URLhaus Database

You are currently viewing the URLhaus database entry for https://wp-test.greenergizer.a2hosted.com/cgi-bin/AdGHCGUS1O73LeAL0FmMIuN8riqj4VkTx2B6OChShH8x1Z40JGzSq0nMGnYSgv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:764347
URL: https://wp-test.greenergizer.a2hosted.com/cgi-bin/AdGHCGUS1O73LeAL0FmMIuN8riqj4VkTx2B6OChShH8x1Z40JGzSq0nMGnYSgv/
URL Status:Offline
Host: wp-test.greenergizer.a2hosted.com
Date added:2020-10-29 08:47:04 UTC
Last online:2020-11-27 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 08:48:06 UTC to abuse{at}a2hosting[dot]com)
Takedown time:29 days, 4 hours, 37 minutes Bad (down since 2020-11-27 13:25:25 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30mes_IC4563912946IC.docdoc 6e4f96c30a71272d69c0789a8ca8dc29ff77127524a628e331cc9207f45d524dVirustotal results 42.86%Heodo
2020-10-3049245133.docdoc f4983c5881da987bb4dcca9069e0134657dbd559cf50165c0f35c3f1c4595948Virustotal results 40.62%Heodo
2020-10-29FILE_VYOFVY0.docdoc c685520233b6d670ab20445051b6688bac6affb5c8b99a71213937d99ac9e380Virustotal results 25.40%Heodo
2020-10-29PO_10292020EX.docdoc a5d70f05d98720bd04c84440dd37092752ad5412805815ee92472cfc5c2aa1b7Virustotal results 32.81%Heodo
2020-10-29doc_HR6324072756LY.docdoc f1360579a25ea174943b561c1e8e174e0145373505152d928c6e1dbeaeae60ddVirustotal results 24.19%Heodo
2020-10-29Mes_478745896535295.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29LIST_65454589.docdoc 1909a3514994e354da8e5abdfbb3b73173a1a6782a739ebdbfbacf098abf0fb2Virustotal results 21.31%Heodo
2020-10-29doc_35899826.docdoc 4105e48c905f55328aa0a89a608c302216a2d4b119573ef85d1e9902d0531119Virustotal results 20.63%Heodo
2020-10-29inf_788487653.docdoc 1ecf50c67d4c4bf7eba5ed050c6500f7ab6a2b63b66f12dd23748e22e9a34ce7Virustotal results 44.26%Heodo
2020-10-29Attachments_16042165.docdoc c914f79bcecd36e66a0afaafa94fea889077dc0eeba31cb470833af137c79564Virustotal results 41.94%Heodo
2020-10-29rep_PO_10292020EX.docdoc 48f5efeee13fcdbe837223ddd4c1de97dd87be397e6f99bb95ebfd19af5aaf86n/aHeodo