URLhaus Database

You are currently viewing the URLhaus database entry for http://santafetails.com/UPS_FR-04/06/2018-012R/31/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:14765
URL: http://santafetails.com/UPS_FR-04/06/2018-012R/31/
URL Status:Offline
Host: santafetails.com
Date added:2018-06-04 07:14:17 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2018-06-11 10:29:55 UTC to postmaster{at}myhostcenter[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-06Facture-impayee#05-4798.docdoc 2bf857edaff236b0b89e9e41bd3105ac4bcf44a47cb24c27bfaef2b402b0be8fVirustotal results 30.00% Heodo
2018-06-05Facturation#03-2565.docdoc 3e1104205778d2e06154efae7b26b2e665292b45860aadbd5050874d4ce88c32Virustotal results 23.73% Heodo
2018-06-05Notification-de-facture-06-juin-0175086.docdoc 0e2122fb15f833766d78a52c9374ed30e90f557e608c270063be5b5172d39d59Virustotal results 35.59% Heodo
2018-06-05Votre-facture-Nr.031340.docdoc e4c2fe61344da7f72e1d869e2958280f69f9eefc0b56b26effc63039981aa38fVirustotal results 36.67% Heodo
2018-06-05Facturation-Nr.040554.docdoc c7fd6d2dc4035b538015b130fd9e79a539097dc024193ebd71d23ced4661fd9eVirustotal results 36.67% Heodo
2018-06-05Fact-05/06/2018-05933-62.docdoc 5c2ea841aa113939aca637de690e296e08c0a39c79f40ce4c814951968686112Virustotal results 26.67% Heodo
2018-06-05Facturation-05/06/2018-Nr.059983.docdoc 1a67e07d2c59fb9e6ae6c2262ffc7416ca661de7aa54f648816554b033bfb289Virustotal results 28.81% Heodo
2018-06-05MODIF-FACTURE-081325.docdoc 6deeaa4b82b75ea137eb1ccaab3deee2e3e8c2fdcf28a3ed536c39fb7e4c3541n/a Heodo
2018-06-05Votre-facture-013965.docdoc a93a1cf204e2f16476871af0b1168139825499cb5dae3299fd43fb8c14753cf7Virustotal results 23.33% Heodo
2018-06-05Vos-factures-impayees-05610-83.docdoc f03329889e67608014f99c496229d2e978c3ce10aabdacf4ee1d9b2e841eb27cVirustotal results 25.42% Heodo
2018-06-05Factures-Nr.0211810.docdoc f081801c8373cf99f816ca2c9b9e00d3aeee512e69a018653621d8237d15554eVirustotal results 23.33% Heodo
2018-06-05Votre-facture-05/06/2018-Nr.0877757.docdoc e8cdf5e3d806ebaefd77b33fe8990be7da51bb00ff5ffb10bf2fc96bfaa9a136n/a Heodo
2018-06-05Factures-05/06/2018-Nr.0743013.docdoc c44a4ff9755338dd3586a08b530292acbf3596ef70ca6542370ab8fbb81d3a12Virustotal results 23.73% Heodo
2018-06-05Facture-impayee-05-juin-Nr.0849198.docdoc 21e99217450650f899f0a9e7aa4bb5e81a008203861f01fba53b4e4195844e87Virustotal results 23.33% Heodo
2018-06-05Facturation-009498.docdoc a645dfcbb18e44f62284f0516316bd65cc0814cd2525094b516881aaf371a527n/a Heodo
2018-06-05Facturation#008-4451.docdoc 9f4b86a8fbfe57b0bff3054b7b2120935e72aa1c04556b6e3c667908e834d321Virustotal results 23.33% Heodo
2018-06-05Facture-impayee-Nr.082283.docdoc 53a061cd02df1c3a1d6fc31bf307aab36fae590ce19fa4e77b70900d034940a9Virustotal results 21.67% Heodo
2018-06-04Facturation-Nr.0924389.docdoc 618c15494cd0770e651dc95b334c5d0419ed967c914a20543a02f158fb68829bVirustotal results 25.00% Heodo
2018-06-04MODIF-FACTURE-04/06/2018-0441383.docdoc ccbc85029fecf14768acc6bea9c201e9ae77e9176aed835cf002bbc11747c138n/a Heodo
2018-06-04ups-facture-08-6506.docdoc 857926085eb624f0991b36422feb8c8a1d8876db9fe13dbec7430437faf862bbVirustotal results 18.64% Heodo
2018-06-04ups-fact-04-juin-005W027/4.docdoc 1e21e3730747fe1a72d723fa575600b40c55118fbf5b30e2858c0d6dfcb98798Virustotal results 15.52% Heodo