustotal results 50.00%Heodo
2020-10-20Form.docdoc 9fe84df0e721c3be3f87b18797064adf7294d5fc84605bdd396e1d7492e85c0aVirustotal results 50.91% Heodo
2020-10-20NX1325362464VH.docdoc 942f47744db5e721c7c600c36f1c1af3455fdf7e3fbb76011c000c221e06b687Virustotal results 51.61% Heodo
2020-10-20Form - Oct 20, 2020.docdoc 477afd6f4a7fed4b0886e1d509e130c736c6f2203be85ed8c18d40bc6db385f0Virustotal results 51.61% Heodo
2020-10-201526104249NW.docdoc abb1fa28c17964d8d4366e43c3fa606bb40eb59a69d128368a37c9ae5ba84544Virustotal results 46.77% Heodo
2020-10-20INV #0088536 FOR PO #00085051232.docdoc b52f4d01a0ab4d1cc721d51d83479234dda82213536075936f096f0d1203552eVirustotal results 45.16%Heodo