URLhaus Database

You are currently viewing the URLhaus database entry for https://moraniz.co.il/wp-content/Overview/uiNSphezRxwN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:735352
URL: https://moraniz.co.il/wp-content/Overview/uiNSphezRxwN/
URL Status:Offline
Host: moraniz.co.il
Date added:2020-10-22 15:51:05 UTC
Last online:2020-10-22 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 15:52:10 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 44 minutes Good (down since 2020-10-22 18:36:20 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22INF-00159.docdoc 9473776ba71d7fb4c1ce5c3d5d0b87d00fc361ae37fd75fd5b7375f30b9c3107n/aHeodo
2020-10-22Attachment_20201022.docdoc b02a934a10f405b76ee0aaa46e19847d9ecf1718d49ef72233e83d4c5468a626Virustotal results 35.85%Heodo
2020-10-22Attachment RE67938.docdoc 00844bafd3dc1431f9661d11e58935bcce4d3b622801cf77904fa51330a84b85Virustotal results 32.26%Heodo
2020-10-22doc-2020_10_22.docdoc d4d6ebf49d6bac5195321c922c5c9ea2b7632f88adaedd8c54a00d98578ff2dfVirustotal results 38.89%Heodo
2020-10-22DAT 2020_10_22 62537.docdoc f5ea3c1fdc14d93a641aed549436c491220ccd2571f6bcc627d23ff0c5e37b1dn/aHeodo
2020-10-22File-2020_10_22.docdoc 33d8282536536c651d28cb08401045d2a01d13e2606369788ecf8ffe2136a4b6n/a Heodo