URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ffval.hr/wp-content/Scan/Q1MRwUSxCh22/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:756441
URL: http://www.ffval.hr/wp-content/Scan/Q1MRwUSxCh22/
URL Status:Offline
Host: www.ffval.hr
Date added:2020-10-27 13:31:03 UTC
Last online:2020-10-27 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 14:14:04 UTC to abuse{at}hivelocity[dot]net)
Takedown time:8 hours, 39 minutes Good (down since 2020-10-27 22:53:25 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27MES TO3575.docdoc dc195bb810b63c35c74cc0cdd8690cff533be0b29da2a5e568c8a03d6b3bc05en/aHeodo
2020-10-27mes 2020_10_28 57920.docdoc 53f11a87c5eb09d98d2ad6807bf4a19a1844cd1c984dcb9365e45650ee7374b0n/aHeodo
2020-10-27SP45244-2020_10_28-02237.docdoc c3818cd19dea22ec57019811800868c16deff091d40f34d342edb80548efe3d1n/aHeodo
2020-10-27Arc-20201028-D0886.docdoc fdc02372ac6d7b4a8701285360493b05002f7036df6d3fec2cde93f7e8a5de75n/aHeodo
2020-10-27ARC.docdoc c4478df05ea4d77b2886f04b1a0b8ab67fd66e0f90064c0fce17fdf1171aec22n/aHeodo
2020-10-27doc_20201027_V294.docdoc be937cc53bc89c68684381e254ea5664f66b9768303dd4785f47cb80a1f74ac8n/aHeodo
2020-10-27mes-W611.docdoc 59e7bf592af805bd634d797e7fe5d0d78c1e3afb137bbb6856ccb666d90a6052n/aHeodo
2020-10-27DAT 20201027 7386191.docdoc cdc1427cf3a9f3846751e5ce98bbbf6ccf50da723831c6c5b6a976423d45a8a7n/aHeodo
2020-10-27List Y699244.docdoc 440710866f2af5dec3a2fb47d43a20a8d599fadce987787c6772a857b926669dn/aHeodo
2020-10-27Mes-HG8756.docdoc a0befbd5126d4660e42ef357002601c14c94c5e2b1f9c83097159362a590075dn/aHeodo
2020-10-27MES_M550.docdoc 56ea3d5db4eb0c842f6ffd51d225f3b420ba1187a6b8f7bc15bf333953b750e0n/aHeodo
2020-10-27Mes-20201027-KXO16701.docdoc e0cdf96812571b284a3020fa25032cb1e55574bc3903c7d56f21226daf864d95n/aHeodo
2020-10-27File G668234.docdoc 64b295d16bdacc46b3fcd5e6c94c46b078fe76819ed6f38eb394aeb82276f7c6n/aHeodo
2020-10-27rep_20201027_X2275.docdoc 771748c06f8fb85d2ff96fe6b210eafd43e3c84aa1cb971e7aa1db6e5b272439n/a Heodo