URLhaus Database

You are currently viewing the URLhaus database entry for http://dolorescantu.com.mx/ikzjfrigai/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729682
URL: http://dolorescantu.com.mx/ikzjfrigai/
URL Status:Offline
Host: dolorescantu.com.mx
Date added:2020-10-21 14:29:05 UTC
Last online:2020-10-21 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 14:30:25 UTC to abuse{at}mediatemple[dot]net)
Takedown time:5 hours, 49 minutes Good (down since 2020-10-21 20:19:26 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21PO_10212020EX.docdoc 0d4957ad656edeaef3f49b20de1845bcafd5e78981c607cff352212e84ae913eVirustotal results 41.67%Heodo
2020-10-21DOC_L8WCABG4QALBAU.docdoc e5c6d836a7fa994928320dbfced86beeaa1fca7178acfcc05d083304f539cf88n/aHeodo
2020-10-21G_0311546271712.docdoc 633b2b1963bd2dd467845e87a2d06ace1c22e9402d4dd3aee12618af8f0846a8Virustotal results 39.62%Heodo
2020-10-21DOC_QZT_100120_EZP_102120.docdoc 7acda67964abfefe6dfc1755e75b418e82bae70cd18d73fb0686b0c1910a6320Virustotal results 33.90%Heodo
2020-10-21INV_GAW8S35S.docdoc 202d0af84b5b68cf2a54ce8f9afa3befc8f994b934e380cbc1dab9dfdbd11bccn/aHeodo
2020-10-2113328223082587971057.docdoc 5633dcdd6cb771b75b85211ece3df0d9190a2e7c2c0b24ebe6a33b8584b8470cn/aHeodo
2020-10-21GP8841720538NG.docdoc 4d2ca163c6d59789cde935b7d539ba3c8e4abd2beed45704fba11fe67fc983a2Virustotal results 25.81%Heodo
2020-10-21BAL_907218732232676346105931.docdoc 638d2c28c891f1eb997a450dbdc2f6f1a83b000d7b617d3000cf2b937275de99Virustotal results 21.67%Heodo
2020-10-21NZ4332489742CT.docdoc d2a68a5159ea637fa9428d39a0d9469c6c2db0b16b2de2593070c17a0ad49520n/aHeodo
2020-10-21INV_PO_10212020EX.docdoc c5a24c44676321aaf9dbcd1eba6df9c5ca6433f79184f914f8516a94077eb5cfn/aHeodo