URLhaus Database

You are currently viewing the URLhaus database entry for http://houseofbluez.biz/vt/myrhx-wrxelpq-aecw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:182628
URL: http://houseofbluez.biz/vt/myrhx-wrxelpq-aecw/
URL Status:Offline
Host: houseofbluez.biz
Date added:2019-04-23 05:48:04 UTC
Last online:2019-04-23 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-23 05:50:05 UTC to abuse{at}dimenoc[dot]com)
Takedown time:16 hours, 6 minutes Good (down since 2019-04-23 21:56:32 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-237124029084DE_April_24_2019.zipzip c7ab91d32ad2cbab263e84c85486a7218be14006c2d0976e873a12ed21dffbf6n/a 
2019-04-23104827282446DE_April_23_2019.zipzip 5b3c6ae0b534a872e6d59f67255ece82b3ed0d4ae299757cab219fd8d98a3ba9n/a 
2019-04-23817388031783DE_April_23_2019.zipzip f99a26bf3f08cb00d15448ec5d8e7b4f63c068f5a614d994f8a1d3802e9a4745n/a 
2019-04-23242156769262DE_April_23_2019.zipzip 0cba8e4bc26a204a56198ea3cf2b2f4a2ec9e3e8cb262581f4714fc6af36c4a3n/a 
2019-04-23105598624848DE_April_23_2019.zipzip 272f7d28c29697dde38e4319550d17dfb5f726504675e443db50de410d1b8922n/a 
2019-04-239672835220DE_April_23_2019.zipzip cfbd8d7341d1828451e520b085306e8bd68f2c173c14f112c6fabac3326b994en/a 
2019-04-234789128608DE_April_23_2019.zipzip c45a8d8b4dbcc16d09ee710220101933e617c7d86f839716ebcf4227c9327a8cn/a 
2019-04-238811718535DE_April_23_2019.zipzip 0b54f5411dd1e80c93fbf3e23a479cfdc2647cad3e9b9eeb178dbc59b37e1286n/a 
2019-04-234369366548DE_April_23_2019.zipzip fa3dc2fb576ab525655cdd7b0e68160e2bd9e7002bc89cd445acf89cb27203b6n/a 
2019-04-230684783616DE_April_23_2019.docdoc 24cf2ab0d94eefc1e250cda59f79f3315a2a42564e07def2f8f1bfe4e937db2eVirustotal results 32.20% Heodo
2019-04-2386028467623DE_April_23_2019.docdoc 1c65c0215346a85601fda399fb4a9ef9b8ccd842ade60d00e203d595a92ee259Virustotal results 30.51% Heodo
2019-04-230677258570DE_April_23_2019.docdoc f6d327e2c36bf45b3d4875ab3663fb0370ceaeab1bd3ed66146ac15934764af7n/a Heodo
2019-04-23259435249443DE_April_23_2019.docdoc 03d471048561df5ca748a9cbb38b424eb5ae4910faebee09b8182c96dfbc37adVirustotal results 31.58% 
2019-04-2336180205535DE_April_23_2019.docdoc f5a6ffb607acd20063ae377d9fec4eb7e711e901ab55a70d05e3027f7173cbeaVirustotal results 31.58% Heodo
2019-04-2392059243098DE_April_23_2019.docdoc da4dfeeea62db89fff33cc53d8e40375c5002c4c98d57d6a1ed7cd4a8a6c655dn/a Heodo
2019-04-23157155365900DE_April_23_2019.docdoc 48c186204c7f7ddec825e8853569ac42ee5f374e0c6a3e01ece52bb24b94381fVirustotal results 31.67% Heodo
2019-04-23604944590995DE_April_23_2019.docdoc 44c89fcfe2b096c7e98f7ade38c8425c043de5f52011f2bd516a127ac21e786eVirustotal results 31.67% Heodo
2019-04-238876566379DE_April_23_2019.docdoc a5b79368dec93d883473c35f7fdfc6edc120b75892906fcd525b685b0df06c9fVirustotal results 30.51% Heodo
2019-04-232476119586DE_April_23_2019.docdoc 2195cee5fa989ab82bd3d8b22f61716ffdabce020a3fe562bdf8aea45dc3c913Virustotal results 30.36% 
2019-04-23339048602589DE_April_23_2019.zipzip 5f78f640712983c77a7b120ba225789606273020a065aebbfeb205878e024517n/a 
2019-04-23042082137200DE_April_23_2019.zipzip bbc7ceb5d2b4b1b49f1dd052e6cf3451735e8c284b82ff34b39308d204552a0an/a 
2019-04-237573752271DE_April_23_2019.zipzip 55c7ca1e5c6a07a25cd1269c5d72d1aa9f966a51339aa9066fcd3d2eba1ebe6en/a 
2019-04-238479883704DE_April_23_2019.zipzip 9aaa216441327941f8d0d4362f9275cb511db31f3550375d6d2f64a0f6f1acd9n/a 
2019-04-234628769383DE_April_23_2019.zipzip 185e8fce28ee36a5f94e117b0c24e19758a49873bbef8f5052d5bb3e0caafcfcn/a