URLhaus Database

You are currently viewing the URLhaus database entry for https://servu.co.uk/test/Reporting/LJKxaT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:726559
URL: https://servu.co.uk/test/Reporting/LJKxaT/
URL Status:Offline
Host: servu.co.uk
Date added:2020-10-21 01:43:03 UTC
Last online:2020-10-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 01:44:07 UTC to abuse{at}aware-soft[dot]com)
Takedown time:7 hours, 31 minutes Good (down since 2020-10-21 09:15:59 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21Form - Oct 21, 2020.docdoc 20822d454fc7b4ccc00e84d41fcfebef444b6d243921dd0e7db0c7252f1e319bn/aHeodo
2020-10-21SKH-100120 XYYZ-102120.docdoc 4b091f47077d168f83c5f39f3ca6837c70c9fef749880418389cf07514420dc3Virustotal results 26.23% Heodo
2020-10-21invoice #27197.docdoc a3b6842573584f704d6a8e14964f20811e162c91bcc4e3aa8b0eb7c7948db506Virustotal results 29.09%Heodo
2020-10-21Copy invoice #53380.docdoc 51ab187886aefdddbe682cc0044049fd5c06bac5f1cda813a77165f3ad31548an/a Heodo
2020-10-21Invoice 06587294.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-212656949087NV.docdoc b7b2d0ef7df5007d18a8a857ab7b35956aa9060aa4edfb1bd80e17299d53d9a7n/aHeodo
2020-10-21Payment status.docdoc a9b5951976e5aebe82b1a18ef33e379ec5f3a36a04b89103649e54d7dc746aecVirustotal results 32.26%Heodo
2020-10-21form.docdoc 5ab195348086d508a9be2e1c480fa60e9de009a7f057dbaf696f8468ec4fe0f5Virustotal results 45.28%Heodo
2020-10-21001423327.docdoc a3bd9261b5a8844a6a6a77e06f0eabf6a21d998001e99718a42f8bfc8147762dVirustotal results 45.00%Heodo