URLhaus Database

You are currently viewing the URLhaus database entry for http://villacitronella.com/En/CyberMonday/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:85484
URL: http://villacitronella.com/En/CyberMonday/
URL Status:Offline
Host: villacitronella.com
Date added:2018-11-27 00:08:13 UTC
Last online:2018-11-29 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-27 00:10:07 UTC to abuse{at}beget[dot]ru)
Takedown time:2 days, 6 hours, 45 minutes Poor (down since 2018-11-29 06:55:50 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-28CM_COUPON_FILE_09218.docdoc 367a7423d3eeae055ebee570869284a087161438a044443f374660089a824b9eVirustotal results 27.12% Heodo
2018-11-28cm_coupon.docdoc c562d51cd490dee1caae145984d86d93eb0598b9768e65764c98a7062b0b0a23Virustotal results 23.73% Heodo
2018-11-28CM_COUPON_10833.docdoc 912b2935a76ce2a52d461d87b93e20ba77ed5b6a15742e063b1f359442831951Virustotal results 23.33% Heodo
2018-11-28cm_coupon_file_45895.docdoc 4b6bb70862b8b576eabc9b0c2074e0fcd3993fd7910875a21d3bb1f05c677aa8n/a Heodo
2018-11-28CM_COUPON_FILE_7940.docdoc 641b3827cc57b54413cc2cea42f48144a4baf5d4a68d5c7dff07280528b7c014n/a Heodo
2018-11-28cm_coupon.docdoc 0da44be038d0321cf029dc1498af4b7c45ec709134ea83646f82c36b599febd1Virustotal results 36.67% Heodo
2018-11-28cyber_monday_coupon_75090.docdoc 0626106e0fcbc70f58fbb07aa60cb96a72a66baeec53c9acf933a75a5cadae43Virustotal results 28.33% Heodo
2018-11-27cyber_monday_coupon_file_76164.docdoc 3273e36283f53d159a20ce1c0cb67733fb976fdf8fe1953130817c4fa9aa4323Virustotal results 22.03% Heodo
2018-11-27cm_coupon.docdoc af9abcab7f3b61d69186253db56c658fdec135d7b37a7cd7d0b4715b991158f0Virustotal results 24.14% Heodo
2018-11-27CM_COUPON.docdoc 25541da7b13c7dd528d1c80cb3ba61d071f2b3d10754b776e7335e88b5a8089fVirustotal results 22.41% Heodo
2018-11-27cyber_monday_coupon_65907.docdoc 031363d0da1eec1c5d3c62d067d7f2dfc58d9c73950b3ede8f2817549b621501Virustotal results 22.03% Heodo
2018-11-27CM_COUPON_14640.docdoc e18247caed44ec7fd8c298387caf16d3f253c11e3163d0d7d46920d85e5cd949n/a Heodo
2018-11-27CM_COUPON_2019.docdoc 3186dc2f65bafee9420752229e7449a30114b3da7a98c7c92f2169c62d11b112n/a Heodo
2018-11-27CM_COUPON_5474.docdoc f4aa05a0dd91fd7c481f3d68643970e4e3f97150c212260caf26471641a038c4Virustotal results 40.68% Heodo
2018-11-27cm2018_coupon_file_14271.docdoc be528e48e63a887906de49cb132133c90874d756d8ce6927fff9e6dced62c160Virustotal results 40.00% Heodo
2018-11-27cyber_monday_coupon.docdoc 1e2b384e850ba1266ec9afd11be5dce973adaa94d8f5befe36cf4caa97fab18cVirustotal results 33.33%