URLhaus Database

You are currently viewing the URLhaus database entry for http://studiowellness.no/cgi-bin/browse/9292327853871/ps7miv8fyya-0958/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761362
URL: http://studiowellness.no/cgi-bin/browse/9292327853871/ps7miv8fyya-0958/
URL Status:Offline
Host: studiowellness.no
Date added:2020-10-28 15:18:03 UTC
Last online:2020-10-29 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 15:18:22 UTC to abuse{at}servetheworld[dot]net)
Takedown time:18 hours, 21 minutes Good (down since 2020-10-29 09:39:37 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2909207136.docdoc df634084d9cb08a06d2e82f00cc3fef1f64efc21da9ebd08ba86b684ee237863Virustotal results 19.05% Heodo
2020-10-29C1861773939KQ.docdoc 8b689836a9b1034619fdff9ed1e672a6c18d09887f73cfa9e3243ae5071badbfn/a Heodo
2020-10-29Form - Oct 29, 2020.docdoc b85f19719ce551a42d5b94b2a3f1594b969ff829e294ea522e4c42ea338f466fn/a Heodo
2020-10-29PO# 10292020.docdoc ca414fa964639ee79c68a68f9bf79c027f92b5736df476ecc2fdbe4def2e8d69Virustotal results 19.05% Heodo
2020-10-29Inv_82907.docdoc c8e574a25c67cc59d9e1eab78d4591aa32efdd56dc3a64d5e02928d42fe1e732Virustotal results 19.67% Heodo
2020-10-29CF1997492335EU.docdoc 2dc19d1576e1d7e5d43a3e0cf6ed690d3b66634515389ca782f0af0198069e65Virustotal results 19.05% Heodo
2020-10-28Invoice.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-28form.docdoc c6446a1b82e57959baa73f792dba78e1b5374bf16e60ae5bacdd7a1981c45f9bVirustotal results 27.42% Heodo
2020-10-28C-100120 YXSK-102920.docdoc 6398e25e380cf00aa433acf528e8f0245fd02007338aa75df4deb5bd9eeefbbbVirustotal results 26.98% Heodo
2020-10-28invoice #313198.docdoc 6c3c1280087fe50fd411676b26ffd9bf41044300aeef5d27ed6322cf365fcd99Virustotal results 26.23% Heodo
2020-10-28invoice #55978.docdoc ccdb2c5ed40ad6227647ac04e1d3d1cb499a0d67ae9dc428c3ef6b275f786a8cVirustotal results 23.81% Heodo
2020-10-28October Invoice.docdoc 19f5c63fa8696a0eaab016bdd4d8d1bcfb5dd7f07d1da25caabaaedf0088dc23Virustotal results 23.81% Heodo
2020-10-28Inv. 02927075397.docdoc 1ffb519f7ee20c735692e941193543d406a780fa0756200654c9d442c5166fd4Virustotal results 22.58% Heodo
2020-10-28Payment status.docdoc 6c5d2dceb77aca3c35f72874bcb483c53950fd5f5aeb9dd9a66fed7341d3cd3aVirustotal results 20.63% Heodo
2020-10-28INV #4006031 FOR PO #0850274.docdoc e69175f1d0fc57715610220f59992ae3a56ac12d27917162e4626cd0ef2bfc30n/a Heodo
2020-10-28October Invoice.docdoc a489db63b3d5de10623868c1348ded5fa888b398c6c9ecd199dc5c1fe55ac9d9Virustotal results 18.03% Heodo
2020-10-28October invoice.docdoc 6b556db13a6bc97a4628816c0d73e375e246ba9dcf0767a7ff38910b06976de6Virustotal results 18.03% Heodo
2020-10-28INV #0071003 FOR PO #09076499935.docdoc 1f83279e11907f0f3b4b2164f90fc56c5043732bb07681b9c8827bc91f3d7181Virustotal results 17.86% Heodo
2020-10-28A8191306389CE.docdoc c6d94cabee4abe9dc14f1ccdfcec3f631453b9e19046806554808e77ddda2cf1Virustotal results 17.46%Heodo
2020-10-28form.docdoc 448eabf56cc654711f7a3a6005be397a5aeda5ba6f329742da01cf7d31712931n/a Heodo
2020-10-28OU094 invoicing.docdoc 08d832a1ff20d74ba37553d0ac28f94bc54d7463e392873c34faf6bb44d47afdVirustotal results 17.74% Heodo
2020-10-28Invoice 26408.docdoc 7cd5248f6eed960168d2898ffde985d947702c9dc04b50d021161ffbed128e95Virustotal results 17.46% Heodo
2020-10-28PO# 10282020.docdoc 268438b641db6d86d82847ad12e55ab098615a5b5328d37db2b6123a4e08a822Virustotal results 17.74% Heodo
2020-10-28Invoice.docdoc 0031e60e9810b98f42bf12765fba57f45b0b41b41dff5216823e74ec607fcd89n/a Heodo
2020-10-28INV_062859.docdoc 5a9c040e67efe0446aaaeff9b0dacd2f668516484cf5487449360cd489ce268an/a Heodo
2020-10-28Copy invoice #905503.docdoc 9819d665344dae10323a62049a4b5193c88afbdd1792f6d8ad80b7df403b6c73n/a Heodo
2020-10-28October invoice.docdoc f104662c93957cb9de8b8b5db529dcd6dc40bd62d362d375d4894efba21b8c94Virustotal results 17.24% Heodo