URLhaus Database

You are currently viewing the URLhaus database entry for http://domiciliazionesedelegaleamilano.it/site/balance/mmz1wsng/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:724660
URL: http://domiciliazionesedelegaleamilano.it/site/balance/mmz1wsng/
URL Status:Offline
Host: domiciliazionesedelegaleamilano.it
Date added:2020-10-20 17:35:06 UTC
Last online:2020-10-24 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: viql
Abuse complaint sent (?): Yes (2020-10-20 17:36:23 UTC to abuse{at}arsys[dot]es)
Takedown time:3 days, 21 hours, 8 minutes Bad (down since 2020-10-24 14:44:51 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22NAX_100120_CDE_102220.docdoc 77de1ed43121b520b0f2810212dbe7e10c305388e6555b5310cf07a7f36396b3Virustotal results 45.76%Heodo
2020-10-2285189253.docdoc 06dc08ea7da16ee44235f6f6009c538b3db08f6198613fbf8c66be4446da7e6aVirustotal results 51.85%Heodo
2020-10-22PO_10222020EX.docdoc 7ed0141f0a2a5f88f9be5418ff02a2fcc1e18b7a11d58fb68581b21b99b5eba0Virustotal results 44.07%Heodo
2020-10-22FILE_2079472398872600493.docdoc e093c016746d804ab3f83b9ae5da804217da67e5038a0b3b77230d830623b560Virustotal results 43.33%Heodo
2020-10-22REP_7884185681732986464121.docdoc 7eaf0df9dd2a33ee958384a9472366f58f1c0a204360efea6a7f8b0d298560d0Virustotal results 45.00%Heodo
2020-10-22E_65007338.docdoc c41bcade49f3e2413b5d95ce09c2ecf30c21b43ab6b306206b9b737f1cd10450Virustotal results 44.23%Heodo
2020-10-22FILE_MH4587290217TP.docdoc e1ae8430f64735e0c767276e1e57632257e7aa36f38cd6515b43e92bcd95dbd4Virustotal results 43.33%Heodo
2020-10-22DOC_PO_10222020EX.docdoc e2e2fc35c9bd68222d8b6d5f8956a22d89314dd8c3eab9686f3b069b37602520Virustotal results 44.64%Heodo
2020-10-22FILE_PO_10222020EX.docdoc fc523dab17f69be0ab6b14d0c02e81b083dd380e76e40267fbd6b1a56128c6ccVirustotal results 45.16%Heodo
2020-10-22K_07254670944165329.docdoc 5e6f9a748268113d3da7867313c0be3f5891553c5690a01354fbbee0d530a136Virustotal results 45.16%Heodo
2020-10-22H_UNE_100120_IUM_102220.docdoc b39c953e5621fd7b9af004e2d9195a7a37f9070b736007d74635c5d36d6ccd04Virustotal results 42.37%Heodo
2020-10-22FILE_LNZ_100120_SON_102220.docdoc 632c5a72a092d28c99811e23f849e709697e9e5fe38e5d17caf58e6c304e65b1Virustotal results 44.07%Heodo
2020-10-20BAL_UKN_100120_VIE_102020.docdoc 73b7efbeee5e1a863951ca7e8732349c122e88572bbd091ac36b23509858bf8eVirustotal results 40.32%Heodo