URLhaus Database

You are currently viewing the URLhaus database entry for http://pelisxxx.me/cgi-bin/IFpV0N2GtzFOmUcW2U7I0ZZZXINfsYKpWJDi4MnBsOzc7aSkS3PxOhhZT9Qh09NNnCHunW/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974506
URL: http://pelisxxx.me/cgi-bin/IFpV0N2GtzFOmUcW2U7I0ZZZXINfsYKpWJDi4MnBsOzc7aSkS3PxOhhZT9Qh09NNnCHunW/
URL Status:Offline
Host: pelisxxx.me
Date added:2021-01-22 21:09:03 UTC
Last online:2021-01-23 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-22 21:10:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 51 minutes Good (down since 2021-01-23 00:01:20 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-22G3C6KV.docdoc 70ac185fdce6d551871ebe57cb2bd1b36cc4d721755c57e27a21fc81beb31ce2n/aHeodo
2021-01-22G93TC9394.docdoc 42468a0f13eb23891636d001f932b9b706f4e43f2bcc3bb417f89ea79e8f7415Virustotal results 41.94%Heodo
2021-01-22IL3Y8F8RE.docdoc 25eae8684f15cff80197f955eff7899e81081b1d9dd37eb92f62d7bb8bd796adVirustotal results 31.75%Heodo
2021-01-22C246VV.docdoc 58679381a46d62f343527eddb0e188a30184ea770eac5182c427ff13ec75412cVirustotal results 44.44%Heodo
2021-01-22SLFS241VM5.docdoc a9298f2707a11dfbafc02b9880250f2fde9e11b3ed26c80bd952ee4c5f41c667Virustotal results 46.03%Heodo
2021-01-22Z003QUS6475.docdoc 42152c466701b05f7fdbc32e290f3cd236d53f2a4a6e212bc675183e4a2eafd3Virustotal results 45.16%Heodo
2021-01-22K2LZ6H4NONQ7.docdoc 74c41fdd82136763f1fe4daf52b1e388f2a4cf39d73e441f895023247b23f720Virustotal results 45.16%Heodo
2021-01-22NMRLKH63ZSC.docdoc a4ca64ab0ba7ae814fe635ce9bf2febea22c4f78b6d9310948f751713214c0d1Virustotal results 39.68%Heodo
2021-01-22LVOE8IG9UIHT6.docdoc c82d9f636e5557e336f7590d7012768bd8060c6ccbe44a3a5c1c2e3976c62b3dVirustotal results 39.06%Heodo
2021-01-22LVM79WPSVP53TMHG.docdoc e86d93199f2f416bf5dca9a736c5bdbac4ee3989ab0f04baad2c7e0066316e72Virustotal results 38.10%Heodo
2021-01-22SEYVZ517CXGZGB.docdoc d369edd4ee295fafd1231bb5d370fff75a48505360a64708bce6418c7f2974a1Virustotal results 38.71%Heodo
2021-01-22A746RYSM8I3S8.docdoc 8af280e70fb92f35455e9f18296c0fbaae42288517c6925a9db673a9368e9bf3n/aHeodo
2021-01-2253UYGRS69Q1.docdoc 9849abef3e272dea13e211d946b289bc80ab32efd5e83178ca17a6bb094be274Virustotal results 35.48%Heodo
2021-01-22IX321XWWF.docdoc dda31bb204e2a3207fe515d3d1952604f010c2b3bfad0df8a1b33e7b4bde2b94Virustotal results 33.33%Heodo
2021-01-22T488AJBZI2G.docdoc 912f6f38547eca79cdd2f66b1252ac5b777f454c8d4da059d319ca9a42d1cf24Virustotal results 37.10%Heodo