URLhaus Database

You are currently viewing the URLhaus database entry for http://ftp.homes2see.com/mirror/Factura-Venta/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:25070
URL: http://ftp.homes2see.com/mirror/Factura-Venta/
URL Status:Offline
Host: ftp.homes2see.com
Date added:2018-06-28 19:32:13 UTC
Last online:2018-09-07 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-28 19:40:16 UTC to abuse{at}comcast[dot]net)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-29factura-GXI-871474430.docdoc ce6ece4f3586cc2306e1a37543c4b9fe5e8d71271016bc953c6ac87b642ab629Virustotal results 22.03% Heodo
2018-06-29factura-XQX-34657074.docdoc 9ad074c5dbb428c4bf699efee12342afa701a707c1c9f3c3dab9e9abf29cf2f6Virustotal results 20.00% Heodo
2018-06-29FACT-AZS/30363336.docdoc 6864655577a22f5f289b9b8e092d6506909c28dd843438064842bab21947807cVirustotal results 20.34% Heodo
2018-06-29Factura-jun-663/61216463.docdoc 0184bc8a665f0a4aa70fe627dfa674ebe6c5ff27056674986763696d298d21a3n/a Heodo
2018-06-29Factura-jun-355/43246757.docdoc e888c8a6f8384f0987a15741f5a865d4beccb38e460a6d1626ca1972a2656df0Virustotal results 26.67% Heodo
2018-06-28Factura-jun-441/39722533.docdoc 27f47adadba6d9f62e8239c19813f2256a86091af65868d18fe5a122ffdfcc12Virustotal results 18.33% Heodo
2018-06-28factura-OHK-18326473.docdoc a1b27163ca2b7f89956e1c8e80e53ed389b63974437b4a2855f4f478f28a7e5cVirustotal results 18.33% Heodo
2018-06-28FACT-FRD/721613244.docdoc 9d515aba7ecf2ad8026c0f0054d9a665dbf02863a88c3beb9ddf171d76727a1fVirustotal results 18.03% Heodo
2018-06-28factura-KMC-4045066.docdoc 3252d431eef2326a3fbd353a528d3294261f9fec8bd1199dfe4c50f1cf6f8241Virustotal results 18.64% Heodo