URLhaus Database

You are currently viewing the URLhaus database entry for http://yojersey.ru/system/1ffz45n0-cyjo499450bj-4WzgmWUrzy-zR0PNZdMZ3x/security-profile/3275828-XhTtE8lbD/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:270102
URL: http://yojersey.ru/system/1ffz45n0-cyjo499450bj-4WzgmWUrzy-zR0PNZdMZ3x/security-profile/3275828-XhTtE8lbD/
URL Status:Offline
Host: yojersey.ru
Date added:2019-12-16 22:47:05 UTC
Last online:2019-12-30 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-16 22:48:03 UTC to abuse{at}ht-systems[dot]ru)
Takedown time:13 days, 7 hours, 52 minutes Bad (down since 2019-12-30 06:40:06 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-19file_ZZR91299791406.docdoc 2096aeb29e7f19f81c094a0ef93d2fb2a64ba7a29bf972d94e1b469ecf5968d8Virustotal results 24.19% Heodo
2019-12-18list 8440815.docdoc 07ab35a0d78f11f8ea58be35156645e2e83acb0a13e1500f6928143220857c26Virustotal results 24.19% Heodo
2019-12-18UNTITLED 17562031.docdoc 8cb117096e7923784d1eed0160f9ccfc37a9df973ecef692d367417bbe1db054Virustotal results 26.23% Heodo
2019-12-18copy-tw0n098o50uwk68.docdoc 3be9f66ef6e3feb291bca66c44fd8651d392ab19807b9bce1a7fad00d4a518a6Virustotal results 25.00% 
2019-12-18VER-12182019.docdoc 6998c2f955541d5a517fd68d96604f2ea2efa83d0d1c0a04fa3d09c629bf3e18Virustotal results 24.59% Heodo
2019-12-18COPY-521172965.docdoc caa090b360b6e3c71db80f8b2d1d3020613c21c862f38150f50f638afd07f3bbVirustotal results 20.97% Heodo
2019-12-18file-t1662nv6r4.docdoc b73e5e0962313a34d109b2bf3a04d3b650cdc791657e1abf930278f364a8f423Virustotal results 24.59% Heodo
2019-12-18COPY_832533.docdoc 43c08049eabb097bd65da44392027b6626e52a6bd358485346f0517aa921806fVirustotal results 24.19% 
2019-12-1812_18_2019_D51319746.docdoc b940831dd5e63865c557cf3eeeebf1a5b859df61b2b463df2c7aedef04f8ad72Virustotal results 22.95% Heodo
2019-12-18release-Z6313_5521.docdoc 92abb6154b33185935537f274a4848863b31ac921b0d3ab7660f4e1028c1afb3Virustotal results 20.97% Heodo
2019-12-18doc 12_18_2019-G346270724.docdoc d7154a3cd6ed7727d5d0a4b1320ae48662ba912131d99a97f80deae5ab47fcc2Virustotal results 21.31% Heodo
2019-12-18vs4pwo7v4mpp0.docdoc c847a7eeb54234a353b810f65e0e317eeaf9c5834815b849bc327b982a1a4021Virustotal results 28.81% Heodo
2019-12-18COPY-12182019.docdoc 24e4ddde59c888a0ab84e147ce46a48a6bfc4a9e3b0ca85706f53a37c76a6d3dVirustotal results 45.90% Heodo
2019-12-18387632488.docdoc 7ab7f374de3e62a8e0f89c58090671e170f9abd2b35ffa3a1df305f71320dbe4Virustotal results 44.26% Heodo
2019-12-18info-5u6r83ov661.docdoc 992d05921516c9f141fca70dfe31a45a23b8eb4a1ed260bac73a3b5aa4c78638Virustotal results 41.38% Heodo
2019-12-17Untitled_file_5982813.docdoc 162b45d30363b3b61c9dcb7a1e78fa518b0acf9a7824118ec25ef0a78af40d65Virustotal results 40.00% Heodo
2019-12-17Doc-N20057924.docdoc a0ee5ed792b92efebc5111e6df93fb20907d929f0fb40f6f82e8d1917dd115fdVirustotal results 32.76% Heodo
2019-12-17STAT 12_18_2019_8992627.docdoc 1f2c9480181a2911c888f8806512b812241631c508c441872a327c221d68d5b5n/a Heodo
2019-12-17rep-482077.docdoc 30078f9329962f5294b88ac781efbf027ba43ec2ce191d7a679e4cd0da73ee6cn/a Heodo
2019-12-17part qp49o39pr9s6lmm.docdoc b7c5359912e1c89f19135f60e2df6d473fa8a3b32c7dde466b65245bf8e20682n/a Heodo
2019-12-17REP-12172019.docdoc 7eb5ec4b9e4eb2b401b34c61b459676f286bdf33b7304becf9bdab4ed2edc728n/a Heodo
2019-12-17COPY WQF84588751497-5728536907.docdoc 36b4c828884257ce27b108bd530afbd168dbf6a5ebd21fbb05d75d0285aa6857n/a Heodo
2019-12-17COPY_S12883_5185936.docdoc 524b69becf744a88a5fc314ee06524973b2695623ff9dcf666f60fcd7b51c943Virustotal results 22.03% 
2019-12-17doc_12_17_2019 53G3826465894.docdoc 143b9b4932a378409b6386bf35c1c12184577b27ee4926b9fa1e571ea0d3d4d8n/a Heodo
2019-12-17N50387507.docdoc 7977471169c4ee8fbc1e96e439ea0e3a710dfb9f5856ce8e374ee142304afef5n/a Heodo
2019-12-17STAT_728689364253.docdoc 7d977bf9c31a903615ffe8d2524741fd3ae11ac416c7c1463ed424ef07dc67b3Virustotal results 31.67% Heodo
2019-12-17rep_S2657761264.docdoc 9c56290024fb776e41606806ebfb1420f0c5c13de45405e7569bd5f94b330661Virustotal results 31.67% 
2019-12-17file-7YW71183.docdoc c9e63f76ed3ad58b071fc36b0e55012348e40b5bb8d82a7ed71b3e77293c2f51n/a Heodo
2019-12-16file W551351241-10321.docdoc 5f67da189685b24f15387ae2d785116f30768abd85b30334a32f8f377fd405d8n/a Heodo
2019-12-16sns513r.docdoc a91d361afd90dc17d4ea32bf5f615ee4d117492ee290b0a2067f604ca4c7bbbdVirustotal results 25.81% Heodo