URLhaus Database

You are currently viewing the URLhaus database entry for https://eflowersncakes.com/wp-includes/statement/336702300490882/33thiivlt-0847855/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:760800
URL: https://eflowersncakes.com/wp-includes/statement/336702300490882/33thiivlt-0847855/
URL Status:Offline
Host: eflowersncakes.com
Date added:2020-10-28 12:22:12 UTC
Last online:2020-10-28 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 12:24:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 46 minutes Good (down since 2020-10-28 14:10:57 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28Inv. 00888907090.docdoc 22501e141b52a24309578121d2ba63249fc21c36c6b4dbfd0f22635c0a0aae35Virustotal results 17.46% Heodo
2020-10-28Invoice #229715977.docdoc d4d88bb7b289fc8fe85835f356c30440662efd3f2a033d4b99bda2f234647243Virustotal results 17.46% Heodo
2020-10-28Invoice.docdoc ffc6e2d43f0cf1523d9c89157520513c0715dc35bc8dafae62bf984587dbaf90Virustotal results 18.03% Heodo
2020-10-28C-100120 WVZE-102820.docdoc 446e21090ce1bf05d7b94165ffc64b219bdaaa820ef729fafc816d0e7d602e0dVirustotal results 17.46% Heodo
2020-10-28invoices 02803 & 82135.docdoc 7d81e94588ab00cf8ba72e199de29d4cdedc472e3285d5679c00c12d0ea2e109n/a Heodo