URLhaus Database

You are currently viewing the URLhaus database entry for https://www.customersols.com/wp-includes/sites/FL0pBLdJCPMe/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:735384
URL: https://www.customersols.com/wp-includes/sites/FL0pBLdJCPMe/
URL Status:Offline
Host: www.customersols.com
Date added:2020-10-22 15:56:04 UTC
Last online:2020-10-22 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 15:58:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 46 minutes Good (down since 2020-10-22 18:44:20 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22arc.docdoc b7758be40eeb57934e1c9eb369fc6dac10dae365c63ae2627ba882425b1992a6n/aHeodo
2020-10-22Mes 20201022 X356067.docdoc aba2852c2ede40d00712d4f0bf753af374f10fa332d165c7bf62b40803c6b393n/aHeodo
2020-10-22Dat 73902.docdoc b02a934a10f405b76ee0aaa46e19847d9ecf1718d49ef72233e83d4c5468a626n/aHeodo
2020-10-22FILE 9476560.docdoc 5921c47a0cb46d88d65b6c9742b65a2156187647336eb9a724af2bd7b5f35d2cn/a Heodo
2020-10-22INF_IXO9235.docdoc ea9805f9723659f50487de76e4fc122b369f76a771cb6d06ff42cc6649485380n/aHeodo
2020-10-22Arc 2020_10_22 60585.docdoc f5ea3c1fdc14d93a641aed549436c491220ccd2571f6bcc627d23ff0c5e37b1dVirustotal results 40.32%Heodo
2020-10-22rep-TJM132.docdoc 6839e799b693e3ca94e8dca6215c30843d0efc0df15a694b38f195b56ee67770Virustotal results 39.29%Heodo