URLhaus Database

You are currently viewing the URLhaus database entry for http://wp.salad-stand.com/powershell-goto/fYkkKtZHtigFxguXkDnP7CeKBF7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:770008
URL: http://wp.salad-stand.com/powershell-goto/fYkkKtZHtigFxguXkDnP7CeKBF7/
URL Status:Offline
Host: wp.salad-stand.com
Date added:2020-10-30 16:18:05 UTC
Last online:2020-12-03 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-30 16:20:17 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 month, 3 days, 22 hours, 35 minutes Bad (down since 2020-12-03 14:56:12 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-31LIST_00054911.docdoc b104e5360f8f17268449e97ba36749b921cf7cdd797fdb8a28ffe20d8d9c59e4Virustotal results 54.69%Heodo
2020-10-31Attachment_PO_10312020EX.docdoc 39991605b314bb39a573ea29a1b1cd2904615afe76292c0f3b6afac181a0d6d0Virustotal results 54.69%Heodo
2020-10-31MES_8445593215582977.docdoc d0173484a8073ed5336acc965770f3875b704785bf08f59a929f20c65512e1fbVirustotal results 54.69%Heodo
2020-10-31Arc_MUG_100120_OCQ_103120.docdoc e054d39b0aac7c2b6c6b76bc40435c1d0ffca154764349deefbc46f9d6ba453bVirustotal results 50.00%Heodo
2020-10-31doc_BU1988547295MC.docdoc 60e4646ea5fbe72e1daf6f3d015b37205898569b303dcfc791e0d02a754c9bf1Virustotal results 53.97%Heodo
2020-10-31dat_SN7197412070ZV.docdoc 4eabd4dcb81c28e86bbfd9ac62090d51aea5a733c96a8f3a7ad130a9841bce71Virustotal results 54.69%Heodo
2020-10-30doc_ZQ7733982085RQ.docdoc 26b30e58ed2342d042367ba0487873439d5c9c28920ddd000bb94b3eac79d94dVirustotal results 54.69%Heodo
2020-10-30File_PO_10312020EX.docdoc 66f30f7d40ef0e230f042cd6abe51971e49af52617515c3d0d99f3f365a59e90Virustotal results 25.00%Heodo
2020-10-30REP_OAU_100120_PIJ_103120.docdoc 14a8572928770f8d61fa05890c3e0a5cd4396bfde2ce2763d533e89d05120d34Virustotal results 25.00%Heodo
2020-10-30Mes_NIT_100120_YPN_103120.docdoc 22a4eae8735782a3f12e3f7ee5b6d0839cd7c4a8b91dce6ce27e2414b2e5f817Virustotal results 51.56%Heodo
2020-10-30mes_XBD_100120_GOL_103120.docdoc b79376701bfc97b082e9d8d61f6886b399692a2b154c6095559ab1da86e4c518Virustotal results 53.12%Heodo
2020-10-30REP_TOY_100120_FIL_103120.docdoc 20a348277c58a86bab1a218fd2dc97ea61811eeca81bbab000bf5f0afa562b36Virustotal results 51.61%Heodo
2020-10-3009816204.docdoc f2413a07e3362999d85fbab3f6c2fe8f228e4567eac899cd565ad65a2d0eede9Virustotal results 53.12%Heodo
2020-10-3009816204.docdoc f2413a07e3362999d85fbab3f6c2fe8f228e4567eac899cd565ad65a2d0eede9Virustotal results 53.12%Heodo
2020-10-3040286646.docdoc d577446435b94d0af2a829f1160b594e95c8051f6b069400ff61fa38d151ba54Virustotal results 51.56%Heodo
2020-10-30DAT_PO_10312020EX.docdoc 8ead4e972ba536f428fbee5bb8f687ff6a1efdae4456aafb1bbb176b37672180Virustotal results 23.81%Heodo
2020-10-30list_07210253.docdoc 4f6d5190871bdf4ebad7eb4520c7a651e3a2f4d8def1ca783c0efb807bdc7ec3Virustotal results 23.44%Heodo
2020-10-30FILE_32813924688039.docdoc 75ca20340c21dbd94ba3ec4c8eeb14f3a78e68a955701cbdc754c29163674a3aVirustotal results 33.87%Heodo
2020-10-30LIST_09641298744118390809074.docdoc 6061326ca1f6965d9ff04a37eb1defb55b410556500c197c6d8c9207a4432fabVirustotal results 23.44%Heodo
2020-10-30Attachments_DDKJZ39A7R.docdoc 1e363452c2a67d40f01390488a99f68ce6fab805b45eab93ee2db2469bf1b05fVirustotal results 42.19%Heodo
2020-10-30PO_10302020EX.docdoc 5fc665986d6e0e5763554e4d9f9db9ccc61b2c20fc408e955d286a458f622f48Virustotal results 47.62%Heodo
2020-10-30UNTITLED_WQ12NDKAI0U1TK.docdoc 1b230d33228fd383eaf4cc6faa376c0173fb8ff8d70c42dc9ab1ee5eacb411deVirustotal results 46.88%Heodo
2020-10-30mes_IPZ_100120_EDC_103020.docdoc 023fdae311195c64889d2c87831a470d7c4826a755cd385729dc6bb02281c4e5n/aHeodo
2020-10-30Doc_83961795.docdoc f49b970c0f5c5e742a76964f8ac3473e2b6a8558589d75cb54c5f7978178af16Virustotal results 42.19%Heodo
2020-10-30doc_35116817.docdoc 4e1fa1070d35befd506b61e5fcd7757c603c2289e9c09d657c6378bdfa6b8583Virustotal results 42.19%Heodo
2020-10-30Rep_PO_10302020EX.docdoc 578a7143a40755b7d7601a1b0e3f660137971473556e817d2a0e2ca57bc91053n/aHeodo
2020-10-30list_YLT_100120_XEW_103020.docdoc de0a1c44011e636f13b7db8734adcc239d484bae417f118f5d1173ff7d708481n/aHeodo
2020-10-30Rep_VT3528505715RK.docdoc 0b8a8e7a53d7fe5cfe16dbec4b9d21361ce7f6eb2f21c9ece0c5fdea89d09b74Virustotal results 42.86%Heodo
2020-10-30Attachment_OOL_100120_FCY_103020.docdoc 7d32a1b128f53a034d8ea7c493b9adf2cb851615918c77bdfc246c13758e7d31Virustotal results 42.19%Heodo