URLhaus Database

You are currently viewing the URLhaus database entry for http://escort-planet.xyz/wp-includes/LxY80wFXhC15PKssNhAQhWKztra9feazZpZr3IcnndJBslQjBGkjoqCq4laK61/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761046
URL: http://escort-planet.xyz/wp-includes/LxY80wFXhC15PKssNhAQhWKztra9feazZpZr3IcnndJBslQjBGkjoqCq4laK61/
URL Status:Offline
Host: escort-planet.xyz
Date added:2020-10-28 13:34:18 UTC
Last online:2020-10-31 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 13:36:58 UTC to abuse{at}iws[dot]co)
Takedown time:2 days, 12 hours, 50 minutes Poor (down since 2020-10-31 02:27:41 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28doc_47456062.docdoc d91ac6b289bd863b217db0a852a8283c9964ffe543f3cfccd63951b76e7761cdn/aHeodo
2020-10-28K_23002895856714936.docdoc 93d882200983e8ea91da547916ade52e52c5f684c19434eb8e3312b4d4251bb1Virustotal results 17.46%Heodo
2020-10-28FILE_82482783.docdoc 6c0cb9fa14216686237503039df79f6ee1a2766d5878c2e3ab77c9ace4204c11n/aHeodo
2020-10-28Inf_683837414362981500396911.docdoc 6ce35993d504db2336d3804f3ed1ec36aabe10a3386bd30aedfc0f4c149ef58bn/aHeodo
2020-10-28D_27843765.docdoc f3a50571ec16f6ce94dfc39a4079b0bfc70192152166c65da1f33e8e046cb06an/aHeodo
2020-10-28Inf_80441939.docdoc aa825d666a2394dad05c014830cd132ecdbabfe1dcfd7e7eba18ed43bda6de33Virustotal results 17.46%Heodo
2020-10-28List_7095702377010836070.docdoc 7eeb30a34016ac7c6d48178f44b12c48df17acb131f0a96847d1cd67c464ce30n/aHeodo
2020-10-28NZT_JX7688100307VT.docdoc 302684a1df1b3b6bcf6995798581972d23b71888983b326ff3eed9bbcaf1c56bVirustotal results 23.81%Heodo
2020-10-28DAT_NUF_100120_PEV_102820.docdoc a4faa1f62f9a2d486a3e4e010117727c063ead8fc4aa228bea32553f85b95353n/aHeodo
2020-10-28List_JS2615077721FV.docdoc 95dbd21a4a3f7bfb45ed46713d99b7881129368a675677e970e647b22cde6d05n/aHeodo
2020-10-2845818067.docdoc 245da199877ac955b9c2640666afb19d13d640da90766a000f6fc8b2c909582en/aHeodo
2020-10-28rep_JXB0TMQC8.docdoc dcbe02f1aa0077b9eb58a4e8a30c9c220fc240162ffcb1bb73376e967d6e7b62Virustotal results 17.74%Heodo
2020-10-28FILE_NWG_100120_HVO_102820.docdoc f976e3edc1892c2009a8000edb80c5329f8ca920af116372b2a274488ddba5e8Virustotal results 17.74%Heodo
2020-10-28INF_6567379543.docdoc a2a1fb0e34755eda063fd82d7fe452eb979f87b8cf484cd8fa59a45df5adb29dVirustotal results 17.46%Heodo
2020-10-28REP_ZD7739187109OU.docdoc 9148521d1b0af5640383d1905b6cae8657ee59b51e04dc0d18624a10234ad20cVirustotal results 17.74%Heodo