URLhaus Database

You are currently viewing the URLhaus database entry for http://www.queaso.be/IRS-Letters-053/6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:21062
URL: http://www.queaso.be/IRS-Letters-053/6/
URL Status:Offline
Host: www.queaso.be
Date added:2018-06-19 23:41:03 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-19 23:45:13 UTC to abuse{at}lcpnet[dot]be)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-20transcript-004834/7.docdoc dc745bbef34c494c1344502aaa66f349097615abb0ec2748f1944673833bd22cVirustotal results 24.14% Heodo
2018-06-20account-transcript-087/176.docdoc ef9296574ae1f8fcea94d03867972f9c2cae555562415a3401c71a46b2a46f87n/a Heodo
2018-06-20tax-transcript-026-92124.docdoc f70d253b89d41d92211f95346b82cc475a5a518521e94a1a12d4ac0a9520d51aVirustotal results 28.81% Heodo
2018-06-20account-transcript-021T1743/21.docdoc d5fa277192228171e711c082a39770c765e06e493d79fb6d42b7e9a2c001c1fdn/a Heodo
2018-06-20tax-transcript-08/261.docdoc 8864996c9486742fad98fb3e8d4580c12cbf2aa20f3674b1c0c4eddba7d22324Virustotal results 28.33% Heodo
2018-06-20transcript-044-84702.docdoc ee29313d5c237645dbbc3808a97a52364466ad64450c73ae49bb3168f92dd359Virustotal results 30.00% Heodo
2018-06-20transcript-07N841/3.docdoc 05a2e3eeb89767c84fb0e92c97bfaf7f0d28cec8e9a70286ec5082b59fbd37d4Virustotal results 28.33% Heodo
2018-06-20transcript-056Q9327/44.docdoc 7581d8d9eae958ec7e3cf465ae65baaa2d23b75f6de0e879549c229df2b6a5faVirustotal results 28.81% Heodo
2018-06-20tax-transcript-07E112/4.docdoc 0e1a166ad702d904352e73bdcd2d036c44e83b0094cd6d06454f3096b834e875Virustotal results 28.81% Heodo
2018-06-20transcript-00/248.docdoc f28a5312c2803b92cca7c028e286220c2d316212a90dafe0314c05b04fdcbbb6Virustotal results 28.33% Heodo
2018-06-19tax-transcript-00404/31.docdoc f0e56c2957e35958ecf4da7fadf186142254f19420ef09233586e22b6f3778ebVirustotal results 25.42% Heodo