URLhaus Database

You are currently viewing the URLhaus database entry for https://studiowellness.no/cgi-bin/browse/9292327853871/ps7miv8fyya-0958/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:760718
URL: https://studiowellness.no/cgi-bin/browse/9292327853871/ps7miv8fyya-0958/
URL Status:Offline
Host: studiowellness.no
Date added:2020-10-28 12:03:04 UTC
Last online:2020-10-29 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 12:04:04 UTC to abuse{at}servetheworld[dot]net)
Takedown time:21 hours, 33 minutes Good (down since 2020-10-29 09:38:01 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Copy invoice #29815.docdoc e2696d2bb597618293e2b3d1d12cfae72aa77c2e3c8f74853f6e77aec8d029edVirustotal results 19.05% Heodo
2020-10-29Electronic form.docdoc 4d064ffae939066e710a994df38ada3de500bfca3fa58d21f40312450b69b3dfVirustotal results 20.63% Heodo
2020-10-29invoice #595417.docdoc 7d28b073c2f12161c6a82211121eb15177b53e23703874c27405e5df52f6e34fVirustotal results 17.74% Heodo
2020-10-29Electronic form.docdoc ca414fa964639ee79c68a68f9bf79c027f92b5736df476ecc2fdbe4def2e8d69n/a Heodo
2020-10-29invoice.docdoc 97eed62203104c59dd3e147c5bef2d4b5d4657667aa4ab49b60b51372d91dcdeVirustotal results 19.05% Heodo
2020-10-29invoices 6421 & 8409.docdoc 8744e383bf013444ed1f687f385d558ee1c4e2a153cdfe224250a02fd1eada2eVirustotal results 19.05% Heodo
2020-10-29Electronic form.docdoc 75c855710955e1f033276db4cbc83c798d238d4ca5cbf2e0fb9968d3944f0e79n/a Heodo
2020-10-28Invoice.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-28invoices 49006 & 52528.docdoc f839b00e54aa7b0d68e3f3d7e7c12965d9d64153cd37d0600c4297542385eec4Virustotal results 26.98% Heodo
2020-10-28C-100120 YXSK-102920.docdoc 6398e25e380cf00aa433acf528e8f0245fd02007338aa75df4deb5bd9eeefbbbVirustotal results 26.98% Heodo
2020-10-28form.docdoc 6904c547286eda2ac977185bbe3705732db4ca6eebc33e340e9ee9540909d671Virustotal results 25.81% Heodo
2020-10-28October invoice.docdoc 92ae5315a4de0857a9f23fa0d4ef298bf2e87573ec75de5c05c6b82c0ca67155Virustotal results 25.40% Heodo
2020-10-28Invoice 0011194.docdoc 651bf3fad674c19a145b70179dc88dcc06a5afee9923b348c400155e1f6b14a5n/a Heodo
2020-10-28Inv_367997.docdoc 4adceae76870fb4ce7b6f62e11956b29535594f3b204e657f08f03c44f87e976Virustotal results 23.81% Heodo
2020-10-28Invoice #4240577.docdoc 77373248ec2c394eb9cfd85b94e561cdd8ed66646be0298961d65b24a97305e5Virustotal results 22.22% Heodo
2020-10-28INV_91650.docdoc a9ae4ffeff58b0aff2408b43bf5572e071f6d1d77ea83e1331981c2154e105c1Virustotal results 20.63% Heodo
2020-10-28INV #4006031 FOR PO #0850274.docdoc e69175f1d0fc57715610220f59992ae3a56ac12d27917162e4626cd0ef2bfc30n/a Heodo
2020-10-28October Invoice.docdoc a489db63b3d5de10623868c1348ded5fa888b398c6c9ecd199dc5c1fe55ac9d9Virustotal results 17.46% Heodo
2020-10-28October invoice.docdoc d1f0145ea0d4e036edd208387b5c7c012b0eec91562b6f210853152462b2ff63Virustotal results 17.74% Heodo
2020-10-28INV #0071003 FOR PO #09076499935.docdoc 1f83279e11907f0f3b4b2164f90fc56c5043732bb07681b9c8827bc91f3d7181Virustotal results 17.86% Heodo
2020-10-28Inv_3398.docdoc f7f94de76d23a7933abb8bd20b8fe7ac8200c6cc8d3b837dcb1686368c86a718n/aHeodo
2020-10-28Copy invoice #27268.docdoc 24fc98fb4608b0e6216b4bf1a61772268c565b9b40cf66c95011f32d64591333n/a Heodo
2020-10-28OU094 invoicing.docdoc 08d832a1ff20d74ba37553d0ac28f94bc54d7463e392873c34faf6bb44d47afdVirustotal results 17.74% Heodo
2020-10-28invoices 77322 & 8211.docdoc b9bb095da1e8ad66589f36b496ee1e2e924f04f73374e3b76f630fbf6c9f573en/a Heodo
2020-10-28invoice.docdoc 2d02f7d64430a41c50eaaed46dce33dcc544dc0d4904fd4561e8ebd851447952Virustotal results 18.03% Heodo
2020-10-28Invoice.docdoc 0031e60e9810b98f42bf12765fba57f45b0b41b41dff5216823e74ec607fcd89Virustotal results 17.74% Heodo
2020-10-28PO# 10282020.docdoc 182920d9a5f644d48dfaf4ff4b3b45ba19446012b6d7a2150f6d53b5c8e773ban/a Heodo
2020-10-28Copy invoice #905503.docdoc 9819d665344dae10323a62049a4b5193c88afbdd1792f6d8ad80b7df403b6c73Virustotal results 17.46% Heodo
2020-10-28form.docdoc 19aaa433ecca6fd07745038e78b223ac4492123a79f15b2e209298466f35cbe8Virustotal results 17.46% Heodo
2020-10-28Invoice.docdoc 8d628c60fb8a3dcaf40f3ad332715bef982f7bb08b77223501bd663299bb719dVirustotal results 23.81% Heodo
2020-10-28Payment.docdoc eb7342e956ea7f0a234e89063bf36cbdb9e2bf4d6478141379a0eaf2efaf711fVirustotal results 19.05% Heodo
2020-10-28BUI-100120 BEOU-102820.docdoc 7e8996f6c2bb380cdd8ee5149be9a14a338720b1db9e4ba106e9e039361ecbd8Virustotal results 19.05% Heodo
2020-10-28October Invoice.docdoc 7b55e5dcf03999a440acbe690dddf943d03bd37fbfc7892d196708992044efdfn/a Heodo
2020-10-28October invoice.docdoc 947ad40b782030b5eb73b4e4957c0f95d236c1414fd8d72520a422461cd211a8n/a Heodo
2020-10-28Invoice.docdoc 75818f0e25504a1fefdbe136826c12c354d25c43b184750ebd110063cb7cb444Virustotal results 18.03% Heodo
2020-10-28PO# 10282020.docdoc 7d18ce30a5e5559dba5b330602ce6d3aed362781f7764ae4d0a152d568a5f45aVirustotal results 17.46% Heodo
2020-10-28form.docdoc 52cffa7b6a722c32c17560a5d71ac09a91bdcd9cd36ab8b9913c92063aa109c5Virustotal results 17.74% Heodo
2020-10-2808099983.docdoc 55555a045c8b3878af56c302aac860598d4216873247ce3332c110e236b11b69n/a Heodo
2020-10-28Payment.docdoc c282e1420304ccfb2f98dcf04512500bd899f86dadcdaa93f65639db1daa83a4Virustotal results 17.74% Heodo