URLhaus Database

You are currently viewing the URLhaus database entry for http://petafilm.com/css/Q5hCjA5kgh6tcfP0SlAqtk2CrjegN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:956652
URL: http://petafilm.com/css/Q5hCjA5kgh6tcfP0SlAqtk2CrjegN/
URL Status:Offline
Host: petafilm.com
Date added:2021-01-13 00:41:06 UTC
Last online:2021-01-29 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-13 00:54:02 UTC to abuse{at}as42926[dot]net)
Takedown time:16 days, 1 hours, 36 minutes Bad (down since 2021-01-29 02:30:57 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-136KQBVZ7P.docdoc 841f665e7fa0dafb08a148c375fc49b0594eecdf01d44cc9b7ea8e6c6b5fe024Virustotal results 41.94%Heodo
2021-01-13Z0ZLO5.docdoc 17ae598e992451fcbd61f1dfe70a4added1091173dadd5cb163aea9902eaf79an/aHeodo
2021-01-13WOJGWAVHJG3Q.docdoc 4ac3c771a4cf5e381984161bbef7c1df3a4c5b75d22d5c6dfd6b494d0cdfc073n/aHeodo
2021-01-13XWHNR58WK24M.docdoc 69d9dc566e89715d0579eaf0478cc5266a91f3535c5dc33db6c532c500a2737cVirustotal results 40.98%Heodo
2021-01-13QAT2WIUHHRWKYC.docdoc 1d60cf7a5a88c9b4a1b2c9ea649413891cd78db09b85027981ec9491cb954e1bn/aHeodo
2021-01-13L1JSXM9HI.docdoc 3b34e75cce4b617fd876f0145c30b4ea5af865c2edb3b8cc89fdc268bb347b1aVirustotal results 38.33%Heodo
2021-01-13WJEGHPA3AQN.docdoc 91a4617e7fd2b891c584ea3f54b6a9864aca1ba6ac8c5a0a4e450bd374b60f6fn/aHeodo
2021-01-13V9TPY82GTQ.docdoc 2d2fa64b93abf2055071f77d797832e29b37dcf63c6991b6dbfd0e779af8c115Virustotal results 33.33%Heodo
2021-01-131HT9DVR170SQWVI.docdoc 866744b3695d0b0c7d2e887aa1d3b2be95583ae6a88f31fbc0f4f6c150477804Virustotal results 29.03%Heodo
2021-01-133FPZXNLX.docdoc a4b2c79223d87bc6523817efc6ae96ddb3a517b509a0907f5aa47ed93cf1bd78Virustotal results 26.98%Heodo
2021-01-13A679MHOXGW.docdoc bf49563033ad40742badf4e09f7aa09e4d4bbeff563e4502c829662d47fd96c5Virustotal results 25.40%Heodo
2021-01-13Q1WRBPDQ.docdoc 91df3e9a9690c149ae4587d46020b21ab675cfd5afa6a5809637d4686cfff6c7Virustotal results 25.40%Heodo
2021-01-13P2DD4GGIOC36KF0I.docdoc 6519108ab0d32b865e06f74784831341df7a5c7a0f02221511a5a13b8762e375Virustotal results 25.45%Heodo
2021-01-13XTKVQ0OZE0995WDK.docdoc d2232dfab1a3d97b00285d3baeedaff80ee090c7fb8bec50f6fb23554fc7d4aaVirustotal results 22.22%Heodo
2021-01-13DFG5AD6L4AB.docdoc d77e78f619d681603f2d2c3ecc803419724067121e18623302a4155a0efba1fbVirustotal results 22.95%Heodo
2021-01-13ET21F58TBVJVWZSN.docdoc 5cc80cc17bbb89808db987af2bbfbe02975c1d67cfb77ac0a9a5af0468a36210n/aHeodo
2021-01-13M63EMQJQPZGY.docdoc d93333dbffefb763131024dffc1c0723d897a65c7b8d2701f5fa5bc9498ae89fVirustotal results 23.81%Heodo