URLhaus Database

You are currently viewing the URLhaus database entry for http://desbloqueosuniversales.com/EN_en/corporation/Copy_Invoice/BalcZ-858_C-HIO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:124692
URL: http://desbloqueosuniversales.com/EN_en/corporation/Copy_Invoice/BalcZ-858_C-HIO/
URL Status:Offline
Host: desbloqueosuniversales.com
Date added:2019-02-14 20:20:13 UTC
Last online:2019-05-03 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU000973325 created on 2019-02-14 20:22:04 UTC)
Takedown time:2 months, 17 days, 21 hours, 5 minutes Bad (down since 2019-05-03 17:27:06 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-12US6979389750062208.docdoc f1fac57e105fc5dea493c436b5a8169a626ceb5f04e7ba277db426378936f575Virustotal results 56.36% Heodo
2019-02-15PAY6136705982516547973.docdoc 1fa95942b50ba9e05216e1d14d810efce62a17e4948e0bc568593807f97935a0Virustotal results 23.21% Heodo
2019-02-15US7207347228945418359.docdoc ef0d92853060f64185bd1e8cbbc8120c68359c8a21925286f3d2bbb8a58000beVirustotal results 21.82% Heodo
2019-02-15ACC02838170754771813.docdoc b3280511fa1f6561394777af7bcd63c1213031e5f4b0c39cf13e22466ef53ebdn/a Heodo
2019-02-15ACC4708411750773.docdoc 4bddb7c97a45703317ead1e7b4c47a303726c38b9279e6bb20304273ea87bb1cVirustotal results 19.30% Heodo
2019-02-15INSTR70917101628822.docdoc ea43e44fe8202b2c586361221366d6d73c7a3f9e00b3471202c81fc8b104dd94n/a Heodo
2019-02-15PAY72476238536.docdoc 7099059f10ab61e6a1d264b2971cdfdb1ff469679082d212f82f45417848b633n/a Heodo
2019-02-15PAY9072072130900040875.docdoc ac71280f56ac47e19ea329d3685797e017a95a44af1dec8d9d0fe18977de5281Virustotal results 19.64% Heodo
2019-02-15830642556657733368.docdoc 5e1e95bbe0fcbd1debbbdfb566674ddb244ce533a66b7476e5f936f5d7e734e9n/a Heodo
2019-02-1545395250399209924732.docdoc 7fead632cfa06762288a63ad80bd0c4117b2731ef976db9aa0e662ab8506d43fn/a Heodo
2019-02-1544664612610.docdoc 5abf0e0ff50beae40763deb3eeb94fc9c8b1b3146fa1d4af4757a2c832a08dccVirustotal results 41.38% Heodo
2019-02-15PAY325309446097571.docdoc b2c737f365bf3786f9633b47b5a6ad178291246a4d5ffacdccdcb82c409d0399Virustotal results 43.86% Heodo
2019-02-15E88272143366.docdoc d3017bf3fef31086400ec840a4d3723960fa5f253645db27cf234b4f79345c6eVirustotal results 39.66% 
2019-02-15PAY64415526007607129674.docdoc ba193225e69c78464bfd795cf91aba262985f7d275828a4b7014af2e9f7e1494Virustotal results 47.37% Heodo
2019-02-15ACC805425539.docdoc 130283482cb1afe672ae27f4be0f4a54059eddc1b8dd3406bad9a7cf46fa92e9Virustotal results 47.37% Heodo
2019-02-158519066887.docdoc 0a63296be569d27f409dd52ab1cac44d5354aae089de3f10812d4ee324cd60faVirustotal results 37.93% Heodo
2019-02-15E31808318512361.docdoc 4180d8687adc9a7377f1da81675b7ad26fd299a3aec263301158d83395d1c249Virustotal results 42.86% Heodo
2019-02-15CCJS781768007089.docdoc db9a1b0df6a3a5243aafb8242fc8066a4b8d874a123b56e10161b7b6cc2b7387Virustotal results 37.93% Heodo
2019-02-15ACC3336654357079885083.docdoc 0b800d68629d09e457b01770eecec25262850047290199e5946098441e93720eVirustotal results 45.61% Heodo
2019-02-1576094030351.docdoc bf2df017031624697f1a3eb18cd8a63352a53b2da30266465216ee56f375df84Virustotal results 42.86% 
2019-02-1571896558848464.docdoc 4d92b58aaf53b74409c96606d43c5317f74392e9656cb6790b2acac4edd1d0f4Virustotal results 35.09% Heodo
2019-02-15US91559409187465.docdoc ef68dc6c49a71cb869bc6a2c1de8232a40fb7383f4cb0ba89e3b191fbbecbc0aVirustotal results 42.11% 
2019-02-15I672458120.docdoc cf7b411657d4645f65f5b0446624f5308e557d01b070c7e86bd3261ec37cbb92Virustotal results 40.74% 
2019-02-14PAY479771769.docdoc b87c6d9d69ea5b2e1007c27fdf3cce675e135aebc269933c59a1d818054c3ec5Virustotal results 23.64% Heodo
2019-02-14Y35509269184322612924.docdoc 64a9cca238ef5a0f0b66bae0ec4737716d3da59fe9033665f043e46dbb38fbden/a 
2019-02-14INSTR978896128327757.docdoc 51876f09ad4a176e3d4cbe9fc7e3a594951d813415b3eea7db9e46a1d50eb4f9Virustotal results 20.00% Heodo
2019-02-14ACC26469132460.docdoc 8684f6a3902e53492c323711ead750c8bc89cfecf275df6dea172dd6ac2496d3Virustotal results 19.64% Heodo
2019-02-14INSTR399018959815.docdoc 8883d9a7d7ff701bd2cbe8a02b9925ca3dfa850859c3be1bca4386637658713dn/a Heodo
2019-02-14INSTR02751811722363.docdoc 2881aab6e692c0525d3d508c89480221759bb26d6a9e5fa56595838efe5db0d8Virustotal results 18.52% Heodo
2019-02-14BJU1886059491229.docdoc 541316a342c2973eb97eeee70a74a023e3f280e2f5f8893979eda15ab55318ffVirustotal results 17.24% Heodo
2019-02-14ACC1263486024402.docdoc 44a43a92eaaf73f061eac4756a945677670642f7036cf4b9b364f7df909e4b2bVirustotal results 17.86% Heodo
2019-02-142919147130508224012.docdoc df153c96c06c400e953a5d568ebbc36a7fdfedcb99baab67f87252150c9457a4Virustotal results 17.54% Heodo
2019-02-14ACC59561210762449.docdoc 82d8ea7296ebb0ab9e0837ad5f4720a3a93873bbdf6c6f1fdfac51a161abd2f9Virustotal results 32.14% Heodo