URLhaus Database

You are currently viewing the URLhaus database entry for http://santanewsdesk.co.uk/wp-includes/LLC/itGcqA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761818
URL: http://santanewsdesk.co.uk/wp-includes/LLC/itGcqA/
URL Status:Offline
Host: santanewsdesk.co.uk
Date added:2020-10-28 17:37:03 UTC
Last online:2020-10-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 17:38:14 UTC to abuse{at}ovh[dot]net)
Takedown time:14 hours, 22 minutes Good (down since 2020-10-29 08:00:58 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29invoice.docdoc 8744e383bf013444ed1f687f385d558ee1c4e2a153cdfe224250a02fd1eada2eVirustotal results 19.05% Heodo
2020-10-29MSO-100120 XMBQ-102920.docdoc 995bfae8132d4637a2d2e72e1f40a22043e19520c5c45039b2f257e9430f3cd5Virustotal results 19.05% Heodo
2020-10-28NE7967785299UF.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-28Invoice 051281.docdoc 767adf40099224255f150c5dab97873a98b3aa9a0516b068d3412b1302ab2352Virustotal results 26.98% Heodo
2020-10-28Inv_4916.docdoc 6398e25e380cf00aa433acf528e8f0245fd02007338aa75df4deb5bd9eeefbbbVirustotal results 26.98% Heodo
2020-10-28QH079 invoicing.docdoc 0c5643d4a7b85e177802b1eae495641a49631f1e3016455f0c7ba45709d27026Virustotal results 25.40% Heodo
2020-10-280822209.docdoc 47777481ca315073bee9224d1ef95b64203170ca33c9295b1519e18a004ea2a1n/a Heodo
2020-10-28R02 invoicing.docdoc 5177894154a2ad0d67c6ea62534a27cdc18b7cfe9c73c8ec6071d72fb8c198a2Virustotal results 22.58% Heodo
2020-10-28Payment.docdoc 2a87f25fe351249b33ffc8d24f6310b9d8e1e3907a6b53b06e324566027dcae0Virustotal results 22.22% Heodo
2020-10-28Invoice 0015705.docdoc 6c5d2dceb77aca3c35f72874bcb483c53950fd5f5aeb9dd9a66fed7341d3cd3aVirustotal results 20.63% Heodo
2020-10-28Electronic form.docdoc 550bb4afeb580c5ca1bef73de9f4548610129a2f407d1375aa69b29c109ee9bbn/a Heodo
2020-10-28000333589.docdoc 661694d6fc62c1af16ddbe2db10c54b471f5acb387cde760666a6a672635f16dVirustotal results 17.46% Heodo
2020-10-28Copy invoice #370662.docdoc 22ccc563e61d8e3c9936d06fb1d86632f7544d213ae91216e74ad8bef00b45c3Virustotal results 17.46% Heodo
2020-10-28034543.docdoc 3e784298291a432cc1c053b0a50d2245977718a7f16e344559d0952260c96049n/a Heodo
2020-10-28form.docdoc f7f94de76d23a7933abb8bd20b8fe7ac8200c6cc8d3b837dcb1686368c86a718Virustotal results 17.74%Heodo
2020-10-28INV #008525 FOR PO #0052669712.docdoc cdcc9f999263c672f77e84b1b08028da0a298140b3e9e300baaa8a6b69c84e99Virustotal results 17.46% Heodo
2020-10-28Form - Oct 28, 2020.docdoc 3732182a2ad2854b3f9ae9a1eeaaec7d53eb43bbc485318ae0a2f573a0159b0cn/a Heodo
2020-10-28Inv. 0368659.docdoc 0c858a0a134a998400efac616b99178e0b542e1229d9260362b329d56ab10b58n/a Heodo