URLhaus Database

You are currently viewing the URLhaus database entry for https://squire.host/termo/attachments/WRyMb4GHbZjKP0Bm4W/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:764023
URL: https://squire.host/termo/attachments/WRyMb4GHbZjKP0Bm4W/
URL Status:Offline
Host: squire.host
Date added:2020-10-29 06:59:07 UTC
Last online:2020-10-29 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 07:00:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 13 minutes Good (down since 2020-10-29 09:13:30 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2976774854_0967138.docdoc fd1a6f6fdc182a980de3818f5c2dfc61b7fe1c9d4f88a114149006241598e829Virustotal results 15.87%Heodo
2020-10-29Rep_2020_10_29_76596.docdoc 7436e8b33a6c2f46e5aadf8ccdbb9e93d725ffdc2ba7e23a043c8a32b1e1fa22n/aHeodo
2020-10-29DAT_2020_10_29_J078342.docdoc 7d971ba436ef47a47ffa7c6e157299776fab8310ae80dddc98c0b7638f5b2ee4n/aHeodo
2020-10-29inf_2020_10_29.docdoc 8b60926cf9d5804b5b4c7900d12d19836729d506ea04601e39c1d72ef37eb703Virustotal results 15.87%Heodo