URLhaus Database

You are currently viewing the URLhaus database entry for https://arqdesignconstruct.com/cgi-bin/Scan/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:271084
URL: https://arqdesignconstruct.com/cgi-bin/Scan/
URL Status:Offline
Host: arqdesignconstruct.com
Date added:2019-12-17 22:54:11 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):No
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-19SW_BLRX3HKJA.docdoc 5b18866c00b22906fc732bc27e409bd65993207586b1ae8844ff238a8e7631d6Virustotal results 24.59% Heodo
2019-12-19EIT_120119_OYM_121919.docdoc 7b59717378331890255ad1aee1b7581861360cc08cb8285756a7ba1bf76a6bf6Virustotal results 24.59% Heodo
2019-12-18REP_028255585779814.docdoc 2f37a55acc32e7d59e31d6c98effdc3171e447d51f5aceea59451fe493461b9eVirustotal results 25.81% Heodo
2019-12-18Z_07888895.docdoc 53c21d965d731f212e3c62743ad88519b2a4290af20dfadf8ba74762743317bdVirustotal results 27.12% Heodo
2019-12-18RP_82881700.docdoc 7af0436052fc188b4873f17046e2e073a7a82706179a796f82c27b32a8fcb95eVirustotal results 24.59% Heodo
2019-12-18ST_SM2759723701MV.docdoc 8b974a004a4926372021ced18f1b480e32367d38fb9e5e8e29ef08f9b03232f4Virustotal results 24.59% Heodo
2019-12-18PAY_94733849.docdoc 9e1926052857a2e225958cd4be2f519fc158025c1917ef13ee55619055c882f9Virustotal results 22.58% Heodo
2019-12-18FILE_UOH_120119_VNK_121819.docdoc c7a4384f56804bd3f32c9e65713fb455ce84bc5a3d45a65e8e7ad429c17990adVirustotal results 22.58% Heodo
2019-12-18REP_38538238.docdoc 83e5d3dd6d2e1ae224de8d75ee08d3ab332823d3c845777db0e532bf80851c0eVirustotal results 21.05% Heodo
2019-12-18BAL_RLG_120119_SBO_121819.docdoc 04dfb2f392ec304df0fe8ff84c4e9e1c4b6cab4f0b9ab8146de6e1cbdf744b3dVirustotal results 20.97% Heodo
2019-12-18P_59565307.docdoc 751bc11854450888ec606d7c725c004e83771068cfcb57409ae20ee399d7e5f6Virustotal results 21.05% Heodo
2019-12-18ST_RL8335882774ZV.docdoc d19458049a137e1bfcd3f580aeef39686b6e1ea204dbf4f4a3abf79bcde08016Virustotal results 42.62% 
2019-12-18SW_58662975.docdoc aaf3e3daf13c96071a436e0b71879423e317e159aea31f016f469790375c4954Virustotal results 42.62% Heodo
2019-12-18PAY_RN2247254396ZJ.docdoc 862593f0ec4b40cc1593362375fb3751cc51fc9f73e14dd6e5681c81433d3472n/a Heodo
2019-12-18DOC_WOU_120119_WBC_121819.docdoc 2175e92f59d8610b907e3989d6fcd6789e81855f2c86efb3a4ea836f934daa9dVirustotal results 42.62% Heodo
2019-12-18DOC_JT9037257655HY.docdoc 93d369757cf3781835bcb065259e16616edc5dd61239a27366bca7abb4b7c0b2Virustotal results 36.07% Heodo
2019-12-17ST_QL1YC2TJ.docdoc d494fef0346aac9497abd8465b6e3bd64fce90b32a1e2048737ae5ca345b7d1cn/a 
2019-12-17ST_960171403757.docdoc 92601448815c89ad8b52f293c293bfbeb4699447e80552699831e622cf6c75d3n/a