URLhaus Database

You are currently viewing the URLhaus database entry for http://ferranroig-psicoleg.com/wp-content/XCMsCR9fuLNvK9i0L19NbDLlequEBkq6lr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:949623
URL: http://ferranroig-psicoleg.com/wp-content/XCMsCR9fuLNvK9i0L19NbDLlequEBkq6lr/
URL Status:Offline
Host: ferranroig-psicoleg.com
Date added:2021-01-05 19:21:03 UTC
Last online:2021-01-05 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-05 19:22:06 UTC to abuse{at}cdmon[dot]com)
Takedown time:1 hour, 27 minutes Good (down since 2021-01-05 20:49:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-05SWKK12IWILRG0B.docdoc 7f9e6b9183a6a254ffcd68100012d645a5fb91caaf3b727bbbd76f4262595bb7Virustotal results 42.86%Heodo
2021-01-055YYYCGH6CD.docdoc 6792a8737e9fa557cdbfc232021a5c2efb01b55d3bf1d560e9ca9671f8af9fben/aHeodo
2021-01-05A51TXNH5U.docdoc 9989dfbbd3669ca3164a605c485ac6a06d5c27ebf7357bf76968e81d2068d3c2n/aHeodo
2021-01-05TCGVHDZV.docdoc 3c8d3c07935afc4bbc31b8c4a7a6b2cc77bdf0c2985a9595ec9edd6d3e8a5279Virustotal results 42.86%Heodo
2021-01-05NTRO1OGNWPCEZKXU.docdoc 3c881e9db07a42e23408d2e8a96c65feec2857b04256e4e9c2a6a9789994258cn/aHeodo
2021-01-057Y85J2.docdoc 203f16a0313a65b940a054b564acd009dfd1d1737b41ed8fa081f8c1f1c53fc7Virustotal results 42.86%Heodo
2021-01-05VE29TRB9.docdoc 974beb7c01603cea485421634df12efd26ff161d1e948dac21502c26f93d7c53n/aHeodo
2021-01-05IHY53A.docdoc c2a6153157de0da1987225400eb7e32c87f9574e825320466772d6804cf8d3b0Virustotal results 42.86%Heodo