URLhaus Database

You are currently viewing the URLhaus database entry for https://www.lyricspanti.com/bzbhf/OCT/TNmjjWUcS1F3nfCNsaC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:763739
URL: https://www.lyricspanti.com/bzbhf/OCT/TNmjjWUcS1F3nfCNsaC/
URL Status:Offline
Host: www.lyricspanti.com
Date added:2020-10-29 05:36:06 UTC
Last online:2020-11-26 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 05:38:23 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:28 days, 12 hours, 57 minutes Bad (down since 2020-11-26 18:36:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29file 20201029 5823.docdoc c5fb6da467aa03871b3d49d8bc5808b6b8e051dca7bd1aa57b58324d9b9a97aeVirustotal results 21.88%Heodo
2020-10-29INF-811588.docdoc 3400d3365c00f74da9c7e268a7467a4fb6df77e14095a274358b6646f084d1bfn/aHeodo
2020-10-29rep_596140.docdoc d94833fa6c0671d510dd2f44d2cc25c3dff5eda7cf98e160177008d91d093210n/aHeodo
2020-10-29Inf-Q298439.docdoc e13e1b5db38b6d366f7ab841db3b6a383d28d78df1fbcdba3754178064563746Virustotal results 20.31%Heodo
2020-10-29DAT_2020_10_29_067.docdoc 51e1904ea1245023e8308cae00addfe2bea2ad7b5946339b0072b1a445d2b6a5Virustotal results 17.19%Heodo
2020-10-29UNTITLED 2020_10_29 UVK45047.docdoc 56ee9fdebd1425ec517e18b06141c4e6a3b4798e9540f77c378a923169e431c3Virustotal results 17.74%Heodo
2020-10-29Mes_U3120.docdoc 14b06f918aa16432976899c05e5f1981b618348b9bdd66d5b05ad1aeff31d617Virustotal results 17.74%Heodo
2020-10-2950679_EEK8528.docdoc 8b3af5e0f1d3a493a3893972faa5ccdc89fa94d4f6780de68d6234a601451b77Virustotal results 18.33%Heodo
2020-10-29List_2020_10_29_CLQ472658.docdoc 741375b07ac32d524e8c607b3eeade5bf05677b047fed42c812d758f46b10238Virustotal results 17.46%Heodo
2020-10-29list-576.docdoc fae885910713e877e3bc35d598867cc34558f009724f5777e84dab81d52c4484Virustotal results 14.52%Heodo
2020-10-29FILE_20201029_DG681.docdoc c47ec97cdbcd82f5d5421f8a0bf4638f3584477d987f37eb220f1117ff0a974dVirustotal results 37.70%Heodo