URLhaus Database

You are currently viewing the URLhaus database entry for https://santanewsdesk.co.uk/wp-includes/LLC/itGcqA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761366
URL: https://santanewsdesk.co.uk/wp-includes/LLC/itGcqA/
URL Status:Offline
Host: santanewsdesk.co.uk
Date added:2020-10-28 15:18:04 UTC
Last online:2020-10-29 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 15:18:15 UTC to abuse{at}ovh[dot]net)
Takedown time:16 hours, 28 minutes Good (down since 2020-10-29 07:46:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29invoice.docdoc 8744e383bf013444ed1f687f385d558ee1c4e2a153cdfe224250a02fd1eada2eVirustotal results 19.05% Heodo
2020-10-29MSO-100120 XMBQ-102920.docdoc 995bfae8132d4637a2d2e72e1f40a22043e19520c5c45039b2f257e9430f3cd5Virustotal results 19.05% Heodo
2020-10-28October Invoice.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-28October invoice.docdoc 86864a725202d28c0714960226d68417581cd2a83ead755ce236d48a2884d1cdVirustotal results 28.57% Heodo
2020-10-28001602563.docdoc 09ccc81a0d3dd19981c937faf388f0fe7117243b355255e387dce0dfb43f7769Virustotal results 26.98% Heodo
2020-10-28QH079 invoicing.docdoc 0c5643d4a7b85e177802b1eae495641a49631f1e3016455f0c7ba45709d27026Virustotal results 25.40% Heodo
2020-10-28Inv. 0067680117806.docdoc ab327e3be9ef1ce4781f725c995feb6a13f6eaf1d1c31e894048e5be6b4e24aaVirustotal results 23.81% Heodo
2020-10-28R02 invoicing.docdoc 5177894154a2ad0d67c6ea62534a27cdc18b7cfe9c73c8ec6071d72fb8c198a2Virustotal results 22.58% Heodo
2020-10-28invoice #527789.docdoc 77373248ec2c394eb9cfd85b94e561cdd8ed66646be0298961d65b24a97305e5n/a Heodo
2020-10-28October Invoice.docdoc 3b31e20a19f924917aea1e08d62b46e74ecf47777ab81e3843195449c1ceb80dVirustotal results 20.97% Heodo
2020-10-28FHF-100120 PMII-102820.docdoc 0402eac76e97d2bc47ed688412a18594674b7e981d4307bbe0b8491d8ba0268cn/a Heodo
2020-10-28P-100120 NIKW-102820.docdoc 87ba8d2cd453427750317da53541442b62760f1757073b1b3a5fe0cbcc69ec14n/a Heodo
2020-10-28Form.docdoc 5abc253a05c73d034f05ece8f508bb3ef3076045e88ef8aafe74cffc6b20edaan/a Heodo
2020-10-28Inv. 92720.docdoc fadcbe7aa3d7b823b03d2627cf8a05b229e0f6c7518a71b9c4a106155b04df3cVirustotal results 17.46% Heodo
2020-10-28Form - Oct 28, 2020.docdoc c6d94cabee4abe9dc14f1ccdfcec3f631453b9e19046806554808e77ddda2cf1Virustotal results 17.46%Heodo
2020-10-28Form.docdoc 24fc98fb4608b0e6216b4bf1a61772268c565b9b40cf66c95011f32d64591333Virustotal results 17.74% Heodo
2020-10-28Copy invoice #00450.docdoc 448eabf56cc654711f7a3a6005be397a5aeda5ba6f329742da01cf7d31712931n/a Heodo
2020-10-28Electronic form.docdoc 4389a855fc217bc2a9ed342735f09fd3d8d148ff29272d80c2efd4a03a9806e1n/a Heodo
2020-10-2802074904423.docdoc 7cd5248f6eed960168d2898ffde985d947702c9dc04b50d021161ffbed128e95Virustotal results 18.03% Heodo
2020-10-2803860395.docdoc 731fa6c4397bb175f81758e00d5dae42e084bf6508dd0e6e7c861c25cfb5f2dbn/a Heodo
2020-10-2803692557123.docdoc 0031e60e9810b98f42bf12765fba57f45b0b41b41dff5216823e74ec607fcd89n/a Heodo
2020-10-28October Invoice.docdoc 1803944ee4f9bc9077c04710e033b33e5ce91263d2b9f5409f742caee5f45fcen/a Heodo
2020-10-28Payment status.docdoc 00be80b011b00e2de85e342852402bd4fb7b9bd28a03d3631202c6ab79baf9cfVirustotal results 17.46% Heodo
2020-10-28Inv. 0050864.docdoc f104662c93957cb9de8b8b5db529dcd6dc40bd62d362d375d4894efba21b8c94Virustotal results 17.24% Heodo