URLhaus Database

You are currently viewing the URLhaus database entry for http://www.alize-flor.fr/lBkOP-lffy6nJ8bKfMeWX_NMvLthEL-1G8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:96753
URL: http://www.alize-flor.fr/lBkOP-lffy6nJ8bKfMeWX_NMvLthEL-1G8/
URL Status:Offline
Host: www.alize-flor.fr
Date added:2018-12-18 00:59:35 UTC
Last online:2018-12-18 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-18 01:00:28 UTC to abuse{at}ovh[dot]net)
Takedown time:12 hours, 29 minutes Good (down since 2018-12-18 13:30:14 UTC)
Tags:emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-18this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 0.00%
2018-12-18PAYMENT_816109PUAJUUV_12_17_18.docdoc 04ed22881589b6c77d01cdda5e35a736db215978e813aaf058da725c1bb48fb1n/a Heodo
2018-12-18ACH_548464UIRBVT_12_17_18.docdoc 67e20396aa806209ca4d38be7958d42cb28700eda1f511dfef542c27b1e1a886n/a Heodo
2018-12-18ACH_4413BLPOPUNB_12_17_18.docdoc 50fd133b606006eb3d0085028fcf5b4a2460132cda32b2e6a25a5d32f54718c3Virustotal results 42.37% Heodo
2018-12-18PAY_220549ISJELR.docdoc 749c2da7a49e60064ee30ad7579a5ac41d2f2bdc9c968ee8b2db96a0a2031839Virustotal results 41.67% Heodo
2018-12-18ACH_721553UNNPGG_12_17_18.docdoc 836c8c98daace0c809964ac4278730d6ac959c2beb288bb14807f69e329c829cn/a Heodo
2018-12-18PAYMENT_564973GPRAZIBA_12_17_18.docdoc 4de6f2cf9c172d566b3b3cdd2d67c74ceb1bb6363aa1d6a04731b551ee6515f3n/a Heodo
2018-12-18PAYROLL_7280542SZGAWA.docdoc 6bd106b90b7e4cc39d90c250e17fb23a0bb255c14e4cdf34d6a80d346f38ba59Virustotal results 41.67% Heodo
2018-12-18PAYMENT_11726LPYJPA_12_17_18.docdoc dda4cb335e20098a220191c90e9c0a195392b90d8e4c76ec0750e1a3584e77d5Virustotal results 41.67% Heodo
2018-12-18BIZ_0389077EKCTCDCA.docdoc ed2aa332b176982c9e7fa391d421ffc0ad861eba32a64e1635fbaed37ff37c64n/a Heodo
2018-12-18PAYMENT_266360CPSIMMLT_12_17_18.docdoc 93239b5ea551061f1ca4166c69075d62e7541a35964b9fba4604a9677432fe44n/a Heodo