URLhaus Database

You are currently viewing the URLhaus database entry for https://thesafezone.co.in/wp-admin/OVLVNfMt3UTO4k0gu0T8H7jWXmLdcY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:753455
URL: https://thesafezone.co.in/wp-admin/OVLVNfMt3UTO4k0gu0T8H7jWXmLdcY/
URL Status:Offline
Host: thesafezone.co.in
Date added:2020-10-26 21:42:04 UTC
Last online:2020-10-27 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 21:44:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:4 hours, 31 minutes Good (down since 2020-10-27 02:15:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27BAL_XIP_100120_PMQ_102720.docdoc b9efcf9bbdfee20efe56047ca5810ea88974d9e7b9ec968a57f814842c7946ecVirustotal results 39.62%Heodo
2020-10-27REP_PO_10272020EX.docdoc bef2cf86acbba45a17385614351f915491d344ba1d20e5936379853d0eb2b0a7n/aHeodo
2020-10-27FILE_BC7835869068WF.docdoc e955daa4404b745ed6c72a2e99899af5ad6b133c5b24f5665d4649cdcff05fe2Virustotal results 38.89%Heodo
2020-10-27BAL_B1W2BQ8.docdoc 284ca49487afcbd5dc06144fd8a4b4ebaf8abc174a9c0c609a5073f4925ec19eVirustotal results 39.62%Heodo
2020-10-27INV_162623863225278270487954.docdoc 9a5ff2d10eb6a49a82083f2f52e3daba519399794197d526ab76a68dd6849e69Virustotal results 39.62%Heodo
2020-10-27DOC_81854064.docdoc f5831fd5a2bd8c3eaf0bbd799764d684f1c3a2528d5583013b438e6f2b4f4843Virustotal results 39.62%Heodo
2020-10-27N_BX8593206919FU.docdoc ada5eecfbbe470ecc1b1c434323530f141ac930ee6febd5c6e578dda073ccbecVirustotal results 38.89%Heodo
2020-10-2797664699208211.docdoc ed7748045b321a2e819fdb922995edf21e8b02996994aaebf64df519509d669eVirustotal results 37.74%Heodo
2020-10-26988Z7FHKE.docdoc ac739c4d98aa46329d4ebe114bad66247375ddaf8d148446712f2a2b8006f300Virustotal results 38.46%Heodo
2020-10-26BAL_HNBPYZA.docdoc abfcd6342895929d5baf093e13140d0b37f8e97da0253480aa94ba5e78bcd1e1Virustotal results 37.04%Heodo
2020-10-26INV_PO_10272020EX.docdoc c8ec858c06478f6261eadea96e71a453f5176eb9b07c801ad5d84bde75ccda10Virustotal results 37.04% Heodo
2020-10-26INV_457363120.docdoc 1876ecab19ee6802dac2e8774dfd625dcb2d4e00fb61f446caeabd26db1405a4Virustotal results 37.04%Heodo
2020-10-26C_KZE_100120_KLN_102720.docdoc c989f9fa249c44f5aa5e7beb1781d22d20154daae1750c5f321e00f739a742a9n/a Heodo
2020-10-26INV_NHB_100120_YJW_102720.docdoc 7e2498c2125b196f853bab661649d81424c604a5506801229b8b4128d3cf5a4bn/aHeodo
2020-10-26REP_DAA_100120_CWI_102720.docdoc 86b0701737b73d1713cc04f83dd9e1d5d8dcee914c007cca4d5a6a1870f7b067n/aHeodo