URLhaus Database

You are currently viewing the URLhaus database entry for http://industriasrofo.com/_mmServerScripts/168934/zwjr-063-168553103-7e0e-iu5li/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272176
URL: http://industriasrofo.com/_mmServerScripts/168934/zwjr-063-168553103-7e0e-iu5li/
URL Status:Offline
Host: industriasrofo.com
Date added:2019-12-18 23:53:03 UTC
Last online:2019-12-30 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-18 23:54:03 UTC to abuse{at}abansysandhostytec[dot]com)
Takedown time:11 days, 22 hours, 46 minutes Bad (down since 2019-12-30 22:40:05 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20PAY_PO_12212019EX.docdoc e23bc5ee382cc5f5a5c5a62deca1d119ee4347bfd72aa40765a336f933d1f7f8Virustotal results 37.10% Heodo
2019-12-20RP_279160192674705351492877.docdoc 2c09ad1e9f2b04bad470d559fe566a0415f6899e722b32c124fc3aee45bd4381Virustotal results 32.79% 
2019-12-20PAY_S68FU2V6QTGP2QIY.docdoc 79e3cdd3341c2a20f5f88852caecd48fd292124c4b9e649a4c29305142ceb114Virustotal results 28.57% Heodo
2019-12-20RP_PO_12202019EX.docdoc 6d74be1af79dcfd81b6b1aa64e4990733c0264973ca86c0ef0a1730ef2ab1919Virustotal results 30.00% Heodo
2019-12-20JUN_24385326.docdoc e8ac62a0e0e1eadff780cb1324a70ce03be311bb33d7c7bc69faddc1c7c2cb37Virustotal results 30.00% Heodo
2019-12-20PAY_MCU_120119_FFO_122019.docdoc a59c9e9e44e265083559fa39278c124dda988863ee5a7425b078e2e4500b6cffVirustotal results 27.87% Heodo
2019-12-20INV_IJE_120119_FFF_122019.docdoc c19e4f9564e304e11d679ca37dc75ab35b3feb1f6e63df36add9dc12cc43e6baVirustotal results 27.87% Heodo
2019-12-20PIRUVK6G12ZT.docdoc 118c66d3e9b8ca9c08ffd48c868218db3fdd2eb2f4938b1d293e9e38c783182bVirustotal results 27.87% Heodo
2019-12-20REP_URK_120119_XRU_122019.docdoc 8f62870ed7ba3a13c0f2552e3789de9221819090622393d8f689e7af17a42ebeVirustotal results 24.59% 
2019-12-20I_0614334441517.docdoc b3a7213579f74c678d6fd8c9258ba534a06e009c01418ef2b4ceb40a2c85aed7Virustotal results 24.19% Heodo
2019-12-20REP_IB8Z7H46.docdoc e4bba0d01cbf6f796e53cffedf881a3285eff0426d344221ae144ac4cea10679Virustotal results 26.23% Heodo
2019-12-20IGF_120119_EOO_122019.docdoc 19f2c7093452e7e5230593bed7cbcf8ce570ee2eadd6fa0513349c4f2dd4a175n/a 
2019-12-20REP_AP5622451707RY.docdoc de8ee9d6ff5217db052c005f8e49a89873ee06eeae2acf202c3de1f3d9a33e0eVirustotal results 37.29% Heodo
2019-12-20I_6VMCSR79TWOCB.docdoc 955a1f6f73eaf4a839941cc66e1ea96d5e06a7d5a9d291806d1172154eaac64dVirustotal results 32.20% 
2019-12-20DOC_85209586057769.docdoc 9e4b17c8494ca6655aba67f946f92aedd8f8ee42ea7fd8fc952a5fe6e7d568edVirustotal results 31.15% Heodo
2019-12-20S_NZN_120119_HJD_122019.docdoc f917dc0d1080638f16e961715423d9abf2e22a9256b0e64c77561e0a0596dffbVirustotal results 31.15% 
2019-12-19SW_0755628603178.docdoc db9c24d60e35b197741ade1553584eb831f3ac5cd6515bbd62dc5a8b76ff192cVirustotal results 29.03% 
2019-12-19RP_529O2BM.docdoc 5cba9e1a0ff954e76f547d533dcf7786003c61fcc3395d81dcf27305a708662fVirustotal results 29.51% 
2019-12-19TN2505969224XR.docdoc 131d652fd46bc9e3ef1023e39dab359648e5e41d6901507538bb697ddc1a8b6fVirustotal results 29.51% 
2019-12-1942960528.docdoc ad6b961455a212d6505b4b8b903b98a059789e6d046c1c8133b44d6dcae8ccc4Virustotal results 30.65% Heodo
2019-12-19I_JKXSBXMV.docdoc e6d9f6d0f912e85696813df87790acc7b5e693e429471f657bcccdf850beb505Virustotal results 25.81% Heodo
2019-12-19REP_16398965.docdoc ae3ad7cc2de9660f9cf3e5b188d56204322931a071d9f1e9302e7ef89f96e968n/a 
2019-12-19INV_08397062.docdoc cf1e1c5fdce6dfaeb87c86090e186b06e0165f13e4e47b7136298473f02118bdVirustotal results 25.00% 
2019-12-19DOC_8851521321619423030709481.docdoc cdeba1be6ff661149500bbcb2f45ac5db0c0af310c302a1bbf4439e1aea7bfaaVirustotal results 27.87% Heodo
2019-12-1903308456.docdoc 0daa6de717e589ea8c3126e8d7047ad5304119e733a8ba96202115ae84adf049Virustotal results 24.59% Heodo
2019-12-19DOC_GWF_120119_YLO_121919.docdoc d72a222b6080f71609f51e12cb182d8aa0b37224caf6281ae9a00474cd312e87Virustotal results 26.23% Heodo
2019-12-1995378618258064819992.docdoc 38c90f95a0def3067b003f8dcd801289e896767661545df059f46f1ee9f89db7n/a Heodo
2019-12-19INV_YGS_120119_JGP_121919.docdoc cb85f97a43fcc49c76da83312f8d2eeb134f4802d0f52420856fb219d76c9dc3Virustotal results 21.67% Heodo
2019-12-193826693015137.docdoc ea8762cde8721bcd9d366dd2c0cae94ce0ec0f44a624b76335c464d49d368d96Virustotal results 22.58% Heodo
2019-12-19INV_WO2BO0ZZ3FYNG4BN.docdoc 25a59f35cfdd7851ee3b7919f81988a018627f9aba95c71c3f8fcf9a49de027fVirustotal results 22.58% 
2019-12-19BAL_FS5121479711LN.docdoc dfde887979e2a371477ada84d0cecb56737421b00cb048f0186ab16146f11fccVirustotal results 22.95% Heodo
2019-12-19PO_12192019EX.docdoc 22461874b83b6287baadcf227b2e495c257af92469d2ac02f98270dbc3fca8e1Virustotal results 21.31% 
2019-12-19DN4IO6WVF5.docdoc dc19d868cbfccec6608b904b7220dd1384fe24e6137be714af752d6c5c86725fVirustotal results 31.15% Heodo
2019-12-19LH3713047621TR.docdoc ec2cbbdaa442e182f9375cf3860d8ec64897319a62aca277d9f3c2cc5005d888Virustotal results 31.15% 
2019-12-19SW_PO_12192019EX.docdoc eece617e68c6bd59cba0abfe3a92b1bd28f333ded755fdeecdf32aa5d9369d44Virustotal results 30.51% Heodo
2019-12-19REP_92235544131067905208904.docdoc 43cf36bece6360c16a5c550fa8a8d5a8bc1520b790e42c2c3b00b5fdb357bbe8n/a Heodo
2019-12-19PO_12192019EX.docdoc 89a22bd587f2bc9df2709648106e06157480b6fb980ae4e779da1fc76038fa08Virustotal results 24.59% 
2019-12-18INV_939538351854761548665.docdoc d993c95ac842ff786d7f94ae1cdde22eaf6e3f5132f05618d815ae4ffb6faa9dn/a Heodo