🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://best-fences.ru/JS/parts_service/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:267347
URL: http://best-fences.ru/JS/parts_service/
URL Status:Offline
Host: best-fences.ru
Date added:2019-12-11 23:35:04 UTC
Last online:2019-12-12 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-11 23:36:02 UTC to abuse{at}ht-systems[dot]ru)
Takedown time:20 hours, 51 minutes Good (down since 2019-12-12 20:27:30 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-12DT2235621504CT.docdoc d34a3b22b311a68cf698ad967f3a8a7473173253098abd4253af7be2fbcee40cVirustotal results 33.33% 
2019-12-12DHCIU4IDW.docdoc 3564b611a66534eae58e5f69f3571fe45d4db45a2f82886bc433c9d228a99346n/a Heodo
2019-12-12L_13793216.docdoc 2b6bf2055790d8fae5a1b31dfc9ff559ccd0586cb7d0c8717c24cdb6262626b0Virustotal results 32.79% Heodo
2019-12-12PO_ 12122019EX.docdoc 5c8dba81db95bc51ed5031e5d36754b7511c85af2bf774d9b2399516815f2936Virustotal results 30.00% 
2019-12-128QAQG7RQ0F3Z.docdoc 0b965425faade68933db02bccca34ef37ce1911c7cbaa10b8a3dfb960b705a92Virustotal results 35.00% Heodo
2019-12-12QWB_5544094190.docdoc 0e16ecde01d063169f28135beb6ee3ae5847da290e943cd60722d7ecd25f1b79Virustotal results 28.33% Heodo
2019-12-12W_96533706.docdoc 03a6a75373a9d6a8cdc3dc2f0bbb827d595216900979ac8df62a5a87439300eaVirustotal results 29.51% Heodo
2019-12-12FILE_1826172040.docdoc cd9fafbae1765254701fe1ed8e741e933871c9982e881a17fca79bd8c40d8dcen/a 
2019-12-12I_AR540NB.docdoc 7880cc42f78ce37e1603207a15bb0471e309eb5fedc7fa51abbefd09e357efcbVirustotal results 28.81% Heodo
2019-12-12IQ9929168143UN.docdoc 15d655db81abf803aa22bb3129e3f12caac4a096d6ccd5965016154ee7676293n/a 
2019-12-12NJ5136599675AJ.docdoc 4721a8055b657c23bd15975b8e48f48b896edb566b8ea44c7709df8967972522Virustotal results 41.94% Heodo
2019-12-12FILE_8425639581504199483.docdoc 03853acef0aa03678d353bbdfac0cc28f1701f384327ff0c3f42b122c0effbfdVirustotal results 43.33% Heodo
2019-12-1239612102.docdoc e0fd2fdc26869f285127622c05a135f251e83e589e2567e1aea88c55c4bb2723Virustotal results 42.62% Heodo
2019-12-1180157238.docdoc 44ecab63049aed6f6bf82a960fb4bc7b77edada709a3be20a674fff13f93e9ceVirustotal results 42.62% Heodo