URLhaus Database

You are currently viewing the URLhaus database entry for http://wp-test.greenergizer.a2hosted.com/cgi-bin/AdGHCGUS1O73LeAL0FmMIuN8riqj4VkTx2B6OChShH8x1Z40JGzSq0nMGnYSgv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:765356
URL: http://wp-test.greenergizer.a2hosted.com/cgi-bin/AdGHCGUS1O73LeAL0FmMIuN8riqj4VkTx2B6OChShH8x1Z40JGzSq0nMGnYSgv/
URL Status:Offline
Host: wp-test.greenergizer.a2hosted.com
Date added:2020-10-29 13:34:09 UTC
Last online:2020-11-27 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 13:37:11 UTC to abuse{at}a2hosting[dot]com)
Takedown time:29 days, 0 hours, 0 minutes Bad (down since 2020-11-27 13:37:57 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30mes_IC4563912946IC.docdoc 6e4f96c30a71272d69c0789a8ca8dc29ff77127524a628e331cc9207f45d524dVirustotal results 42.86%Heodo
2020-10-30File_MDX_100120_JZF_103020.docdoc 21d510dc43e2e064f6d94e3b502c483eb6fc1171828a5349dd22c43ccba66638Virustotal results 42.19%Heodo
2020-10-3049245133.docdoc f4983c5881da987bb4dcca9069e0134657dbd559cf50165c0f35c3f1c4595948Virustotal results 40.62%Heodo
2020-10-29FILE_VYOFVY0.docdoc c685520233b6d670ab20445051b6688bac6affb5c8b99a71213937d99ac9e380Virustotal results 28.12%Heodo
2020-10-29List_7981301852712768211133143.docdoc 1fa65cbd054792ed8ce72d5729cb95a5810f1371e5b096b2f1a099416c193420Virustotal results 26.56%Heodo
2020-10-29PO_10292020EX.docdoc a5d70f05d98720bd04c84440dd37092752ad5412805815ee92472cfc5c2aa1b7Virustotal results 32.81%Heodo
2020-10-29WAS_100120_NIX_102920.docdoc 837f8783d77afcf060f98f1a7e0b2ad270f9b42780812799d499b0d8c9af1f37Virustotal results 31.25%Heodo
2020-10-29doc_HR6324072756LY.docdoc f1360579a25ea174943b561c1e8e174e0145373505152d928c6e1dbeaeae60ddn/aHeodo
2020-10-29Mes_478745896535295.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29LIST_65454589.docdoc 1909a3514994e354da8e5abdfbb3b73173a1a6782a739ebdbfbacf098abf0fb2Virustotal results 21.31%Heodo