URLhaus Database

You are currently viewing the URLhaus database entry for http://immuneboost2020.com/wp-includes/3qjyapu1/y4f75uu5bssd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729680
URL: http://immuneboost2020.com/wp-includes/3qjyapu1/y4f75uu5bssd/
URL Status:Offline
Host: immuneboost2020.com
Date added:2020-10-21 14:29:04 UTC
Last online:2020-10-23 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003025954 created on 2020-10-21 14:30:11 UTC)
Takedown time:1 day, 21 hours, 20 minutes Poor (down since 2020-10-23 11:50:35 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21F_RYOJZUWG5.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 41.51%Heodo
2020-10-21BAL_PO_10212020EX.docdoc 0d4957ad656edeaef3f49b20de1845bcafd5e78981c607cff352212e84ae913en/aHeodo
2020-10-21SE2947164030LW.docdoc 45624f05bc4fd26e7a1d0263d25d177e1296ffbc6c459542f3e64709f517f1ddVirustotal results 40.74%Heodo
2020-10-21CGTB_83042399899472419.docdoc 77aac1b53f10e8c37401b99cd8c746ceed663e34f07f4195ee437178595c5a89n/aHeodo
2020-10-21F21AF4JSOQ3AT.docdoc c918e4496eda71d4934774f5bed0f956d1810ac516f9460cfe22f4abeddf2af9Virustotal results 30.65%Heodo
2020-10-21REP_137506098887.docdoc 1cb0001d422c0b16aa106ca96ff8aa0db8fec461c49b8f80ac75b5ab4001803cn/aHeodo
2020-10-21PO_10212020EX.docdoc 29cb3ec3beb6ca2f741754847b581ceff558616ae86bd67e8487abced4417160n/aHeodo
2020-10-21BAL_98738194928213732359.docdoc f32c2612be11b6cce6029b0f7b2b9396e61d7313b26fb513f79b5d416349f937n/aHeodo
2020-10-21INV_GEG_100120_KSC_102120.docdoc 25c71c161f7a916496cd76d407fc6a0863e2f36fa50e8b2cb886b5ca7b853dfan/aHeodo
2020-10-21DOC_CYR3Y5CU.docdoc c795410a11e049b4c007e1648b82c47fcd32c76a3bdae2cc72ebe46aad435854n/aHeodo
2020-10-21BAL_NV7631764800GI.docdoc c5a24c44676321aaf9dbcd1eba6df9c5ca6433f79184f914f8516a94077eb5cfn/aHeodo