URLhaus Database

You are currently viewing the URLhaus database entry for http://www.lyricspanti.com/bzbhf/OCT/TNmjjWUcS1F3nfCNsaC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:764544
URL: http://www.lyricspanti.com/bzbhf/OCT/TNmjjWUcS1F3nfCNsaC/
URL Status:Offline
Host: www.lyricspanti.com
Date added:2020-10-29 09:36:05 UTC
Last online:2020-11-10 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 09:36:55 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:12 days, 0 hours, 32 minutes Bad (down since 2020-11-10 10:09:20 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29file 20201029 5823.docdoc c5fb6da467aa03871b3d49d8bc5808b6b8e051dca7bd1aa57b58324d9b9a97aeVirustotal results 21.88%Heodo
2020-10-29INF-811588.docdoc 3400d3365c00f74da9c7e268a7467a4fb6df77e14095a274358b6646f084d1bfVirustotal results 25.00%Heodo
2020-10-29List 2020_10_29.docdoc 7aaa9a98edfbcbe126159992ba06f8c91ec5560f77e2d0052dd18df4f5bf843en/aHeodo
2020-10-29Inf-Q298439.docdoc e13e1b5db38b6d366f7ab841db3b6a383d28d78df1fbcdba3754178064563746Virustotal results 20.31%Heodo
2020-10-29DAT_2020_10_29_067.docdoc 51e1904ea1245023e8308cae00addfe2bea2ad7b5946339b0072b1a445d2b6a5Virustotal results 17.19%Heodo
2020-10-29Attachment-20201029-55790.docdoc 984473c63ce979671f89a4cba67e41d45803aae51ecb5a47e54d83e62c6aa448Virustotal results 17.19%Heodo
2020-10-29Mes_U3120.docdoc 14b06f918aa16432976899c05e5f1981b618348b9bdd66d5b05ad1aeff31d617Virustotal results 17.74%Heodo
2020-10-29Mes 2020_10_29.docdoc 73b50fadf718b2d073b51af2fc11b8a76e2ae9424ecfd37e0ae1518f6edf78d2n/aHeodo
2020-10-29List_2020_10_29_CLQ472658.docdoc 741375b07ac32d524e8c607b3eeade5bf05677b047fed42c812d758f46b10238n/aHeodo