URLhaus Database

You are currently viewing the URLhaus database entry for http://cflaval.org/quiSommesNous/u1hts-mxde0-yudrr.view/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:156918
URL: http://cflaval.org/quiSommesNous/u1hts-mxde0-yudrr.view/
URL Status:Offline
Host: cflaval.org
Date added:2019-03-12 09:12:23 UTC
Last online:2019-03-12 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2019-03-12 09:14:10 UTC to abuse{at}ovh[dot]net)
Takedown time:11 hours, 0 minutes Good (down since 2019-03-12 20:14:38 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-12RQ779665020305402.docdoc 001237033e35334dfaac1419dab32a086bd29456f8a58d4c301e31be86540b6cVirustotal results 23.73% Heodo
2019-03-12US028316892847965.docdoc d8a2eabf0d5286c78297fac24798458c99250c41ce64e22dba5ec3ab6418a7deVirustotal results 22.41% Heodo
2019-03-12PAY792592040.docdoc f08d0e73c57f41ce301cd6f79c2da738c7bd4e65a9aa46d19affb454f54e863cVirustotal results 21.82% Heodo
2019-03-12US752006180.docdoc 0ab092e093616ecab1627b90cbbc9fe0aa2d295ac5188ce440a8714bcad66634Virustotal results 21.82% Heodo
2019-03-12US915884992560327.docdoc c0ccb64d0d66e42334be0247a4c12062099cfd39a2651e38242c76169601390cVirustotal results 21.43% Heodo
2019-03-12PAY5283131903391112.docdoc c31690d76f1cc046c8dbca819e6173699f2c8b6d03f532e8a4c90d13ef268b9cVirustotal results 21.82% Heodo
2019-03-12INSTR54396565556298661741.docdoc b6c0a75b1280dd885a3c20db39f80ca390e6fd9937e648216f5050528b50a2a4Virustotal results 22.22% Heodo
2019-03-12ACC3270502025013646.docdoc e3af5d9186e98f7e7fcfceb13d38a4f37fe799a0203dee369e1c08ccc66be979Virustotal results 28.81% Heodo
2019-03-1236573542566603412.docdoc f3ec9ec1409dae4afe28cab0f7a39674a9c41d444d2666ae67b4348f1f17c344Virustotal results 29.09% Heodo
2019-03-12INSTR4306203765.docdoc c73098e10c39bf29628b0a390a42d935bbffbd9b783a3aaffef778a7c0f58197Virustotal results 29.31% Heodo
2019-03-12ACC25540216852.docdoc 55d1f4109d124397b061da807dca77739d0006eabd6dfad3093ff73cbff617afn/a Heodo
2019-03-12XUVN8309919505.docdoc 2af7895b50a3fa44ad63b57ab9400cc00d685ac93828f21b24c0764b9dc82b4cVirustotal results 21.43% Heodo
2019-03-12PAY62207015945411337.docdoc c030c1d45f1b79d13bde148fc27a69b0b2c82e7102cf2e70a81fc42ccb244777Virustotal results 27.59% Heodo
2019-03-12INSTR0390067871851.docdoc fe02929a2dfe359e67d944437755f220665befbe81b0003100cc8fd5ba73c9e4Virustotal results 25.86% Heodo
2019-03-12INSTR9423268785820.docdoc ed23427d6fc3cfad3f0604c197ddd550b48d11f827e0522b2ea29dca1d8dc73cVirustotal results 26.32% Heodo
2019-03-12XPSUG6118453599642281772.docdoc 1b722f3258bd814b1b741fd29637800522dad879c69529d6f546139ae44cf5aaVirustotal results 23.21% Heodo
2019-03-12INSTR25637120165281395.docdoc b6a078ab28ff7aba221ac6141081296e4a1e3186d7a8c34ab2d6f2ea7fb99f15Virustotal results 25.00% Heodo
2019-03-121644927636582784.docdoc 29c37bc222a6429b5d2c518e9477a5b3adf5d3be4d965402ea419bb05c9c8f91Virustotal results 25.00% Heodo
2019-03-12PAY962935819397874.docdoc 3e42ccf761e85a28ea39a33a33f988253a4ad767626790e2fffb04a6e19d719fn/a Heodo
2019-03-12INSTR742857613.docdoc 1889486704979eb152fb0fab692fbc4c9b25eb5821fc889c55f7de45af825d43n/a Heodo
2019-03-12ACC3959548924023.docdoc 7cc9f9a665aab99b13b5eec6c61a5f2fb49d0968932ec2663d17638b672fda7eVirustotal results 25.45% Heodo
2019-03-1299326560962346201861.docdoc 8381975e6fdbfa058b0b917d563333bbe8fe9a32964dc74795d95848adda6059n/a Heodo