URLhaus Database

You are currently viewing the URLhaus database entry for http://yucatan.ws/cgi-bin/DOC/5ELzR1tzjFq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:188161
URL: http://yucatan.ws/cgi-bin/DOC/5ELzR1tzjFq/
URL Status:Offline
Host: yucatan.ws
Date added:2019-04-30 18:15:05 UTC
Last online:2019-05-21 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-04-30 18:16:06 UTC to noc{at}perfectip[dot]net)
Takedown time:20 days, 11 hours, 24 minutes Bad (down since 2019-05-21 05:40:38 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-02Document_23840428256US_May_02_2019.docdoc 0b1310aa7bb2e7465a222a04326079ef48b0c163b96e95a1860e79666b479b7cVirustotal results 32.79% Heodo
2019-05-02Document_6770317253US_May_02_2019.docdoc 5a065c412c5ca5029a12a0c5bb8fc9ea3fbe72f7b3a89fa7fbaede2f06ae8185n/a 
2019-05-02LLC_00455186936US_May_02_2019.docdoc 0aba359f77ac576510a26b160b60e4b0bc470db5ec0341e64234681ec8c607c1Virustotal results 34.43% 
2019-05-02LLC_8481000509US_May_02_2019.docdoc ca014e6230918cfcc607b656e4d58d48a11f073abd1be05dbf3c5fd93c20bd5dVirustotal results 26.67% Heodo
2019-05-02SCAN_75469106398US_May_02_2019.docdoc 6fd96bc05d0194613f21bd6315bfbf2d6e4606b291ab673209ebd70ce801b5c1Virustotal results 27.87% Heodo
2019-05-02LLC_215534854481US_May_02_2019.docdoc 61363331b4ed5c211a5108f4820e0e7b31451bb9fb50da87d537b88e01159528Virustotal results 28.33% Heodo
2019-05-02FILE_1019418892US_May_02_2019.docdoc 5df383f04feac1ecc7ff1cda2e577d97e612db6ded6d2d33830eaaa3fc0d569eVirustotal results 27.87% 
2019-05-02INC_544428722241US_May_02_2019.docdoc 94f9a3e8cb648efb537b8a9a1e4510d286b80f06b04a72ad3ef9c4c474bcf810n/a Heodo
2019-05-02DOC_6408345135US_May_02_2019.docdoc d208f3eff68d5739131aeb2b16c66c1b6afb8fae27517f1b7b9029d4ef8b1ce2Virustotal results 32.26% 
2019-05-02INC_7565133545US_May_02_2019.docdoc 71f892530436e11f487144a6a0938fbca4ee47850fa221ca6518d6c2f9e4c837Virustotal results 30.00% Heodo
2019-05-02SCAN_469624064495US_May_02_2019.docdoc b0ac55a9a3533916702fcb365a321abaf4990b73459a2fd1a32a3378cda957edVirustotal results 32.26% Heodo
2019-05-02Document_92303004543US_May_02_2019.docdoc c4bb3c6de8d16d8d68841fd2fd8230fb13d8f7c51feaced318d5f41c78f15da1n/a Heodo
2019-05-02SCAN_6643903481US_May_02_2019.docdoc 195a1fb436c1c7497259f18d4332423f886a38242d824dfc498ee40625ab82c5Virustotal results 30.00% 
2019-05-02LLC_281394283894US_May_02_2019.docdoc 7f1c516c36a737bf48d2ec5556e1e3232d47994d94c10675f7c00ba10b04aa00Virustotal results 30.00% Heodo
2019-05-02FILE_9360015577US_May_02_2019.docdoc 17f4ae8fba484e7fb87c16216ece4622556d70db4d807d8b0a4ac207eba7d015Virustotal results 35.00% Heodo
2019-05-02DOC_37746566150US_May_02_2019.docdoc 8849cbdb89ef44865f23e8745eee176d529ca564c20c66da99aa5c04db555ec3Virustotal results 35.00% Heodo
2019-05-02FILE_2132288629US_May_02_2019.docdoc e39ace0837155e85d59f5059bfe202ba3de02a88c848a6067c9965cadb79c5aeVirustotal results 36.67% Heodo
2019-05-02DOC_474754278488US_May_02_2019.docdoc 4208aa9b2a8e40195be3444efc9bc9cd2accf732b249c921025207feb62a0970Virustotal results 34.43% 
2019-05-01LLC_1713805739US_May_02_2019.docdoc 07ad82ee6f552024b89e9569759078672295762694af017f35f64bb7284b93c3Virustotal results 35.00% Heodo
2019-05-01Document_38323283333US_May_02_2019.docdoc 438757f58f956c0bf3c4d88c3270f25c6bef6cc6c7599d01e2050871e1c7ccedVirustotal results 32.79% Heodo
2019-05-01SCAN_4231128574US_May_02_2019.docdoc c0d56c06f445e3284464894bb9855dac7036a7f5e0da7183ad31c6d0c2477db2Virustotal results 32.79% 
2019-05-01LLC_7850376616US_May_02_2019.docdoc 8e56b9601576954a6830441430cdbf339831df28e8b6a4c29fa76471d83594ceVirustotal results 31.67% Heodo
2019-05-01Document_15779711818US_May_01_2019.docdoc 811f6ec9cc7105d1b81e5352a0b9f90df420a293afc43ba91507952e7cb49f72Virustotal results 33.33% Heodo
2019-05-01FILE_80103179466US_May_01_2019.docdoc 72f28f83d17f71068693f8f34ea40d09dc75d111635427f1b58fa9d4cad29558Virustotal results 32.79% Heodo
2019-05-01Document_38546644780US_May_01_2019.docdoc 3b338a2b75997eba6f9666aaea6f422da3e38754657f4be7f7e0e9967c479a63Virustotal results 31.15% 
2019-05-01LLC_8441224379US_May_01_2019.docdoc 60fef10a83e873748b44cf932f3e0fa0a0d891f414e591696daeefc00f0d01c9Virustotal results 31.67% Heodo
2019-05-01Document_25671688147US_May_01_2019.docdoc dc49d2d7421719050d62368d665c84629bb08d6874ade0bb8940f133b619d9aeVirustotal results 31.67% Heodo
2019-05-01DOC_6195334447US_May_01_2019.docdoc 2ade167cc02b318750feb789c0476581e4f2e0864c3a51fd65bd74c25534a74eVirustotal results 33.33% Heodo
2019-05-01SCAN_765698353112US_May_01_2019.docdoc 1a6641086b78035d6c9ba38c7199aac02d37dafbadf96059a81b6f4c35e49f84Virustotal results 26.67% Heodo
2019-05-01Document_85834788260US_May_01_2019.docdoc 68e686c3f2b87d3169766ffe4bba021a8acd7648ca38c6c75be829a864558ecbVirustotal results 26.23% 
2019-05-01Document_18753161590US_May_01_2019.docdoc 42981d37b50801d5cdc23d5d9f0a1e0e20f3787e24c4d20f606d2250ce5bf804Virustotal results 26.67% Heodo
2019-05-01Document_778126089534US_May_01_2019.docdoc 6f926261cf70832a6f3332c727eb674da29212109a968a25cab4cb92fced7694Virustotal results 25.86% Heodo
2019-05-01SCAN_84625778218US_May_01_2019.zipzip 970ebd639c5450fcedd81a23e6221668f8d10894023b2a19cc9889e89cfebd07n/a 
2019-05-01LLC_4186821112US_May_01_2019.zipzip c2f0dcb140e2249daa3cca64a81632508557fc53dd1cfe04313e49446231ebb2n/a 
2019-05-01FILE_34866325758US_May_01_2019.zipzip e7d68c6ab9a78414b008207a35da56c9258a7246a06f8e46055727a5535f4f96n/a 
2019-05-01INC_638512812897US_May_01_2019.zipzip 462c4ad418982ba02cabaa565fced084ece04c6553a55ee13fb4cd59342c363bn/a 
2019-05-01LLC_365334995543US_May_01_2019.zipzip 552d46512cf9d510aec7cad45afa34f740dbeeac1073b3bc16083f5e02c8b8c1n/a 
2019-05-01Document_8216343141US_May_01_2019.zipzip 49983e6d640d6d191e36ec2e565cf3f165a55643ce2a983d2ceff5e4163ba47dn/a 
2019-05-01LLC_28547730826US_May_01_2019.zipzip 9f158074af6890f9223b8abe7712ede9a18f302c55d93403a647fac70fa9b985n/a 
2019-05-01LLC_55478452635US_May_01_2019.zipzip c85169ea98c83ab8b2af0a818e34747db73e2b070635d01d18619bedcd611745n/a 
2019-05-01FILE_975045660998US_May_01_2019.zipzip 683d602023fc321678ae1011a3961d246bb7ad00cf1f525dcc613b658855959dn/a 
2019-05-01DOC_189706360131US_May_01_2019.zipzip 81491ba56fa66afdf50b517badc99fdba8bb253da86f5c2eeb09d5e6ea228fc4n/a 
2019-05-01INC_4140935552US_May_01_2019.zipzip fd6ee264810a918944746cc82c44bcd23337266701d39b1f4f87d649a7956d21n/a 
2019-05-01FILE_6005622299US_May_01_2019.zipzip 5da3a96f0b27d8b7d6dac93d1abbe18fbf0aa292a7c5d291cdc35671d8368749n/a 
2019-05-01DOC_4136932049US_May_01_2019.zipzip 05b185ebfad951cfcd6a18c647c8574911780f7da792f9d7430d59c6f473b174n/a 
2019-05-01DOC_388305210268US_May_01_2019.zipzip a8369caed1e53fb32420e728eca9039a8e858450119424e722c858c9c4635df9n/a 
2019-05-01DOC_408922057569US_May_01_2019.zipzip 73990a318aa9282dbaa027cc65014d9a648f761d51eb77f74f501d40ca3b825bn/a 
2019-05-01DOC_367863557363US_May_01_2019.zipzip 9c96191c73e5768771a59c0b34b900296c309c9ce7c45c764e71171c4a4a233en/a 
2019-05-01LLC_4648244189US_May_01_2019.zipzip a80e3de574574d3c152de85763919dc354432f2c9b0984adbe54a75fa8a0bb7en/a 
2019-05-01LLC_20127401713US_May_01_2019.zipzip 4451f7058e77652b15cf73715a65d00e22f4c6f3ec4daba1b068f3a514c8e8c1n/a 
2019-05-01FILE_738083554179US_May_01_2019.zipzip 6cc750c76ff63fd8f84ec0694ab4d5c4257e36a55a0fa6b47f6a303a88640b1bn/a 
2019-05-01FILE_53642476551US_May_01_2019.zipzip ea744e26dce46d9dcd02a5b5e3fe41497b81ae83475504852d852941fe00464dn/a 
2019-04-30DOC_89183483239US_May_01_2019.zipzip 3ab658142e441e33054ac69f041d3902084a1624cdbf28d9ae696ea3a1fccd08n/a 
2019-04-30LLC_244711388481US_May_01_2019.zipzip d797f7ca3990399577f138431a77a90dda526d5e211e3f1fdbb599139804c56an/a 
2019-04-30INC_0907219933US_May_01_2019.zipzip b87ccd31ea199193134baa5f40f3dd9bc2e0fc0e60c2526c0d14de527e6ad343n/a 
2019-04-30SCAN_666902927235US_May_01_2019.zipzip cf70b8a4eafc5504500a95c114281c2b53db8ad61e3cf14ad4352ca847e61727n/a 
2019-04-30DOC_496035621844US_May_01_2019.zipzip b22c381283ff257474a4f726b4850a052164ed9f70f50820caf65392ea34bed7n/a 
2019-04-30DOC_2430129421US_Apr_30_2019.zipzip 831c6ebce5f2eec58b1ec145fa59b333ba7ea3654ab331ab35e4bfc246e6da70n/a 
2019-04-30SCAN_3660084416US_Apr_30_2019.zipzip 0afd4c802b22e89c0157f020067ed9bbb6446769953007fcc0bb92f4fc0af00cn/a 
2019-04-30SCAN_117476678734US_Apr_30_2019.docdoc 8430c4680ac5779d052836f9fbdbdb6a9809d1eb8c62246036e89c5c919312dbVirustotal results 48.33% Heodo
2019-04-30LLC_9552614213US_Apr_30_2019.docdoc 026a3e3fa8543fcd8e57a4c32a90a87e41938dd8a27b2ef685b7d89303667f3dVirustotal results 48.33%