URLhaus Database

You are currently viewing the URLhaus database entry for https://ramun.ch/bbq/esp/umZsbobvaPlRLyqqeIy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:203569
URL: https://ramun.ch/bbq/esp/umZsbobvaPlRLyqqeIy/
URL Status:Offline
Host: ramun.ch
Date added:2019-05-29 17:20:04 UTC
Last online:2019-05-30 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-29 17:22:04 UTC to abuse{at}tierpoint[dot]com)
Takedown time:1 day, 1 hours, 58 minutes Poor (down since 2019-05-30 19:20:30 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-30Document_362521266720US_May_30_2019.docdoc 70b6d041f2b2be97e5fb0986bcfe40882c2f567e20b2c5d8dc9328f718293ce2Virustotal results 33.33%Heodo
2019-05-30FILE_0750880256US_May_30_2019.docdoc ff60d17aee6a178f5d9506325bbece194f115bd4e8e16eabab54796247372617Virustotal results 30.00% Heodo
2019-05-30SCAN_35540886399US_May_30_2019.docdoc 2b705178a0a15e634c582853d6b8794f72f80f76cbcaa1105b6ea3d25febba3cVirustotal results 28.33% Heodo
2019-05-30DOC_9407763903US_May_30_2019.docdoc 9e0813a45e8e949ce8b813e8559018d0b4236780d78faa9996362d0097327983Virustotal results 28.33% Heodo
2019-05-30FILE_3793288962US_May_30_2019.docdoc 380bc34ae6bcee0b78b3c7a7fa35b93f56a83669c38c3acff66b18956ca40be3Virustotal results 28.33% Heodo
2019-05-30LLC_0540801321US_May_30_2019.docdoc 8243d585376feab2066db0a0adb3a4fc1522d21be3b51c99683ea2d8d910c1d6Virustotal results 28.33% 
2019-05-30Document_291600660357US_May_30_2019.docdoc 743bb6f03307fbcb5878e462019a6d417299c7b313ba0c201256038bd11d53dcVirustotal results 26.32% Heodo
2019-05-30INC_58736305278US_May_30_2019.docdoc 19b57a0733c66849a89e61ba18c031e2e3529bee49dbbfeb64cf614ade70aefaVirustotal results 25.00% Heodo
2019-05-30FILE_0241881514US_May_30_2019.docdoc e9f94b310253d5dd1e7db1bab6bc2b612d91967b04b10a73dca0613905bb690dVirustotal results 27.12% Heodo
2019-05-30DOC_2583587861US_May_30_2019.docdoc a6de48d770963d4712ba096c29dd64e887e16771109fa75f1fb4c9feb2f66dc5Virustotal results 23.73% 
2019-05-30Document_6966980942US_May_30_2019.docdoc 476e2c9864524e7613926fd0411439c0e18162065c4448d14b254491525d7f44Virustotal results 25.42% Heodo
2019-05-30SCAN_43833579222US_May_30_2019.docdoc 05aad39628f200ae651d034b8c609c0f1059aaf24d91203eac3059c72d5c7a3bVirustotal results 28.33% Heodo
2019-05-30INC_79278277665US_May_30_2019.docdoc 7953d886e1cbfff3c3a9a0870cdc37c5a89a134f1a99d8ab85784bd18bcc1661Virustotal results 45.00% 
2019-05-30DOC_3480074629US_May_30_2019.docdoc 517ead09a95c0042ae364b668bd8568b6dc06edb01b4e52e38e88fd0d4e83394Virustotal results 44.83% Heodo
2019-05-30DOC_8062357704US_May_30_2019.docdoc 29de9d50aa76455f1f7e7f4ff35ed5b53170231dc965f77d1c8938b4db8b5f4bVirustotal results 45.00% Heodo
2019-05-30Document_27098799567US_May_30_2019.docdoc a80ef402bca0511250912bd1b8b67e1d234cfc80a28abfe20546fa017ff7b5dfVirustotal results 45.00% Heodo
2019-05-30SCAN_7140061526US_May_30_2019.docdoc 19e7d25532ecbedb271be911eec224979a835324361fdde38882d397b9f63af3Virustotal results 44.26% Heodo
2019-05-30Document_525574657862US_May_30_2019.docdoc f5b34b067c6114672981014429bd672bbe054c9a8f0b60d0bd6ed704e20de146Virustotal results 45.76% Heodo
2019-05-30DOC_42904367950US_May_30_2019.docdoc 076e6a2e725a459e96ac4b7eed109a308e89b21fab77cecd5bca6fa349d11d7dVirustotal results 45.00% 
2019-05-30Document_3362986444US_May_30_2019.docdoc 0e56b2fdf81e7458a521fb26b9a47a6fa2976d0c971cdf823d5bb5293d19c4cdVirustotal results 45.76% Heodo
2019-05-30INC_2820284706US_May_30_2019.docdoc 90769c702b9dcc0c672e6b08382cedb354baf72bc920ef777040f98b5c5f7049Virustotal results 45.76% Heodo
2019-05-29DOC_287293948768US_May_30_2019.docdoc 4e4fc97261a1040772783653956f7974be6e71666561221b9e1a47e5c5e51548Virustotal results 40.98% Heodo
2019-05-29DOC_469151525534US_May_30_2019.docdoc 7b68db429bbb2c184ed0cf44e6eebdc616bebde08f31ec2cb3f0256c3090f2fcVirustotal results 45.76% Heodo
2019-05-29SCAN_250222098484US_May_30_2019.docdoc 6742a93ad7dd9523c2c6c6910ce8051116a6ed81ffca82add07f46bfdbd07532Virustotal results 44.44% 
2019-05-29LLC_39727810872US_May_30_2019.docdoc d7ebd801f1e1696f3f7f0969cab9049595b41b978bde29913095e14a0613be47Virustotal results 43.10% 
2019-05-29DOC_902042979466US_May_29_2019.docdoc fc2800ea95b3ea98d494a50794e6e89684e3707f20fa18e75dad94c8851f9c7bVirustotal results 40.00% Heodo
2019-05-29LLC_094186751979US_May_29_2019.docdoc fb5133d4022266ba87e2fa79c07b881a634e95e213f9888c269c20943f8ae97eVirustotal results 35.59% Heodo
2019-05-29SCAN_721893590199US_May_29_2019.docdoc 0b8668d6728b7de9d9f490dfbf41977740f44be0ba9190c79f008458bd5f4366Virustotal results 29.31% Heodo
2019-05-29FILE_7394666690US_May_29_2019.docdoc 82e4b14dd3b87ea43c6765588ebe9db8f1e84ba5fec5d180cc33794b4bc6ee04Virustotal results 29.31% Heodo
2019-05-29INC_115618718861US_May_29_2019.docdoc 8e2fbbfb86f8c74d7e50f8c14a430521852fc8ad4ee2452a00983368ba961ea1Virustotal results 30.00% Heodo
2019-05-29FILE_2315286442US_May_29_2019.docdoc 6c3732769b4aa9de80935b5ccf8120aaf63cbc3838915dc58fe51d1d6be4f75cVirustotal results 28.33% Heodo