URLhaus Database

You are currently viewing the URLhaus database entry for http://www.clinicacrecer.com/language/Document/3ekcjwz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:266853
URL: http://www.clinicacrecer.com/language/Document/3ekcjwz/
URL Status:Offline
Host: www.clinicacrecer.com
Date added:2019-12-11 09:29:06 UTC
Last online:2019-12-12 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-11 09:30:03 UTC to ipadmin{at}colombiahosting[dot]com[dot]co,abuse{at}colombiahosting[dot]com[dot]co)
Takedown time:1 day, 4 hours, 45 minutes Poor (down since 2019-12-12 14:15:29 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-12REP_PO_ 12122019EX.docdoc 0b965425faade68933db02bccca34ef37ce1911c7cbaa10b8a3dfb960b705a92Virustotal results 35.00% Heodo
2019-12-12QHH_120119_EEW_121219.docdoc 281353f5be1adab4b3bd5be93b4397edae5d9fc5a5595fa72dbf0d7967606d61Virustotal results 31.67% 
2019-12-12REP_PO_ 12122019EX.docdoc 82530e43beb901de5fd2bc9f3bb07261167734a25e36b77420cc31cb6e13cc1fVirustotal results 30.51% Heodo
2019-12-12DOC_88615358.docdoc cd9fafbae1765254701fe1ed8e741e933871c9982e881a17fca79bd8c40d8dcen/a 
2019-12-12DOC_J269XD8Y0.docdoc 4f70a7bfe9ee741ef85de95bf2f83878379fa30cfa6245a1b1049e68eadb7cdaVirustotal results 27.87% Heodo
2019-12-12FILE_PO_ 12122019EX.docdoc 15d655db81abf803aa22bb3129e3f12caac4a096d6ccd5965016154ee7676293n/a 
2019-12-12J_NP1388725514NZ.docdoc 4721a8055b657c23bd15975b8e48f48b896edb566b8ea44c7709df8967972522Virustotal results 41.94% Heodo
2019-12-12REP_PO_ 12122019EX.docdoc a7feb13fcde7026f34f534d7cba0254dbaa73cd900db12319766d6eccbfd0ed0Virustotal results 44.26% Heodo
2019-12-12DOC_PO_ 12122019EX.docdoc 3292c4956d982de5eef4cd373fd0ecc1d828837ee3c25d57e418bd06a64e6f6dVirustotal results 41.67% 
2019-12-12FT7597011063MH.docdoc e0fd2fdc26869f285127622c05a135f251e83e589e2567e1aea88c55c4bb2723Virustotal results 42.62% Heodo
2019-12-11C_ZBX_120119_PNL_121219.docdoc ba8a46dbbb037ccf3e0a61a8586f83dab16705872f382c5535d25789f4bfa0cdVirustotal results 42.62% Heodo
2019-12-1198541174452916.docdoc 85118d674a99c1775c9710cec5e80f0a336484100c6be9208a129f8b60d017f4Virustotal results 42.62% Heodo
2019-12-11Z_DBC_120119_FFJ_121119.docdoc 037fe92dfc94de04f3746bb987b3a4804a340f1be8f732f298ab99560a650fa7n/a 
2019-12-11OGV_FSHTF4S.docdoc 47095efb545a3e750f0e188d92fac881e98477bf6f4085b64dd64bd2f2cfb93cVirustotal results 39.34% 
2019-12-11FILE_MX0288243984EY.docdoc 16d858b7b873b037e1d1f7285200452dfda3fb83b12808428df4d125a4ed30a4Virustotal results 40.00% Heodo
2019-12-11ODXMELKTTRY.docdoc 803f1f187b179418ffd852244736173da6ce83813cbc66e851ea359e04af585cVirustotal results 38.33% Heodo
2019-12-11DOC_11915407.docdoc e8cd54e34e41d09248447a693ad7f56ba0b180485aa2e3285f96f3d7628364ebn/a 
2019-12-11GP30EX2HBT1O8.docdoc 5b509684825da89a4b2b9fbec5b19d91c46b461f40263753e0cb5e8a493c58a7n/a 
2019-12-11FILE_BZ3138377644SQ.docdoc 548224a38744ef108aa9d7a4d35d0f2df4a19cd8553530e0899bbe1e03eb09ccVirustotal results 29.51% 
2019-12-11OTR_120119_FJJ_121119.docdoc 14bb4c77bd13601583c9f839fe90abd0e28d07ef889ad17b77f8740ca408802an/a Heodo