URLhaus Database

You are currently viewing the URLhaus database entry for http://hbsurfcity.com/cgi-bin/parts_service/ig402gin3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:270253
URL: http://hbsurfcity.com/cgi-bin/parts_service/ig402gin3/
URL Status:Offline
Host: hbsurfcity.com
Date added:2019-12-17 03:13:20 UTC
Last online:2019-12-18 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-17 03:14:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:1 day, 4 hours, 12 minutes Poor (down since 2019-12-18 07:26:07 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-18INV_PO_12182019EX.docdoc 5d06e9b005226160b0e131f85812f4f98077b439baebe2581f27b3678c920990Virustotal results 41.94% Heodo
2019-12-1887325279.docdoc 2175e92f59d8610b907e3989d6fcd6789e81855f2c86efb3a4ea836f934daa9dVirustotal results 42.62% Heodo
2019-12-18V_4722434675298815714287.docdoc f2a74df5302a1cd0bc302de52610490d80ca4730f5451c0b5a28480f57600474Virustotal results 36.07% Heodo
2019-12-17FILE_PO_12182019EX.docdoc 96d4aac0f3abf694b0a71e6948aed4ab10019fe41f8a981854b6c94915adc066Virustotal results 37.10% Heodo
2019-12-1749648293986376.docdoc 09d7ba0e62f409bf7ec8e9e18bfbac4963eb0910a20274efcdc32897fafbae43Virustotal results 35.48% 
2019-12-17C1L4SBYSYK.docdoc 5f8e6e5aa39964eb98832414d520af7154f0cfa719d2953f5eb4718dcdad7b51n/a Heodo
2019-12-17SW_AXV_120119_ZBG_121719.docdoc 681b243258cb3a3ee8c5c0d4052909dcf6db5b795496533539c7e571181b4e86n/a Heodo
2019-12-17FILE_DVYJ5PZZD1L0.docdoc 0061258396098be6656503cf2eb97c5ce407e160fa521a1e79faf9a0d05e46a4Virustotal results 28.81% Heodo
2019-12-17RP_ERF_120119_ZGM_121719.docdoc d48af019c03390885b1876e1ff206ccad6930a8d5854e893dfc5c3a3e592e4a3n/a Heodo
2019-12-17RP_LA1602142376AB.docdoc a53ac5677652d397c8666a63f766c4ff7921fe7b50250c9e7c6e2eb32a4d7941n/a Heodo
2019-12-17PAY_UJS_120119_ZEC_121719.docdoc 0033429b263b67e4f436ffe2aaecb77de6b85ca9d6a4c7f8a37f320cdb0a8dd8Virustotal results 28.33% Heodo
2019-12-17PQ7063875440LD.docdoc 1804de5289b4a78128f1270148c48699f0e756fb6ec4e14b17cac1bd45c05919n/a Heodo
2019-12-17BAL_PO_12172019EX.docdoc b01da25e2db90af2ff5926e0076ebaaac04db732598695f644ee4da87c3b0b53n/a 
2019-12-17P_92434173215781704972.docdoc cb58a6837dedb9f1a8dcf5d0a37dcc35a2e2fd90010e49b7ceb644e77bb135e1n/a 
2019-12-17BAL_VNJ_120119_SSS_121719.docdoc 66e13d3e634ca65322fccb6b3ea5bd18a6b18f8ba7aa4c3895f1749655c281dbn/a 
2019-12-17REP_LIB_120119_LID_121719.docdoc 1c1f8c21ca0ec906bf5286c8474dfa5202c11b49646881c9919f07c6d3e781b8Virustotal results 30.65% Heodo
2019-12-17DOC_NDO_120119_TGB_121719.docdoc 0c659cfb446e20a87d733a9566d9bb40bb0500f00152a80b9a477ea0e4b0726fn/a 
2019-12-178477672483921575721510105.docdoc 6a4ee057fff19048b2286761858a4266a2744a70db1e4f8cf17ed6844374c7aeVirustotal results 27.42% 
2019-12-17UZ4481391318PX.docdoc 5a01edc18d7a59e8a7352801d2e806552be0e83aca9a3aaeb4436acce98a1b76Virustotal results 27.87% Heodo