URLhaus Database

You are currently viewing the URLhaus database entry for http://egrextracts.com/wp-content/AK8XeVt2DBneMHWchOT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:949134
URL: http://egrextracts.com/wp-content/AK8XeVt2DBneMHWchOT/
URL Status:Offline
Host: egrextracts.com
Date added:2021-01-05 00:28:04 UTC
Last online:2021-01-05 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-05 00:30:05 UTC to abuse{at}amazonaws[dot]com)
Takedown time:3 hours, 46 minutes Good (down since 2021-01-05 04:16:33 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-05YTK35EUFPO.docdoc 09292d51e8d353b88a500ab38de30d3aaec41733df7b368af869cf472bfef48dVirustotal results 31.75%Heodo
2021-01-05BZGNLSYN.docdoc eedc56307590cb415b9388656d7287000bf530c10ab8c8c1f8bf4875321c2398n/aHeodo
2021-01-05T4DNXX031O.docdoc 48e5d9cf1ebc2c615dc60b2f35595632cb1ebf25c2305ea31f087bbe8689a1adn/aHeodo
2021-01-05IP1M1Z7VCXST7.docdoc 6e9366c10b06f94a3e436527ed163f7b68c4a81f911d593d64e6312d7b0e39b8n/aHeodo
2021-01-05EA47N1O.docdoc 252656a16cf6ef7ede48d6dfbf08918fae477b4e2ed50a5b2dcb46a1d6240fbfn/aHeodo
2021-01-0568LDPF.docdoc 2f410493048157fd2bccd80a02a83ad071a7b37038ab5fb6160ff9d6d1312522Virustotal results 31.75%Heodo
2021-01-054KM7DITDPH.docdoc d156b4fc840034beae78f8d4c55226d4dd1771465d0b8f45322dcd63731bdd4an/aHeodo
2021-01-0575R3NN5TV9.docdoc acbb7afbd6807623f7b138be593f37aed6daf29c912342a71aa8b65fbb4a99f7n/aHeodo
2021-01-051N7BDEQTS01.docdoc d315e07599f48461af20a81347aae5972ba5aea6210a0e28244b902a18cefc78n/aHeodo
2021-01-05F8R5BMALJ7KDT11.docdoc 89f2c53efc4423c85870b7b59615a36152242f602d3c1269a2226f9331684aedn/aHeodo
2021-01-05CQITWECEBLVY8YQ.docdoc 68f2889fb26be5dfaef1c55d3d1509e9a6b88f12ad89c8f869bf829d463ef59fVirustotal results 32.26%Heodo
2021-01-05BR8X1FYX2R.docdoc 38d17dfd9fc5d7eb04a6ed019750022081fd13b253d0eb08d92fd9109815ec52Virustotal results 31.75%Heodo
2021-01-05UKKEZT1U56.docdoc 8488d087b6010876c2aef93e85bcd715e0698b8c09e7c58e31a655b3c4860f4fVirustotal results 30.65%Heodo
2021-01-05OVU575SR.docdoc 401e09065cc4fe70319e8924de8ab2ace957de8a65a2a1ac15330fdfe2f9c092Virustotal results 31.75%Heodo
2021-01-05O6B8PAPDS2U934MB.docdoc 773a15b11264f83c09890cedbb7aedc943a30430f5b355d38e5625f2ebd3fb8fVirustotal results 31.75%Heodo
2021-01-057TN99YALO7DKF.docdoc 269b7e9055041b22adcfd3f3d1d0a4711292eb08c8674a535071c2ccf27a31fdVirustotal results 31.75%Heodo
2021-01-055DO42Y2P.docdoc dc9236f8bdf3716d6ad5bd3fc91beab4505cfe0585682cc68064718e9680c53fVirustotal results 32.26%Heodo
2021-01-059D2O1PG99G8LX7P.docdoc 63162fe833789ed99b85cf9524ce3254d7f676c2a187f7e2c2ecd23ad59ac5c0Virustotal results 31.75%Heodo