URLhaus Database

You are currently viewing the URLhaus database entry for https://costcutterent.com/wp-admin/aCMFeCi7BM3kJPQUNOiL0ed/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:759510
URL: https://costcutterent.com/wp-admin/aCMFeCi7BM3kJPQUNOiL0ed/
URL Status:Offline
Host: costcutterent.com
Date added:2020-10-28 05:45:04 UTC
Last online:2020-10-28 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 05:46:02 UTC to abuse{at}contabo[dot]de)
Takedown time:7 hours, 14 minutes Good (down since 2020-10-28 13:00:23 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28MES_A51W32I6UJ7SDTY.docdoc 9edf498a6066ff0e5be970253b4e90411ca4d164fbee2a688c65724a0a0dd403n/aHeodo
2020-10-28PO_10282020EX.docdoc 852d88f248a132193134baba17eb75649f9aab9cb04fc39652d337149c5dfd87n/aHeodo
2020-10-28doc_QGQHXJLDGK.docdoc cb10354a6aff051fe7ae1c2cfb38b40e5ed1c8fd1a4c4b1a35724efed4885995n/aHeodo
2020-10-28UNTITLED_028482196675663427.docdoc f557390768f97bbb354c11917ec9e1ae3447832fbc09b34625656d8cb3db0931Virustotal results 14.75%Heodo
2020-10-28Mes_59845344600594838.docdoc f8ce9f330d0b10e66d01f784d66c98d45fb6dc902c622d65ab15dbe965cf36bdn/aHeodo
2020-10-28ARC_84078877.docdoc 2ed9663048bfe1c969ee302588f17bbee321277d16204ebc6fcc3a626d03addbVirustotal results 28.57%Heodo
2020-10-28dat_03484748.docdoc 33c735ac2d43594d1fb25ef35adae90aef216e70c30065596ad24ffb5299de94Virustotal results 28.57%Heodo
2020-10-28List_LX6732451941FQ.docdoc 5acee595ee1bc75adea710f92e969aa5c62d0a2693b6dc8c678b2bff8a4a7e51n/aHeodo
2020-10-28Inf_FWV_100120_ZZX_102820.docdoc 0fdb302c3db79d7ed89244d7adf4c56d5cc9e4643c3e5bac39c3e82cff3834e7Virustotal results 29.03%Heodo
2020-10-28mes_QGB_100120_PUV_102820.docdoc 9ef4f6f51b375bbf59cc1d992a0be8455a3a9c3a026b28c4abe77a4f16805c50n/aHeodo
2020-10-28DAT_PO_10282020EX.docdoc 520ca27ad3a13618d306b397f83a91daf238997358520459895991c6285328e5Virustotal results 29.03%Heodo
2020-10-28Doc_M1DAC7CX8.docdoc f10a2b9719d2cd6b88deefff1b2c61c214527041c7097ccd16d96c80c577f58cn/aHeodo
2020-10-28File_PO_10282020EX.docdoc af7a1932766cf0a2a6bc07298751e49a47f81b2b7f255579bcc6d1a93f335af4n/aHeodo
2020-10-28arc_XE6848803568EW.docdoc ed9cfc1c33944c034d599ffe6b86bbb5629c22af3213560f5782e96dbc3d5fd5n/aHeodo
2020-10-28ARC_8F4GF93N52DG.docdoc e2f58ed91009de4f156ecdfb6fb04401ce82b2281242941e3a80fa9fe451cfcdn/aHeodo
2020-10-28Attachments_5394370464707759.docdoc 34eea5e4f2e92b636f9fcade14a7aec223d0ef960f9c0f6c749b2b806096aeb5n/aHeodo
2020-10-28FILE_28285960.docdoc 5dae469fdf99625a0b53d223a55b04fc4e77d3e660e1ab904e79071d5dc13c9bVirustotal results 28.57%Heodo
2020-10-28DOC_JB3161415650EU.docdoc 101fcc93c33f4a28332bd09291db3501b3d13ef433719cbf7750e9f6a73b88f2n/aHeodo
2020-10-28UNTITLED_UB3232900047RG.docdoc 9c509bf6c3b7824436cb299b2efffd013f3b0b156e9398a6975b71b50152cac3n/aHeodo