URLhaus Database

You are currently viewing the URLhaus database entry for http://pro.fligby.com/wp-content/uploads/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725293
URL: http://pro.fligby.com/wp-content/uploads/swift/
URL Status:Offline
Host: pro.fligby.com
Date added:2020-10-20 19:54:04 UTC
Last online:2020-10-21 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 19:54:47 UTC to noc{at}integrity[dot]hu)
Takedown time:11 hours, 14 minutes Good (down since 2020-10-21 07:09:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21DOC_SNN_100120_MCC_102120.docdoc c75ff84fe40e2bd56dd64dd2a51d43de4ae2eac42c9efb6df985ff4244f7f974n/aHeodo
2020-10-21TLF_100120_VOC_102120.docdoc 39a7385578321db9d477ff19e7087b03d3c57076ceca16fc2af049c087f72343Virustotal results 38.98%Heodo
2020-10-21BAL_SOG_100120_CQN_102120.docdoc fdf5102af9db589345a5c7d4e747c98489a7341147058b2a42e337a03fa62baan/aHeodo
2020-10-21INV_GZ0081508894PO.docdoc 192d1f4fdc36c10af1e2e207ca659c5b7549c01b189257a12f226c42a6c6b4cfn/aHeodo
2020-10-2192324001.docdoc 84163a483557d206843913f622d2da3f15392e74ee55e35d61961d07a1dd68afn/aHeodo
2020-10-21H_3764618024009.docdoc d8d4feb29b46ade146a7b8343070d2a975e4b0e186ca6aac31ea941e46a7af73n/aHeodo
2020-10-21HPO_100120_VHT_102120.docdoc 927877d8e5e4459c44bb91a386050f2aee647421c37048212690b5caa0fba080Virustotal results 48.39%Heodo
2020-10-21INV_87713770.docdoc a977513362ad46e1cab8cdf98638a7e3edcd11796c732a818660e18e49b74a5aVirustotal results 43.40%Heodo
2020-10-21INV_FG8045774790VT.docdoc 8ea38c51f8926ffa9ee61be53fc7ee3e4f968f2c7683bbc3b9320d14a2443067n/aHeodo
2020-10-21PO_10212020EX.docdoc 84feca377993d253e4d214e7c044ddd45eb3ef0f47796ef2970e9a5bd1f2f535n/aHeodo
2020-10-21BAL_PO_10212020EX.docdoc 8db61b871aac2949105b26c1ca2a22579e3b3d6e99aab20279c3bbea5dc87b8bn/aHeodo
2020-10-21BAL_4654094310.docdoc 2465db836fb8ce33c72ba9c55528a00a290b770a2bb977ecaed539b453c1211bVirustotal results 40.38%Heodo
2020-10-21DOC_43999483331493216743857.docdoc 7b59e4314d2b1bbefd045815d54be5bd19315bcd13e3de6816a36bfd0930e032Virustotal results 39.62%Heodo
2020-10-2193227610.docdoc 1393994f35a8a5910cbc519d9a9d9baa91d4dbc85080bea49d95c152892a2aabVirustotal results 40.32%Heodo
2020-10-21FILE_92595770.docdoc cd0c0ee5979ebfa7ed73a40ee1f879f2b65cc57ed38619fc4f7e186c15e54128Virustotal results 38.89% Heodo
2020-10-20DOC_BF4311128821AG.docdoc 681fa75f785a2b6eede8e0045ce0ba666fc0be736b8bba8d23f474b0bc400a7fn/aHeodo
2020-10-20BAL_QVC5O06VFIYQJG.docdoc 8cadf5fc31643a1acc9b991d110e039e7e0520e94783c61d9caf5ccb2481915eVirustotal results 43.40%Heodo
2020-10-2075450244.docdoc 4d4e7e2524b7f191957074f7a24fbae03525c1247ab5d9bad157a9c1405517d6Virustotal results 45.00%Heodo
2020-10-20FILE_81092507.docdoc 73b1ecd0729d4a6776f63d5ec7943f5914ff080311e5f670ab38a4991795d29dVirustotal results 42.62%Heodo