URLhaus Database

You are currently viewing the URLhaus database entry for http://redhillestate.com/wp-admin/5HlVTtE3qnVDAJoyax/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:735608
URL: http://redhillestate.com/wp-admin/5HlVTtE3qnVDAJoyax/
URL Status:Offline
Host: redhillestate.com
Date added:2020-10-22 16:55:04 UTC
Last online:2020-11-01 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 16:56:02 UTC to abuse{at}paragon[dot]net[dot]uk)
Takedown time:9 days, 18 hours, 7 minutes Bad (down since 2020-11-01 11:03:25 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22REP_ZGC_100120_CUG_102320.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdVirustotal results 42.00%Heodo
2020-10-2201009656.docdoc afd227b07c577d52646f947182d3f65be45a70cb65bbc5316ecfae58e51e33bdVirustotal results 41.94%Heodo
2020-10-22CL7453123710LC.docdoc bac7b15c1cc9eedfd4670ffe4383b4c9562b04a5fb2cece968408833f933a765Virustotal results 44.26%Heodo
2020-10-22DUB_98448306.docdoc 9f65b2da9711ae073e9056684b032f224a74c70618847b58f9ba3f45149193fcn/aHeodo
2020-10-22FILE_72872033.docdoc ed814b65f700a5233872fb47c90aeecc7be03da2397e5b3b74143544ad1c4099n/aHeodo
2020-10-22J_CAA_100120_CPP_102220.docdoc 7726801f846f3a79f073244ea0ffbfbed6ee847b498b4ae15f94a1dc09489fdcVirustotal results 39.62%Heodo
2020-10-22BAL_NKQ8SPGLW.docdoc 4cbf400ac380f9f7eacf85fc40e4445447d878ad4023e251f16769b44ff39a46Virustotal results 40.38%Heodo
2020-10-22REP_UC0OJEYFDVW5.docdoc 9240c94cc6ed0ba3216b915f27c3b8ed8995206803a332f664297fa4d5e1c72cn/aHeodo
2020-10-22PO_10222020EX.docdoc 55e79ed4dc97111eb94b6830fdada156fc8d7ca76f3dc5a15d737fbd0dba8757n/a Heodo
2020-10-22REP_07699927.docdoc 92a3496e0cd2170dd3e3a0f5dbe4a3ba772390ca8f139e3c742f2f3a9f006d2bVirustotal results 37.74%Heodo
2020-10-22INV_CMV_100120_RYQ_102220.docdoc 80674fb8973e2a7ee31596d9105d1d897a92f7bbcbf6f07b3bf7a9444f71ca9cVirustotal results 38.33% Heodo
2020-10-22REP_73949489556838716456.docdoc fa80d9c5ac5a3d08f91d1d1a13ca9e8dc5bd6e9dc289fa203b6822c74a1dbab9Virustotal results 38.33%Heodo