URLhaus Database

You are currently viewing the URLhaus database entry for https://atrezzos.beneficiosparaempleados.com/wp-admin/w4u796wx6s4ke/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:726024
URL: https://atrezzos.beneficiosparaempleados.com/wp-admin/w4u796wx6s4ke/
URL Status:Offline
Host: atrezzos.beneficiosparaempleados.com
Date added:2020-10-20 23:18:05 UTC
Last online:2020-10-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 23:20:22 UTC to abuse{at}amazonaws[dot]com)
Takedown time:10 hours, 14 minutes Good (down since 2020-10-21 09:34:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21REP_JP4301265992NL.docdoc 442199396365c09418756cb80ff20ce46129c4a0cc2cfc6dabf5e8bb2cc42437n/aHeodo
2020-10-21BZU_HYG_100120_PKS_102120.docdoc af36ad567085faaef5425d233641e227fdf842e426001e855103b942dde705efVirustotal results 46.55%Heodo
2020-10-2113809913.docdoc e6335af6ecbbb9d05de5332fb55088045d8066babe6f9fb4cb05e7097ce44046n/aHeodo
2020-10-21E_TF5415587513BS.docdoc 389ad5d9d72b446e4ea03160b107fdc48402bcc7c9f664d73851ebe4d4c7b660Virustotal results 50.98%Heodo
2020-10-21BE6743516510BZ.docdoc 8be69726081c102e6e9fff4160b360cdb5818e8d002bfb2cd1732b9d511fce92Virustotal results 49.18%Heodo
2020-10-21INV_HDO_100120_ELT_102120.docdoc fcd4efaae00015d956a28f77cd06f9b327aab1c3f6a7604660cd4ce3e638e1edn/aHeodo
2020-10-219003635597212790858015123.docdoc 39a7385578321db9d477ff19e7087b03d3c57076ceca16fc2af049c087f72343Virustotal results 38.98%Heodo
2020-10-21W_55316722.docdoc 4d674a6143e1a896967213d335f2d95bdcee16aa83b718071ad004c674e458c5Virustotal results 48.33%Heodo
2020-10-21N4FYGWO1L30O6.docdoc bde4c84d280a8a946e6bc75242c05f9d2b7feb93f84625d34174f8b92b772a15Virustotal results 48.08%Heodo
2020-10-21482154705486357960395333.docdoc fe1e5c66a4990cc515e5925db68def9f29f1893d9c6d3fa6b47e05f5c5f618ddVirustotal results 46.55%Heodo
2020-10-21D_PO_10212020EX.docdoc ef31028a7bfb047b5233493c6b8e14ac6fa49ac6d022b6e016a22276a4be732fVirustotal results 46.67%Heodo
2020-10-21DOC_69597729.docdoc 56074bdd23c71846faa6ab17e8fc8485ce763ae329af8573a9e877dd6ec6513cVirustotal results 48.39%Heodo
2020-10-21ZT5294376284CG.docdoc a22d83a786eb7f5a04facaabb04117ecb5f8cdf09fcbb8405c0a70c97a51f225n/aHeodo
2020-10-21INV_08032613.docdoc 730dc7281140bb144e159ad27638ff4f4d3a021999727a26b7731250343a3f76n/aHeodo
2020-10-21DOC_0992847229205123701412.docdoc 84feca377993d253e4d214e7c044ddd45eb3ef0f47796ef2970e9a5bd1f2f535n/aHeodo
2020-10-21DOC_QXC_100120_EIV_102120.docdoc 8db61b871aac2949105b26c1ca2a22579e3b3d6e99aab20279c3bbea5dc87b8bn/aHeodo
2020-10-21NMN_79606561.docdoc 6eb67022c07e3f32436afc6e89eddb132a4c5d34d733c824ab3dabf51b7c712aVirustotal results 39.62%Heodo
2020-10-21BAL_RSF_100120_SVW_102120.docdoc 9a65518effade1bf32d7589d7f7a8a028f9fa7f1fca4491673680847d26d3f0aVirustotal results 38.89%Heodo
2020-10-21INV_DDV_100120_LPU_102120.docdoc fb83f2eec33aadc1229efe5c44276c92fbf59ce6dfab221071a61ca25c694a82n/aHeodo
2020-10-21REP_64840463.docdoc cd0c0ee5979ebfa7ed73a40ee1f879f2b65cc57ed38619fc4f7e186c15e54128Virustotal results 38.89% Heodo
2020-10-208O5E1Y2THJFUM.docdoc 681fa75f785a2b6eede8e0045ce0ba666fc0be736b8bba8d23f474b0bc400a7fVirustotal results 39.62%Heodo
2020-10-20DOC_PO_10212020EX.docdoc 42ed0808f1038d0899d043a7d0e074010bd3dddfdc23d46455c728cad69edb68n/aHeodo