URLhaus Database

You are currently viewing the URLhaus database entry for http://cnaantours.co.il/wp-content/OCT/AtT2P5rG09mB5s/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:756371
URL: http://cnaantours.co.il/wp-content/OCT/AtT2P5rG09mB5s/
URL Status:Offline
Host: cnaantours.co.il
Date added:2020-10-27 13:16:06 UTC
Last online:2020-10-27 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 13:18:02 UTC to abuse{at}upress[dot]io)
Takedown time:5 hours, 1 minutes Good (down since 2020-10-27 18:19:26 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27arc_20201027_999117.docdoc 8a1b55c98e4946eec03ce1b525e3051f05f02a515b87b9c2b53888e52f8bb13an/a Heodo
2020-10-27Dat 20201027 UJL701.docdoc 9da429ab41ad163f2dd7a4f949c160d473aa786147a5088e86c4a7ba277b543bn/aHeodo
2020-10-27dat-2020_10_27-FDM769.docdoc ad416b925e4aa45c9144ffb09541298b08067f86561509827fa141ecae649914Virustotal results 33.87%Heodo
2020-10-27list 20201027.docdoc 0733e953ba1f52bb87d8be9fa084223ad405b556d65ff73351ad83e6550c9517n/aHeodo
2020-10-27Dat_2020_10_27_396275.docdoc 4a6894fbfe3e963d774dabbe89a8bfddcfb7e2feea50050195178d73f3562336n/aHeodo
2020-10-27Inf-20201027.docdoc 56ea3d5db4eb0c842f6ffd51d225f3b420ba1187a6b8f7bc15bf333953b750e0n/aHeodo
2020-10-27Rep_20201027.docdoc 541f859ac32cad287b78d2c974c701bfdc423e364b1887d596e0a65b33de30a5n/aHeodo
2020-10-27REP-2020_10_27-7482.docdoc e0cdf96812571b284a3020fa25032cb1e55574bc3903c7d56f21226daf864d95n/aHeodo
2020-10-27doc-20201027-B78495.docdoc 8ec2421fcede86da656d51271e5e5987a485c0ae19bbd7e385bf7029947da4dan/a Heodo
2020-10-27ARC-714.docdoc 0d4606b5760bfc879d2a19d4015d5bea06657aaeb4c571fcab5de758141b64d5Virustotal results 29.51% Heodo
2020-10-27MB48769_20201027_55576.docdoc e9e8c81c1a04398354083d9ca64a76a70ef2440c1011ebbc59de0ebd1b7ddbd4n/a Heodo
2020-10-27Arc-2020_10_27-98122.docdoc 622b70a9335e95bd716b8d4e6cf68bbed4e395c0acdc8a7ff73a9458e77d6c66n/aHeodo
2020-10-27File 20201027 WK2918.docdoc 771179cd9433568cd9fa5162c351f2f753d685b6645514e85e897c0f78fc8ca8n/aHeodo
2020-10-27MES 2020_10_27 10100.docdoc d37e36ccf1d1d6305c792cf1fa6646b2ea51b0caab3d7c9c5b26e852d14c0b89Virustotal results 34.43%Heodo
2020-10-27arc 2020_10_27 498001.docdoc f612801db656f25281d54994a6c06e69b16e74f17f8d1b7db534adae339e2910n/a Heodo