URLhaus Database

You are currently viewing the URLhaus database entry for http://esfagrup.com/wp-content/xj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762972
URL: http://esfagrup.com/wp-content/xj/
URL Status:Offline
Host: esfagrup.com
Date added:2020-10-29 00:12:12 UTC
Last online:2020-11-02 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 00:14:18 UTC to abuse{at}chronos[dot]com[dot]tr)
Takedown time:4 days, 21 hours, 56 minutes Bad (down since 2020-11-02 22:10:27 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30File_23755236.docdoc 1e363452c2a67d40f01390488a99f68ce6fab805b45eab93ee2db2469bf1b05fVirustotal results 22.22%Heodo
2020-10-309737339278700949015657910.docdoc c0e896c6e7521d6431ca692ef69c30c605ab7e599336d9c027721e573d1b2161Virustotal results 30.16%Heodo
2020-10-30FILE_32184117.docdoc c21fd3f4bfb11db1fc709bca4079eb7f97b6001e5695a430566b61e5e630053dVirustotal results 29.69%Heodo
2020-10-30Inf_EJ4156068845TM.docdoc 72cbfce2d1bb68f6583a651975d64056490779254d19bbf18636a754d88688c3Virustotal results 26.98%Heodo
2020-10-30Untitled_32619259.docdoc 0406910d3c48dbd18d57086dcab9b4f73a8081dae9fac3010f0ae90b73c7c34fn/aHeodo
2020-10-3040999063100824672347.docdoc 60e4646ea5fbe72e1daf6f3d015b37205898569b303dcfc791e0d02a754c9bf1Virustotal results 26.56%Heodo
2020-10-30RXX_100120_YZL_103020.docdoc 84f8bd87a1f8207da3a4722b9eee322be498919fed6323fe33c0ce60ef7aadcfn/aHeodo
2020-10-30VD3081936069DH.docdoc 22a4eae8735782a3f12e3f7ee5b6d0839cd7c4a8b91dce6ce27e2414b2e5f817Virustotal results 23.81%Heodo
2020-10-30inf_95474469.docdoc 917a6b067e825cb71b0d60b4e428f283cdbf100bcec01e467503d18077125c4cn/aHeodo
2020-10-30REP_SC3827378009LG.docdoc e37545649e9e7c9250af64a93a2fa3e37fd90ab7f9c16e96b4469290f309b52bn/aHeodo
2020-10-30DOC_968698475166439546597702.docdoc 4f6d5190871bdf4ebad7eb4520c7a651e3a2f4d8def1ca783c0efb807bdc7ec3Virustotal results 23.44%Heodo
2020-10-3086236250.docdoc f2ce2b3d2bf2f5d0f22eabb44f0b7c9183e0fea547e90ab926beae89d85cdf0en/aHeodo
2020-10-30B_I4JXJAJ0I1Y5SD2.docdoc f4983c5881da987bb4dcca9069e0134657dbd559cf50165c0f35c3f1c4595948Virustotal results 40.62%Heodo
2020-10-30Attachment_27233069.docdoc fbe079c5cd46bcc371fedd49df3189de10406984e2882c76b08947941f1726fdVirustotal results 40.62%Heodo
2020-10-30NG8949759698ZD.docdoc a120ab7f12256c4b260034ecf26910f2eb405bb2c41ea9d1d78fcd2f529d2debn/aHeodo
2020-10-30FILE_741869866278116472848957.docdoc 3619ca27723e87006b7061bd608e1e02d5087392ec513cfe82ecec069074fbd7n/aHeodo
2020-10-30arc_ULDRG10076X6WIE.docdoc 8c5ec7de8acd87d586e9bf7a74458c2a96f88ddbeacbde0ae3791d84594cc983Virustotal results 41.94%Heodo
2020-10-30Dat_ETX_100120_XDE_103020.docdoc a9e9b3f8a28330089d36e3ace6c5aa5ce2a38204767293a05e9c407ad2c4da4en/aHeodo
2020-10-30mes_397597640566943.docdoc 7bfa1640c072951be3fb17704054b151541525eaa8a22606d94fc2d037a6a663n/aHeodo
2020-10-30List_QKH_100120_QMS_103020.docdoc ceac47b63a26dc75f489b8882600b4a6ffee7b0c5b5dca3ef7732746cd3ec229Virustotal results 40.32%Heodo
2020-10-30rep_PO_10302020EX.docdoc d77f9d8ce192df999a4c7c9564c086962623dc1a6e020f14bf19f264f59d316fVirustotal results 37.50%Heodo
2020-10-30DAT_PO_10302020EX.docdoc 0b7f26dc76b83127cdf687f818e652f050a9b3726aa76bc30947f94e4e25ffd4Virustotal results 40.62%Heodo
2020-10-30file_EEB_100120_BNE_103020.docdoc e4c4aa874feb371209199ddd6b159ed4a677b94568dfe6b09351807263dbef9bn/aHeodo
2020-10-3002017845.docdoc b2f80aa2efc9abdf137f78f830f2366b29e5bba74409138f8db1ed6163e25819Virustotal results 35.94%Heodo
2020-10-30Dat_81397076.docdoc 401b08eb1c58500e67d4a452cf053775266c050d2e5cf3abc7b7d3ab0ac5bbadVirustotal results 35.94%Heodo
2020-10-30INF_EI2028851777BW.docdoc 2fe61550011a52e12cb324aa8cd06faeece3d1f05ae42f1c51bb7e055a647877Virustotal results 31.75%Heodo
2020-10-30REP_PO_10302020EX.docdoc b33622a59cee3ca443a74701f86f58ee524e9901c05d359270575f52d7d37380Virustotal results 28.33%Heodo
2020-10-30rep_PO_10302020EX.docdoc c2d7ed25c4c34f44dc293833d3ea302d281d24981385c437e411a50ede35e72bVirustotal results 30.16%Heodo
2020-10-30REP_PO_10302020EX.docdoc 785620ae5f3c011f3939803b6f7da0f097c81d008495ba545b805d7edf1fd707n/aHeodo
2020-10-30inf_PO_10302020EX.docdoc 8bb5a15cb71b657003f306f7244048209df651b7d03e95efb7318b15018c6a49Virustotal results 30.16%Heodo
2020-10-30O_26678877.docdoc eec673d1180b8765a6d45f7e7164e7e86024dce5cd09472669369e410fa5d161Virustotal results 27.42%Heodo
2020-10-29Inf_PO_10302020EX.docdoc 57a23ee50bad094280feb716af4f6917dcf92157f899a609736ead07c82e6432Virustotal results 26.56%Heodo
2020-10-29Attachment_TX0158402199RO.docdoc f69a365c0b551ac35010e98b64364feedecc32dae4284fb4afe62ced4b5d17ebn/aHeodo
2020-10-29mes_PO_10302020EX.docdoc 80ddf54fac7a016a1cd9cb22825bd7d9001001893d2d425c8436093582939224Virustotal results 28.12%Heodo
2020-10-29UNTITLED_HZ1491613930FU.docdoc af5f164e4a01dce68ffde542decdb164b6873582d81bb169b4982624cfac5ce3Virustotal results 26.56%Heodo
2020-10-29FILE_YSJ0OR0.docdoc 168c46a9b7c3c72ceb572a447f6317e5b66aca4735ea8e096bc92f0d03628879Virustotal results 34.92%Heodo
2020-10-29Attachments_243782084122632508.docdoc fdd08f8a983b5fc70a146d936dc6ef6d53ae736a3eed003bf193343704e5ad47Virustotal results 33.87%Heodo
2020-10-29Attachments_UQBJJZHCG26UPC.docdoc c61fca273223598ec29bcc70b0f716f3cb0ff9d9e293a02c8e0328dcf0011153Virustotal results 34.38%Heodo
2020-10-29FILE_RIH_100120_NGV_102920.docdoc 41439f935c27535a7752ad0b7a778de41fa076af62cee2bf3ce8138567fd7060Virustotal results 34.38%Heodo
2020-10-29doc_PO_10292020EX.docdoc 957fdc10c373706014fb0f314948a99ca0723fcd625cffd748c8d544d32dd4d3n/aHeodo
2020-10-29Dat_PO_10292020EX.docdoc 51657b8a72e7e81349ee2744529184125522759769f93b02aebc3a2d33fddc2bVirustotal results 27.87%Heodo
2020-10-29E_STE_100120_OQC_102920.docdoc 633a628e9a364cb3bbd93ebdce10e5f23fb15370a584efb4fcecf4549c3b975dVirustotal results 31.25%Heodo
2020-10-29Dat_97939206.docdoc 72795d86c0dff6adb123dad6b3a9b9c23d725d275a28e5fc69d10b701169ce29Virustotal results 31.75%Heodo
2020-10-29dat_NVFGIZDQE5TG2D0.docdoc 4a2b5b076857ff6ff381d978c57a1820e0117128142cfc3b3e548b7902b98431Virustotal results 31.25%Heodo
2020-10-29list_S3R4UYVC.docdoc a5d70f05d98720bd04c84440dd37092752ad5412805815ee92472cfc5c2aa1b7Virustotal results 32.81%Heodo
2020-10-29FILE_70275611.docdoc 839abc433704b3c9f252e4b68c75716c695fd3f83ea2663bfff7d1c5a5f5ce10n/aHeodo
2020-10-29UNTITLED_06179060.docdoc 26116918df27572814521839a1d3ffdb544bc825e81c871aa514890cc6411d44Virustotal results 29.69%Heodo
2020-10-29PO_10292020EX.docdoc e6a7e6b13c6bf9156c51ce46213a68a27ed5da4c01903cc86465ac63c073fd7dVirustotal results 26.98%Heodo
2020-10-29rep_4045530308.docdoc 98de74a1b000e840bd188d7a4e35eb9150102a43f8c4fe5357bebae3ad586955Virustotal results 26.56%Heodo
2020-10-29IHT_100120_EIC_102920.docdoc d28ab268249104b8e40b88f99670cb44f0cc8c440b22b983193c4e6fa4e0ea95Virustotal results 26.56%Heodo
2020-10-29ARC_19910749.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29list_89BHZH3B7KE3HK9K.docdoc 134e4b929d0e83768f3bad032abd87bd8d004dd2a7256fb9ff9d4bfa9f29e5fbVirustotal results 28.12%Heodo
2020-10-29dat_44934636.docdoc 777f2166c1b82de635874052d889fa727eba91067fe544d279a8699a2e89529eVirustotal results 28.57%Heodo
2020-10-29LIST_35120214.docdoc 29808c9db3a80e9ed46d4aecbe478dd8e57089d7e2977c916421cba71b0d6c42Virustotal results 26.56%Heodo
2020-10-29inf_40742294.docdoc b97ef63f4cdcb7c82862e52763408c1c6e70b9e4282e940d30c71dee4630e8d3n/aHeodo
2020-10-29AZZU_582473321028984702762544.docdoc e134359bfa4a04bffabf20a6522d2a4c8d807619578853ba0387aa395b6495c9Virustotal results 26.23%Heodo
2020-10-29doc_88989769.docdoc 1909a3514994e354da8e5abdfbb3b73173a1a6782a739ebdbfbacf098abf0fb2Virustotal results 20.97%Heodo
2020-10-29doc_PO_10292020EX.docdoc a536a1efba18ff7db257286623904f5d131c7e933b0af1302fec81dfca157b65Virustotal results 20.97%Heodo
2020-10-29MT8785465032RN.docdoc 12c570f649005ea1ae77c36167843e3e87252075b68b652c5f05b0d8e54b2ad0Virustotal results 20.31%Heodo
2020-10-29Rep_AIPARGZ063H.docdoc 3c06e83a34a8da9715ec0fb21f45160520d6058d9624263c4c2a585b04c7adb8n/aHeodo
2020-10-29dat_8661289335772430.docdoc cd49f6f6b2b1cbf28331a1eff67e7179731f34a790a1bb69c89b65ffcfc38e01Virustotal results 20.31%Heodo
2020-10-29List_PO_10292020EX.docdoc 0cacb466a5cd54765f2b551a75b8b0880cd991d16fd662402d00efc578060da7Virustotal results 20.31%Heodo
2020-10-29File_PO_10292020EX.docdoc 2427ee3cc0798fcee02c718a1fb58d735d9cf3b0ebd9bb10c14cb9326bb5e489Virustotal results 20.31%Heodo
2020-10-29TZ_3RHPI8AFEJ.docdoc 371a442d56b47bd24ec601a710beb116a75f09be269d0a2e18b29d6fe0927bc1n/aHeodo
2020-10-29SHY_100120_DEW_102920.docdoc 5a00d4a9d8e50c06f30007460af1dc4f73950dff8ef4d1966ec4098c16712bf0Virustotal results 42.86%Heodo
2020-10-29FILE_RLA5X660JSTPT.docdoc b9e189f0cb3064ede89dc2167eca309a64edc4ae42aeda9b8fab875c4906b5dbn/aHeodo
2020-10-29DFY_100120_QTR_102920.docdoc 72e4ad0a1b83a8af4bffff0b32b6f8b9fe9680a323457b9ae5b866c9cf789ca1Virustotal results 41.27%Heodo
2020-10-29arc_PO_10292020EX.docdoc 203c3fd643e932d50df0ccb5aa112bf49bbf44dd16e722b4bdc67551bf3fb133n/aHeodo
2020-10-29inf_BW7EWU7H.docdoc 9e3811f229348aa0b4c22ca7f0808d1d13ec1f3a19d4a0e675168b552da2e96en/aHeodo
2020-10-29doc_95844364.docdoc 5d0b92f454b00f1679bc6b090749bf784d1fa854eac55bf453eec083b6aa2076n/aHeodo
2020-10-29H_FB4076376986HJ.docdoc bb6a910117fc42075d0f29a1d7f63f94814e7f787223e3af617ca5018180a77eVirustotal results 40.00%Heodo
2020-10-29List_06610865.docdoc e3a96d2e3adca1fc3dfea0ac14af9b1d4cec3a20d9d7c6874edf1c6fec60d90bVirustotal results 38.10%Heodo
2020-10-29Rep_4QD4MIG4Q9TNJ9C.docdoc 67bf175be626fe3ee59387c2c162c6fe009315964e0d4de581dc1a94daab51c5Virustotal results 37.10%Heodo
2020-10-29rep_PO_10292020EX.docdoc 40e1e0d4ba67280ae17c0050feb66bf13f27e271efd4fc91413f8553dcf12a09n/aHeodo
2020-10-29INF_5741493881808.docdoc d41fde459d5a6605355b1daac05e7fe5ed46f2f70d564951027067566a049475n/aHeodo
2020-10-29file_O3IUQQ4AUV1L.docdoc 665ea7994646d6f55327063f07c46e3d51cce78766dc14fc03031b5581283b10Virustotal results 38.10%Heodo
2020-10-29LIST_PO_10292020EX.docdoc 9f2ed62dea3b679b6dfecbb79905a34ef056e81af2e92c4249fe4521711b047fn/aHeodo
2020-10-29FILE_PO_10292020EX.docdoc e805aba1645cd9062f3616474fe439626cd8d4aca4eea889c9271dd1508d51ddVirustotal results 36.51%Heodo
2020-10-299310EJHR7VUN58.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 35.48%Heodo