URLhaus Database

You are currently viewing the URLhaus database entry for http://ecube.com.mx/public/hi43-544-7989349-qp839jrpe6-fk59nax4cf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287963
URL: http://ecube.com.mx/public/hi43-544-7989349-qp839jrpe6-fk59nax4cf/
URL Status:Offline
Host: ecube.com.mx
Date added:2020-01-14 12:31:54 UTC
Last online:2020-01-15 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-14 12:46:07 UTC to abuse{at}tierpoint[dot]com)
Takedown time:13 hours, 52 minutes Good (down since 2020-01-15 02:38:52 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-15PO_01152020EX.docdoc 678c5ed922797efdaf2fd7c86cfbbdbdda3f748143606d1167925c17d6cf7994Virustotal results 31.15% Heodo
2020-01-14PJQ_48731920.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23% Heodo
2020-01-14FILE_17709556.docdoc e8e877eb89bc1a478fee7e89597bcac889a3776e27aae4692b63920428f58e53Virustotal results 19.67% Heodo
2020-01-14INV_DPH_010120_GXY_011420.docdoc 8cfbeba4189d63e24f257f8d06ae7e8d2f9a54c9fbbd30e385380d356c747c7dVirustotal results 19.67% Heodo
2020-01-14BAL_3404020045335814.docdoc e3cd5ab045097c55bcb00a1cdc84e11c8d7214e15f536baffd899dfb8e0a3149Virustotal results 17.74% Heodo
2020-01-14ST_G122QX6UO5RBXD.docdoc 11eff1ee3baa4018b746994350fdefc67169f53201d97bb7bd9076bed15d7765n/a Heodo
2020-01-14RP_JO1425574113OY.docdoc 9ee85b399435a194b9b67f49143134a823ef4dc87f95970c3516773b340fe9afVirustotal results 18.33% Heodo
2020-01-14DOC_PSFSE2XG5SY6.docdoc f5f4d5f08a7cb7e623d0bbfae4b90f9cf9151135d1218fc30b351b23903cbea3Virustotal results 17.74% Heodo
2020-01-14ST_OH3071536281CN.docdoc 2034078fa59ba80aa4ea104fadd6e28f7fdb58220f8a6c434014ec88a007b0ffn/a Heodo
2020-01-14NCB46G6NTSY0.docdoc 4e1c36be80c8d49de9d619166b44e070c37538978fd2b281547e1ceb47c90afen/a Heodo
2020-01-14OL8611685739EX.docdoc f55d03e3ad7e00c22487c4297a898c96e36b144a5619d181623997b6b4782d13Virustotal results 22.00% Heodo