URLhaus Database

You are currently viewing the URLhaus database entry for https://www.argentiina.ee/wp-content/NcRrBEwiV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:735626
URL: https://www.argentiina.ee/wp-content/NcRrBEwiV/
URL Status:Offline
Host: www.argentiina.ee
Date added:2020-10-22 17:18:05 UTC
Last online:2020-10-23 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 17:21:19 UTC to abuse{at}zone[dot]eu)
Takedown time:12 hours, 33 minutes Good (down since 2020-10-23 05:55:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22BAL_2934225981.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdn/aHeodo
2020-10-22UE8096947033NU.docdoc b8ece70cf490f0972af7d834da13670c73176dc58bd1d22e254548ea64220df4Virustotal results 42.31%Heodo
2020-10-22DOC_ZPL_100120_ZGP_102220.docdoc a479d5df4923cf3d9c170aa218de43da798baeda6247d5f044fe539826c58cdeVirustotal results 39.62%Heodo
2020-10-22I8BUNZSJ1JMQ.docdoc 892a53376594e2bdf65731771d6e7faa4d36e2d3b95340ac4984ec74536d3604Virustotal results 41.94%Heodo
2020-10-2206129052576369741027.docdoc e9d87e6f00f59e3b84a5389f77adc3ce03b38559a26aee1be20f6bf5c00e76fen/aHeodo
2020-10-2261381921.docdoc c9eac6b72f9a7b1750b750639e977312f982799bf1e82ba3c19a8f3c1be46f7bn/aHeodo
2020-10-22BAL_ZB7881350091BL.docdoc 9240c94cc6ed0ba3216b915f27c3b8ed8995206803a332f664297fa4d5e1c72cn/aHeodo
2020-10-22KOOG_56981286.docdoc 0dcf5051405a8df1087b5cf36dc02c73c8625397dd38bbee394b11858055e85bVirustotal results 38.89%Heodo
2020-10-22DOC_89255820094.docdoc c2d0f5206ff0a203e1aa63b0ecb20b112dadd22f5e451ae5df23c58d687512e0n/aHeodo
2020-10-2279448558385592613805293.docdoc 130b0d52b8df9059f2964dae24544b8b6f7b9d9c2aff69e233802076bc6f3c0fVirustotal results 37.25%Heodo