URLhaus Database

You are currently viewing the URLhaus database entry for https://costcutterent.com/wp-admin/public/3yyxbnr90ybs-0946/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729132
URL: https://costcutterent.com/wp-admin/public/3yyxbnr90ybs-0946/
URL Status:Offline
Host: costcutterent.com
Date added:2020-10-21 12:17:07 UTC
Last online:2020-10-28 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 12:18:17 UTC to abuse{at}contabo[dot]de)
Takedown time:7 days, 0 hours, 53 minutes Bad (down since 2020-10-28 13:11:33 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22SOK-100120 ORHE-102320.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 39.66%Heodo
2020-10-22October invoice.docdoc 7104dd32f9de62701f5d5a01ac763237757d11e8fa2c10ec24749f5791467fcbVirustotal results 38.98% Heodo
2020-10-22Inv_7003.docdoc 67c1b651e75a7c189396cf60ba8461c90336f917091b09d97b042a0ca7ef70a2Virustotal results 38.33% Heodo
2020-10-2207313256.docdoc 4a44eb422716acd382deed2b165d37ce8de2d799d1c466a1aa2e1952f4b943eeVirustotal results 45.16% Heodo
2020-10-22INV_671189.docdoc 2c746449ae089b436ecab1058c035e9ea8e01fd8f45508ed2ed720ff30ee2c01Virustotal results 45.16% Heodo
2020-10-22October Invoice.docdoc 2bc5c1591569f6e8a480a530bf343df21867da564b7503824cb0e5193d3f8937Virustotal results 41.38% Heodo
2020-10-2200865708.docdoc 889113bf50a9e3543f97ca07e4e572f2328587944be4de82f441ba1b23e6ece1Virustotal results 45.90% Heodo
2020-10-22Form.docdoc 410f511f7ba84ffbd69fbabc0226828f52eec22c5b5db6759f60fb65ea20270aVirustotal results 42.62% Heodo
2020-10-22invoice #5457.docdoc 948302725f3208d721629436cfe1abbf592c813da68627c3c158cc6547e1cadbVirustotal results 43.33% Heodo
2020-10-22form.docdoc b97b367766b6d02c9d56c0e849f894229c5eed891450c0a04794ec7124168c56Virustotal results 47.17% Heodo
2020-10-21Inv_52478.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo
2020-10-21004436201.docdoc edceeb0a4307b08df79e506dd7c07185337cd4a6b3f7a979d55b168f768d94eaVirustotal results 32.26%Heodo
2020-10-21Payment.docdoc e99ab9a43fda936582d3e49abcd562f045f62340fba2162f933fd97006ee5e17n/a Heodo