URLhaus Database

You are currently viewing the URLhaus database entry for http://cnaantours.co.il/wp-content/Document/c8q1to1y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:730575
URL: http://cnaantours.co.il/wp-content/Document/c8q1to1y/
URL Status:Offline
Host: cnaantours.co.il
Date added:2020-10-21 18:39:03 UTC
Last online:2020-10-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 18:40:13 UTC to abuse{at}upress[dot]io)
Takedown time:13 hours, 21 minutes Good (down since 2020-10-22 08:01:59 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22PO_10222020EX.docdoc d810adecb2a17cc42025465a49799119896605f16af88bb79a6342746b7cd8d8n/aHeodo
2020-10-22G_33779367.docdoc 1d2531f558d817649eb30142108364e3d3716712a0e17d4bf033d4b3013fc7c5Virustotal results 50.00%Heodo
2020-10-22ZKAD_65555880691413589535271.docdoc 0d59d407c6fca62823b5b9e4eacce7270e5b98640aa37b1852d5c298805319ddVirustotal results 50.00%Heodo
2020-10-22YW0Q14I5O3B0.docdoc fe8d90884de697451ea446a5dfd254041d252229a8a17175f11f77486dcdc4d4n/aHeodo
2020-10-22DOC_25244148.docdoc ef3eda0a0ce827c44632df7b430f082bf54965ce02293734e942776bbfd2b1fcVirustotal results 49.06%Heodo
2020-10-22INV_SXD_100120_FGG_102220.docdoc 5216126689ce29d0ead65c0774e9b395ade4b5c2ce71e69d464f3a603a22bdb4Virustotal results 50.00%Heodo
2020-10-22SNWK_HZA_100120_YKX_102220.docdoc 24ca326ece108e2ec02346c32536bd5cd2a990364f8d8c9fa35b082ba4a68f2fVirustotal results 46.15%Heodo
2020-10-22REP_43481816.docdoc 638d64989d1dd97fb0243d59735dcc9441f106f3eaa6288d3c6e18a2b11aaef7n/aHeodo
2020-10-22INV_CUZ_100120_OCR_102220.docdoc 2622c411514e2ebeb404ff72a11abb8b36da194d0f09dcc95869802a01cf4a20Virustotal results 45.76%Heodo
2020-10-22BV1FD8QU9JR.docdoc a7b558ea557788c16a9c93a7aa0cac42b96b2fe92e02c26f4c5d17c1b1da0291Virustotal results 46.77%Heodo
2020-10-22INV_IQF_100120_BQC_102220.docdoc fe681aba1adcf7e82fd0daedeb3af000c89d34693b1dd0022c273e936ed660cdVirustotal results 45.90%Heodo
2020-10-22BAL_HX0892093332JF.docdoc 0b25fca35bd60d2257616a1c1adbf89fefba07969c5a0fc3aa22d3f43ad7c2f4Virustotal results 45.00%Heodo
2020-10-22GZ3984090267TC.docdoc 9b4d04d1dad15a8a798ceba5f12e03c81a04335dca8703f2e4790675688590aan/aHeodo
2020-10-22KGX2YI8.docdoc ac34efa35d04bc35c3bc9eb52c130c25c9841995ed37b75e3f9e04d7c2599bb4Virustotal results 40.32%Heodo
2020-10-22DOC_DJJ_100120_SEQ_102220.docdoc 2da1ed7b630f4a606c6c65a41dc9c852015d64174113023eff5a63c64f5eac0dVirustotal results 41.51%Heodo
2020-10-21BAL_PO_10222020EX.docdoc 0ff220d90538db68f12796da43439ff4b8cfa6fe238bf19c8da81c8463f2c4ebVirustotal results 40.00%Heodo
2020-10-21INV_110254603184413629702095.docdoc 5d0aa0758ab6ea6f3bde55fd7a21fdc8813fe575af13e19a7d0b134a65508638Virustotal results 40.98%Heodo
2020-10-21AH_29320267.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 41.51%Heodo
2020-10-21INV_YEP_100120_PWN_102120.docdoc b730b36a22a6d6da4bf394e59e3bdb0a0bc32a3adc8fea6f568a58b926a7fdc4n/aHeodo
2020-10-21PUCP_GEJ_100120_PNS_102120.docdoc b96b5470dc7d8ed5cab5f58b9064e6c57382d8dbe135093a8ce692e5b4171266Virustotal results 41.07%Heodo
2020-10-21BAL_PO_10212020EX.docdoc 5603b9a3314a6d1e9220de7c0d42d8fae17921bf022ea4a8be18d5615989848cn/aHeodo