URLhaus Database

You are currently viewing the URLhaus database entry for https://testers.me/cgi-bin/p/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:751714
URL: https://testers.me/cgi-bin/p/
URL Status:Offline
Host: testers.me
Date added:2020-10-26 13:17:08 UTC
Last online:2020-10-27 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 13:18:17 UTC to noc{at}premianet[dot]com)
Takedown time:11 hours, 21 minutes Good (down since 2020-10-27 00:40:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26BAL_PO_10272020EX.docdoc 99f4e6496067c7a7b9d8cd390470315cc63c4f3adb23c3d885b886f9d86786edVirustotal results 38.10% Heodo
2020-10-26NRR_100120_GPZ_102720.docdoc ac739c4d98aa46329d4ebe114bad66247375ddaf8d148446712f2a2b8006f300Virustotal results 38.46%Heodo
2020-10-262969936017837666.docdoc 7569ec933b0114593361c66c86f8317cdb131aece55945e0634987155a0d0ddeVirustotal results 44.44%Heodo
2020-10-26KGV_1353237288650754461039669.docdoc 5542c37ee5faeeea86b317db009b24a38f581860e468db0ae1d61b0850aa3463Virustotal results 35.48% Heodo
2020-10-26FILE_3KBG7K6SG7.docdoc 1876ecab19ee6802dac2e8774dfd625dcb2d4e00fb61f446caeabd26db1405a4Virustotal results 37.04%Heodo
2020-10-26VQUY5D1KCSKEM4.docdoc c989f9fa249c44f5aa5e7beb1781d22d20154daae1750c5f321e00f739a742a9n/a Heodo
2020-10-26REP_5XN9XVYU.docdoc 395aa1cb5a6a567708e1a0d53eb1c21eeaf8973a53bf52baa2bbfb968525c351n/aHeodo
2020-10-26INV_HT2759469431VU.docdoc cc341e2451041bcd6d9dedc66abe480900021abc803788e2d56b701edee7e044n/aHeodo
2020-10-26INV_IZ1308438991FO.docdoc dcac3f433bca625d1c831d29f00d254dcc6740ca1779ebf9f6483ab6fe431c21n/aHeodo
2020-10-26FILE_RACC21IW6MB.docdoc 5a852301fc77705feb086249753d26f6b2b8cf5f8fedd64ef0fc246e842af909n/aHeodo
2020-10-26INV_PO_10262020EX.docdoc fd1ed1165259d49544da247f9fa6025087914113360a444c9a13aaaeab57a5b8Virustotal results 38.89%Heodo
2020-10-26DOC_PO_10262020EX.docdoc 0f42df210cf372d884bd0cb9074d9760880bc0aa34168f889b8e28dc016b006cn/aHeodo
2020-10-26DOC_PO_10262020EX.docdoc 175f70e42ab1da776d956a78b3813c139a60bc27bcc82d52b292184499905fb4Virustotal results 38.89%Heodo
2020-10-269995832939049983151020645.docdoc 9984eddfbc2dd95122946859d15907841ecc6834d8a87869837cd309180f03d4n/aHeodo
2020-10-26INV_68532660.docdoc bef2cf86acbba45a17385614351f915491d344ba1d20e5936379853d0eb2b0a7n/aHeodo
2020-10-26BAL_72820908.docdoc 9c6f43dcc3bd1778ac7082fcd98251f2ebbc67b02f5d6e41ab97c2e8924a4e17Virustotal results 38.89%Heodo
2020-10-26REP_PO_10262020EX.docdoc 77308b34c7f167510dcdfc5e0de665824b0826603235b32f2c644ddf354cf6fcVirustotal results 36.36%Heodo
2020-10-26YK9561487135IJ.docdoc ed7748045b321a2e819fdb922995edf21e8b02996994aaebf64df519509d669eVirustotal results 39.62%Heodo
2020-10-26REP_AS7366883428LV.docdoc 0ab03990f76631ea9155550ab1ce403dbcebc068697d78958d1e6fbb587c2639n/aHeodo
2020-10-26INV_BGM_100120_KLG_102620.docdoc 59313b58db747c4adbf79a02bb4aaa6b2d05a4f261f9281cb85b0a9354112506n/a Heodo
2020-10-26DOC_PO_10262020EX.docdoc 49b1f2c7ac2e8c1c45de03a14885c7f3d52072416c83e28144303a139fd14decn/a Heodo
2020-10-26GGU_100120_SKW_102620.docdoc 4513610c3e62aa333e75c078ea6d65a4180d4b525ed28c93d9f275b676cba261n/a Heodo
2020-10-2616157723.docdoc afae246f3da5ce4240ec1b56423c9e4e48f18d87ef7de357639b3273752b0e6bVirustotal results 36.36% Heodo
2020-10-26PO_10262020EX.docdoc 6aa9657cfafdc356e9d69ff1eb419f66eaf20e826eec75b414cafea0a4a5bf02n/a Heodo
2020-10-26PO_10262020EX.docdoc 40c2d1798a011903e75ff5bdd7efe2d44845a2f799084210fbce273a0a4b413dn/a Heodo
2020-10-26DOC_374957371868018.docdoc 89e9087c2069b0a91de01d8586e0c76eeb254c421bacbe87986af7a04c154ec8Virustotal results 35.48%Heodo
2020-10-26Q_KE4PTSZY.docdoc 8c78a8f59d55c687a6335a8fd89df4bc5145de33f88d09b68ce9bd36c9430fd6n/aHeodo
2020-10-26FILE_YEV_100120_YSO_102620.docdoc 0f843d1073b6f1f43e4fff6136ff834dbcbe5716f80e1b5620e535c4f63957cbn/aHeodo
2020-10-26XEV_100120_IML_102620.docdoc 08815b189e49c8ac0b9650dcfdc52a7443d90353a83d3393b9e104bb4c2c0701Virustotal results 37.29%Heodo
2020-10-26BAL_36198466.docdoc 243709f4e8786c289062a5c719dcd1f45382f1fe57b527abd097f68fc897eb4fn/aHeodo
2020-10-26S_OQU_100120_ZDX_102620.docdoc a63c502e6b17dff5564bd862d8f81577c7311ae759e5dd3a63e9ad5e91071a40n/aHeodo
2020-10-26FILE_P5GTWZ45M9XD.docdoc 4b1547415d334829daf8667917db64ab56ce678a7b27f6e3fc08f342ad6fae73n/aHeodo
2020-10-26DOC_KSO_100120_DOC_102620.docdoc aef00a331229e379b2f5709780900d6f28df9cfad621d3ce64663ced9f4ac828n/aHeodo