URLhaus Database

You are currently viewing the URLhaus database entry for http://seabird.com.ph/html5lightbox/e49fc-v1zh9o-zrdsp/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:198938
URL: http://seabird.com.ph/html5lightbox/e49fc-v1zh9o-zrdsp/
URL Status:Offline
Host: seabird.com.ph
Date added:2019-05-20 11:28:05 UTC
Last online:2019-05-30 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-20 13:19:18 UTC to abuse{at}networktransit[dot]net)
Takedown time:9 days, 23 hours, 5 minutes Bad (down since 2019-05-30 12:24:29 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-29073313333450DE_Mai_22_2019.docdoc ed219ca4af7d632aebb303a35c95fd1145abef46978e76d47b0211cd83117d61Virustotal results 71.67% Heodo
2019-05-20Rechnungs_Details_52849968504DE_Mai_20_2019.docdoc 33a4c297c96c8e0221d6ec50d18aa5305dfcc92776eeb60c0d0c19d0ecb13976Virustotal results 18.33% 
2019-05-203985111522DE_Mai_20_2019.docdoc c4548a16dbfbb5fdd5172d70bc93ea07af48b0301ef25ad94b72d4feb16a4488Virustotal results 16.95% Heodo
2019-05-20Scan_211520228171DE_Mai_20_2019.docdoc b0afa6464395b631fb978a358a9e890a9187a88f26975b2f85b84f0db8ea838fVirustotal results 15.25% Heodo
2019-05-2073867131676DE_Mai_20_2019.docdoc 2681fe5afa78ad3ca3edec710e9eb01e50b58c39f35d413415053018b52e04ddVirustotal results 16.95% Heodo
2019-05-20Dokument_6845085030DE_Mai_20_2019.docdoc 0eab3af784eeeaaf4f10c2a98a7dcd2a15c394e02b57c58a1ec271e1de1b70bdVirustotal results 16.67% Heodo
2019-05-20Scan_08538825098DE_Mai_20_2019.docdoc 70815321613db330b58d461f800d0eb271c09bdd10f208bbc01cb82d349d74cbn/a Heodo
2019-05-20Rechnung_822565455524DE_Mai_20_2019.docdoc 4ee136ec6b4ad8365d472457b32c3eef46f3784edab4a3d3ffe20494d6a38f7bn/a Heodo
2019-05-20Dokument_780761415548DE_Mai_20_2019.docdoc ee7eeb0aa1f4c91f1625cf75ed82a745e2b4785d2f9fd6bc181e2cf45dabc6d7Virustotal results 22.95% Heodo
2019-05-20Rech_314995851803DE_Mai_20_2019.docdoc fda0fe2182c97b161f56da2d76e8eb21a39e66483e0419726dcfdc2889c521d4Virustotal results 14.04% Heodo
2019-05-20Rechnungs_Details_5502530300DE_Mai_20_2019.docdoc 281546d6de344a2441e0e834fc955847a0508c912df7e433107a151a3c74fc45Virustotal results 21.31% Heodo