URLhaus Database

You are currently viewing the URLhaus database entry for https://reallifehealthandfitness.co.uk/wp-content/sites/0vq77k5bsv705yg/ln2x6l8cczgwi0q3u73fzgzen/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729962
URL: https://reallifehealthandfitness.co.uk/wp-content/sites/0vq77k5bsv705yg/ln2x6l8cczgwi0q3u73fzgzen/
URL Status:Offline
Host: reallifehealthandfitness.co.uk
Date added:2020-10-21 15:50:04 UTC
Last online:2020-10-21 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 16:32:08 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 42 minutes Good (down since 2020-10-21 19:14:17 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21FILE_GGT7Z8VEVQK.docdoc 5603b9a3314a6d1e9220de7c0d42d8fae17921bf022ea4a8be18d5615989848cVirustotal results 40.00%Heodo
2020-10-21MVSDVBE6RRDUFTZM.docdoc ee8ef9beac4202e018577996e293215dd2cc1e260bca0ac0a38f9abcdcd4fa2dVirustotal results 33.96%Heodo
2020-10-21FILE_98674892.docdoc 0f850282e2508eb5472f9cbae697cfca8675a66d6581f269509f5db6a9f30e53Virustotal results 32.08%Heodo
2020-10-21FILE_61826829.docdoc 29cb3ec3beb6ca2f741754847b581ceff558616ae86bd67e8487abced4417160n/aHeodo
2020-10-21INV_3EFYGKKXHMLYE.docdoc c0308a4a6567ed36df7165b3cffbe26f676322783de09900dd7b7e6b7d642b97Virustotal results 30.19%Heodo