URLhaus Database

You are currently viewing the URLhaus database entry for https://cuz-art.com/wp-admin/sites/rwc5bk8ltenrs-00029/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:735625
URL: https://cuz-art.com/wp-admin/sites/rwc5bk8ltenrs-00029/
URL Status:Offline
Host: cuz-art.com
Date added:2020-10-22 17:16:06 UTC
Last online:2020-10-27 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 17:18:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 days, 23 hours, 54 minutes Bad (down since 2020-10-27 17:13:01 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-23October invoice.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 57.38%Heodo
2020-10-22Invoice #786518686.docdoc 73c15020ef9bf16ef338a7808aeba33bed02253197dbf1251f68c3a954ead5b5n/a Heodo
2020-10-22Inv_9341.docdoc 2a3debc28e12818dd54c53582337c7024a1cfb99138ea2baf06c6b45a36efc2bVirustotal results 38.71% Heodo
2020-10-220519683.docdoc 9192adc6ad055a6e640fd17c385e4aa7e88fad75617119f2f64efcec5dc4da19n/a Heodo
2020-10-22form.docdoc cd20ae1b00fceba422cc5bd5b2c7e42686f65e5ea4ef237340ffc7dd3e1a28f1n/a Heodo
2020-10-22INV #0852 FOR PO #35938505.docdoc a53f4bb796189439737207c506acde597330328109ac2d78b693d2d6a72e4ba8Virustotal results 32.79% Heodo
2020-10-220021624.docdoc 2f11fb391c4e5106c86f7af02261b1ce605f84877b62af40538177fc258c9e05Virustotal results 35.85% Heodo
2020-10-22INV #392251 FOR PO #005684750.docdoc 01b228cd4f024acce23be7b762797915e8ece1d47c301e20f9596a98aed2acb5Virustotal results 49.06% Heodo
2020-10-22G026 invoicing.docdoc 74e16bd58ef88cfbc4267cf32b54a6444f5a01675811af2f8da025c1dd9e7272n/a Heodo