URLhaus Database

You are currently viewing the URLhaus database entry for https://www.plannueve.net/wp-content/GKvjONMVzlapctZOJflhS5m4KHL1sBfKceMhL6UXnL01C00raevICTmfREkKURW5TYQtg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974288
URL: https://www.plannueve.net/wp-content/GKvjONMVzlapctZOJflhS5m4KHL1sBfKceMhL6UXnL01C00raevICTmfREkKURW5TYQtg/
URL Status:Offline
Host: www.plannueve.net
Date added:2021-01-22 17:30:05 UTC
Last online:2021-01-22 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-22 17:32:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 39 minutes Good (down since 2021-01-22 20:11:35 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-22YA1QJTJ22E.docdoc 5b8a09ecc983f2bfa3c172b58755d141faaaa80c8016de77c9cbcdd83805d5abn/aHeodo
2021-01-2244YMFZ53JLK.docdoc 37866f94856a5faf43b8d90001a46a03ed9a8c10d666298bcc0341d28842a1a6n/aHeodo
2021-01-224POV9H.docdoc 18eeb3c4acd968e5fb4a847ef4eb4953690be2b5a9ad36d6f82a9cbc7caa7a53Virustotal results 32.26%Heodo
2021-01-2203MB714D3S9.docdoc c7f261f11d0e317860ef68857f8457e85439e702a7c90170b9b74b1508656b99Virustotal results 33.33%Heodo
2021-01-227A1RVV.docdoc 18a322bc3bc173a8128d00e372d608c3251f083c2587e69c79ec037933928d39Virustotal results 32.26%Heodo
2021-01-22L95US4A6.docdoc e35524adab62617f979bf2093ed1c81d50ea11bbf40b3f32bc000a58fe99a39cn/aHeodo
2021-01-22R3LUNB5TVA.docdoc 1d2d80a3a1d3ba28ca88d827cc5fb6b166f7d41b3f91065e8448f691275bcd3cVirustotal results 31.75%Heodo
2021-01-22GNEM9Z8BDXP6M.docdoc 361afbb90589c1dbaba30c9c8b380772449df5b01544e084fe473b501f583129Virustotal results 31.15%Heodo
2021-01-22KQJDZ7TOSR.docdoc 6ff60fa0ed16508f73c39701cb9dcd8b1440b3778b8059d97ad3a25cabd65cb7Virustotal results 31.15%Heodo
2021-01-22Y58V366LCA8NG.docdoc e26acfd8ba9ac131426a2d9667e8ad19344e9977a884531fd2a2127615481f99Virustotal results 32.26%Heodo
2021-01-22WETKBJIC.docdoc cb61a7b158e7abd85d3eae1f24f813429ca19d16a207e7263022e5ffa0b16fd8n/aHeodo
2021-01-22QADKGKVT4DNXX0.docdoc 077fd7de4590c86cef6c92180c5d65a613bc17a38f749b04ac9ec8d2bee2ecafn/aHeodo
2021-01-22E8K3QHI8U45.docdoc 0dc0f00a3ed385b6bff2f9188766ae977a173405c9bfed86474e9f7fccfde9c1Virustotal results 31.75%Heodo