URLhaus Database

You are currently viewing the URLhaus database entry for http://www.esfagrup.com/wp-content/xj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761846
URL: http://www.esfagrup.com/wp-content/xj/
URL Status:Offline
Host: www.esfagrup.com
Date added:2020-10-28 17:47:04 UTC
Last online:2020-11-01 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 17:48:06 UTC to abuse{at}chronos[dot]com[dot]tr)
Takedown time:3 days, 23 hours, 13 minutes Bad (down since 2020-11-01 17:01:49 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30File_23755236.docdoc 1e363452c2a67d40f01390488a99f68ce6fab805b45eab93ee2db2469bf1b05fVirustotal results 22.22%Heodo
2020-10-30DOC_145719519300.docdoc 7419637ce4e2a7bf1c8503dd9f1878136c8bc0e38e88521f6500c7c717524be4Virustotal results 30.16%Heodo
2020-10-30Inf_EJ4156068845TM.docdoc 72cbfce2d1bb68f6583a651975d64056490779254d19bbf18636a754d88688c3Virustotal results 26.56%Heodo
2020-10-30list_QL3339056670AN.docdoc 12ef90a776bc1f4ae05962313e6b3711ec5211f8ba450527585d2da80c2d03b5Virustotal results 25.40%Heodo
2020-10-30REP_AGMUQV6I8IP48.docdoc 9210f9032280641d080e5abde6a49a3032839cec91f757f2469a4eeeb4080afcVirustotal results 26.56%Heodo
2020-10-30RXX_100120_YZL_103020.docdoc 84f8bd87a1f8207da3a4722b9eee322be498919fed6323fe33c0ce60ef7aadcfn/aHeodo
2020-10-30VD3081936069DH.docdoc 22a4eae8735782a3f12e3f7ee5b6d0839cd7c4a8b91dce6ce27e2414b2e5f817n/aHeodo
2020-10-30REP_SC3827378009LG.docdoc e37545649e9e7c9250af64a93a2fa3e37fd90ab7f9c16e96b4469290f309b52bn/aHeodo
2020-10-30ZE4194905828QX.docdoc 0df4e83145becd16b2074bb93563596b613e43856bbd653b98a316f5d92ab817n/aHeodo
2020-10-30FILE_GE0429774124HQ.docdoc b86e09a5bdebde57bd67e1fa11ddbd3381e5972d091fdc61b68e34226fabf084Virustotal results 23.81%Heodo
2020-10-30INF_69EHGD30MHHOG.docdoc f4983c5881da987bb4dcca9069e0134657dbd559cf50165c0f35c3f1c4595948n/aHeodo
2020-10-30arc_PO_10302020EX.docdoc 81f0a17e652679d94849f61bfd6679f35308909ce08fcbcfdfbf2d6c59d62ae0Virustotal results 41.67%Heodo
2020-10-30FILE_741869866278116472848957.docdoc 3619ca27723e87006b7061bd608e1e02d5087392ec513cfe82ecec069074fbd7n/aHeodo
2020-10-30rep_PO_10302020EX.docdoc f16118ebe3dbd05212ed3e350e3d509e02c403cacf34497532c50e1be09b7e16n/aHeodo
2020-10-30mes_TB7865866136YY.docdoc 6b88f01b98b04205fdeaca9ab7f387ea479efbb68e1e0a940c909d66e6ed092bn/aHeodo
2020-10-30mes_397597640566943.docdoc 7bfa1640c072951be3fb17704054b151541525eaa8a22606d94fc2d037a6a663n/aHeodo
2020-10-30Doc_KC0771613561FM.docdoc aa221230a7342817478b117f2ed838ceb8290bb367bea08770c362b14c2fdcbbVirustotal results 39.68%Heodo
2020-10-30328855046770.docdoc d938809af2f315ccb3059ebdb60f135d1a78267221ebe954f6ece48ad1c4851an/aHeodo
2020-10-30DAT_PO_10302020EX.docdoc 0b7f26dc76b83127cdf687f818e652f050a9b3726aa76bc30947f94e4e25ffd4Virustotal results 40.62%Heodo
2020-10-30Inf_BPL_100120_UNK_103020.docdoc 8f71742d1582c153a4011a49f8bf5ab9fe4129b6937832fba73d68bc0e95a438Virustotal results 35.94%Heodo
2020-10-3002017845.docdoc b2f80aa2efc9abdf137f78f830f2366b29e5bba74409138f8db1ed6163e25819Virustotal results 34.38%Heodo
2020-10-30File_52VQPAG.docdoc a51d194ff7cccab7defe2f64127934a4ff3699de37c60019b40dd62d631baf04n/aHeodo
2020-10-30Inf_CFY_100120_BNV_103020.docdoc 3faba02f0eb970ef25a2a874736e4f758dd3424cdba2637795ada41385024679Virustotal results 31.25%Heodo
2020-10-30INF_SII34L90WMJWQOW5.docdoc c0f5989eb238c0d187f0a5341698ac293ee524d1132278aaff5ab4144a4b91a2n/aHeodo
2020-10-30rep_PO_10302020EX.docdoc c2d7ed25c4c34f44dc293833d3ea302d281d24981385c437e411a50ede35e72bVirustotal results 30.16%Heodo
2020-10-30DOC_39202673.docdoc 785620ae5f3c011f3939803b6f7da0f097c81d008495ba545b805d7edf1fd707n/aHeodo
2020-10-30DOC_8HE95H7PF.docdoc 9cdf4102c45c7f549ee4e0290a07d4f7783c6371b1a8fe35a6f1f04d56cd6857n/aHeodo
2020-10-29Dat_AV7676458591QK.docdoc a692ebd8ffaf553afe6a7e4b21ec46977dfc073877399130d26bcb1aac0ec33en/aHeodo
2020-10-29DOC_305400352455809.docdoc bda57d2e85ef3df82eb86725562b0869718ad3497f2cf84ab96fd619933e6467Virustotal results 26.56%Heodo
2020-10-29REP_PO_10302020EX.docdoc f69a365c0b551ac35010e98b64364feedecc32dae4284fb4afe62ced4b5d17ebn/aHeodo
2020-10-29Arc_WI8258509169IQ.docdoc aa9631cdb98dbe55b81b029660a0589039561664b34f249207dc0d83e273a030Virustotal results 26.56%Heodo
2020-10-29Doc_72640959.docdoc 1fa65cbd054792ed8ce72d5729cb95a5810f1371e5b096b2f1a099416c193420Virustotal results 26.56%Heodo
2020-10-29FILE_6408145641.docdoc 53af27fd84005d52576f0314e3d69537d573c6b97a0c54d7fdd7f36ddb8ea38cVirustotal results 34.38%Heodo
2020-10-29Arc_94426355.docdoc 30afb0ba6cad7d0adca2d6200ecc891e79a8901808aa35a78dc2e03b6b1b3fean/aHeodo
2020-10-29FILE_PC98XD1.docdoc 18456f3c952a94d93064ab5e0fc948f5cf8c35d1615d18886c7ef84d7dc22a2aVirustotal results 34.38%Heodo
2020-10-29AICF_VKW_100120_XLE_102920.docdoc 970feee22d30c517c525e36b3327903c843552de7138215c5fec184444b56e19Virustotal results 34.92%Heodo
2020-10-29FILE_7981131768788390260682600.docdoc 1d0a436d11e82575e2d3159ad264e3a58bb3caa9f6638ee4b8a94a5373219628n/aHeodo
2020-10-29Attachment_HF0444099368FQ.docdoc 5f1e824d934b11f7e7a92d426e5083d30f51fee6471908f3a6c0a065d46d752bVirustotal results 30.16%Heodo
2020-10-29E_STE_100120_OQC_102920.docdoc 633a628e9a364cb3bbd93ebdce10e5f23fb15370a584efb4fcecf4549c3b975dVirustotal results 31.25%Heodo
2020-10-29Untitled_JIS_100120_GBT_102920.docdoc 16d27526d0453d93110c60d19d8a4680f2ae783858a4ec2093a235fcb819556dn/a Heodo
2020-10-29dat_NVFGIZDQE5TG2D0.docdoc 4a2b5b076857ff6ff381d978c57a1820e0117128142cfc3b3e548b7902b98431Virustotal results 31.25%Heodo
2020-10-29list_S3R4UYVC.docdoc a5d70f05d98720bd04c84440dd37092752ad5412805815ee92472cfc5c2aa1b7Virustotal results 32.81%Heodo
2020-10-29KDM_57707988.docdoc 1cfbaf38e833a8dcab12a6f7a0c42e5b5033bc4f188f022607c0e3853f92a6eeVirustotal results 31.15%Heodo
2020-10-29rep_7707238530952994958.docdoc 5e49a64852901bd8057faf79a29c4014763a93bd4f8a0c448a58ab101da4fac7Virustotal results 29.69%Heodo
2020-10-29PO_10292020EX.docdoc e6a7e6b13c6bf9156c51ce46213a68a27ed5da4c01903cc86465ac63c073fd7dVirustotal results 26.98%Heodo
2020-10-29Untitled_TB3381298293DK.docdoc 5a586d16a655c4b142b0d419a75c12e385b6f96a2eb46e966663b8b820556f3an/aHeodo
2020-10-29FILE_312156594712166021320659.docdoc 541fe3cb96d86e7e7acac38913e1f12a0006bb4e07269700b8878279ecb8df5cVirustotal results 25.00%Heodo
2020-10-29ARC_19910749.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29Attachment_980969600193779.docdoc 5edf42ab917e99566d6904b93308695efb66e834390a35fcdc05d184cbca6ef8Virustotal results 28.12%Heodo
2020-10-29USG_100120_RBY_102920.docdoc 13b5e4daa9de72cca849daddaf829c4a3c019c11cebbc6e0c7fb67481fbc9b97Virustotal results 30.65%Heodo
2020-10-29Dat_PO_10292020EX.docdoc cd3fe863b543b7cff0caa09fe57459ed428b05158a34dd748438f0f7a671fabbVirustotal results 27.87%Heodo
2020-10-29Z_BA1325253503ZL.docdoc 4578d3920daacf96ae730e547892639558d1ae71b1820d402dbcbfc3ebfcc816Virustotal results 26.56%Heodo
2020-10-29ARC_25123972.docdoc 405fadefb4061d6af8c5857c120bb843c94b11edd508facc87ddc8c95c45081an/aHeodo
2020-10-29File_TTE_100120_RUH_102920.docdoc 4a66929263cee2a8c48e07dbf1fb484199f5d51da94f42703fff35d3213235d9Virustotal results 24.59%Heodo
2020-10-29doc_88989769.docdoc 1909a3514994e354da8e5abdfbb3b73173a1a6782a739ebdbfbacf098abf0fb2Virustotal results 20.97%Heodo
2020-10-29MT8785465032RN.docdoc 12c570f649005ea1ae77c36167843e3e87252075b68b652c5f05b0d8e54b2ad0Virustotal results 20.31%Heodo
2020-10-29DAT_HZ5BGCD.docdoc 8b4afb8076a68f93b44032c82700252f8971b853903b31fd0eaf50671f7c3cd7Virustotal results 20.31%Heodo
2020-10-29Inf_ECFKX24VNG61.docdoc 4a364de81c8e1064d68390dd954375aeadf021b771249cea59881e7e0fcc3156n/aHeodo
2020-10-29List_PO_10292020EX.docdoc 0cacb466a5cd54765f2b551a75b8b0880cd991d16fd662402d00efc578060da7Virustotal results 20.31%Heodo
2020-10-29File_PO_10292020EX.docdoc 2427ee3cc0798fcee02c718a1fb58d735d9cf3b0ebd9bb10c14cb9326bb5e489Virustotal results 20.31%Heodo
2020-10-29DOC_KJIC8KP6QL2IP86.docdoc 371a442d56b47bd24ec601a710beb116a75f09be269d0a2e18b29d6fe0927bc1n/aHeodo
2020-10-29SHY_100120_DEW_102920.docdoc 5a00d4a9d8e50c06f30007460af1dc4f73950dff8ef4d1966ec4098c16712bf0Virustotal results 42.86%Heodo
2020-10-29File_67356149.docdoc 92b5a1128e03487da18589470f8c7fdaeb929ce4b5cdbdafef40a4060035c8abVirustotal results 41.94%Heodo
2020-10-29AY5610830237MJ.docdoc 6cff316da0b26621e5b1fc3d5a85c6931a68a90fde20acf702195a175fb4ce44n/aHeodo
2020-10-29CK4793432118AA.docdoc 48f5efeee13fcdbe837223ddd4c1de97dd87be397e6f99bb95ebfd19af5aaf86n/aHeodo
2020-10-29INF_A6VTLW22W.docdoc 5b38f86c2e96fa7a30fc424bf52cc9b26e6fe82c65cec38c00392e135c703b8fVirustotal results 41.94%Heodo
2020-10-29doc_95844364.docdoc 5d0b92f454b00f1679bc6b090749bf784d1fa854eac55bf453eec083b6aa2076n/aHeodo
2020-10-29inf_FLJ_100120_KIF_102920.docdoc 4a64cdcef15cb3314d81486a5c6c1fc590e6579da756365b73c08c8adae77b95n/aHeodo
2020-10-29List_06610865.docdoc e3a96d2e3adca1fc3dfea0ac14af9b1d4cec3a20d9d7c6874edf1c6fec60d90bVirustotal results 38.10%Heodo
2020-10-29Rep_4QD4MIG4Q9TNJ9C.docdoc 67bf175be626fe3ee59387c2c162c6fe009315964e0d4de581dc1a94daab51c5Virustotal results 37.10%Heodo
2020-10-29rep_PO_10292020EX.docdoc 40e1e0d4ba67280ae17c0050feb66bf13f27e271efd4fc91413f8553dcf12a09n/aHeodo
2020-10-29File_10284723.docdoc 2ce6ab8ee89411f1463ed6831f078e930f121aaa93880728734efa7d25503623n/aHeodo
2020-10-29I_83004456.docdoc 2ddd69d637bb813f74ae33be71c1cf20fd61be5a25f0bd5e69c296136a8d1813Virustotal results 39.34%Heodo
2020-10-29FILE_1516903363702896385638.docdoc c353f3d728d9ff052a3ee47d7dd1c5e8bcd8813238a8e20f2f2d0a97fe5bd8e0n/aHeodo
2020-10-29List_TZ6348994681IX.docdoc 17d6d17702d158eda616b2096600e47fe0808914ae353ec5009763a5de5fffe7Virustotal results 35.48%Heodo
2020-10-29list_PO_10292020EX.docdoc ab7a59b346e75d68ff9a689f85a0d2a96833a3048478fab68af1e8f1bd4d5905Virustotal results 36.51%Heodo
2020-10-28arc_4DLB217OJHB7A2.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28DP_DI4194863822PZ.docdoc b693171616c84c6e6bf6f7a486ac2efef18cab45a608593d95def463549f2f74Virustotal results 25.40%Heodo
2020-10-28Attachments_ZM0G2MHZ6DKQO.docdoc f13e48098e4dc4a27534f29ee41bafc7943a5a1c14ad493e2a5e955e6c2c1148Virustotal results 25.40%Heodo
2020-10-28Mes_YM1503164155VO.docdoc 92bad3b1416d1b7f759e20c2214cbfe1f31b2f334d818e67dd917cde8a72befcVirustotal results 24.19%Heodo
2020-10-28Attachments_XF1850002573MS.docdoc 304314cb220d129f1eb18cc72da395146c2515aacaf0b81353667ddbf78413bcn/aHeodo
2020-10-28mes_65845024.docdoc 11974ec5ce543646a57980f46943cb2a955f3d5a1e4732f3afdfd141df1cb76fn/aHeodo
2020-10-28List_4466183148451838547.docdoc eae43aeb02650178d0fd02ed1c824f36d89c2a2950399621c4a7c29ecb8d7e73n/aHeodo
2020-10-2804962458178770292.docdoc ad112b9ed4b1078a7142b24121c402ec49a036e33bf0e514f8bdc5b720c216deVirustotal results 17.74%Heodo
2020-10-28dat_NNX1DSCA8H87B2L5.docdoc 87591b36ad962f6009043a5af2f6ab3d515e7fd18b199f2da448d2eeabe8e83cVirustotal results 17.46%Heodo
2020-10-28ARC_0943353929136850758343.docdoc d91ac6b289bd863b217db0a852a8283c9964ffe543f3cfccd63951b76e7761cdn/aHeodo
2020-10-28list_BP1YUUCZHQOTN.docdoc 78344d3e894155b6b6fa65119c449406b1ad08900e1cb58f68d7efba27947084n/aHeodo
2020-10-28File_5U7QMD09R6TR.docdoc 7d38c4d98d05cd3a7a0fc6898c9d86ef1c29cd8dcfa3403d0222ff508843a325n/aHeodo