URLhaus Database

You are currently viewing the URLhaus database entry for https://www.eflowersncakes.com/wp-includes/Pages/AtkpIu7fLPl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:765189
URL: https://www.eflowersncakes.com/wp-includes/Pages/AtkpIu7fLPl/
URL Status:Offline
Host: www.eflowersncakes.com
Date added:2020-10-29 12:46:06 UTC
Last online:2020-10-29 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 12:48:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 10 minutes Good (down since 2020-10-29 14:58:50 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29REP-0010888.docdoc 691fdeef1abdf9ff8b887a8525d4c15c82e16eacae4e41fc10cf14300ca23148Virustotal results 26.56%Heodo
2020-10-29dat-2020_10_29-298.docdoc 2a117f803129615a11fb51b03aa78464658c82e754b6140a4a01b2ef3bc13a69n/aHeodo
2020-10-29242752 1604420.docdoc 7aaa9a98edfbcbe126159992ba06f8c91ec5560f77e2d0052dd18df4f5bf843en/aHeodo
2020-10-29INF 2020_10_29 230.docdoc 09b8d65b64218ad504489c3b2bc0e3cd74300774ddc3e908c0628f95234fc3ben/aHeodo