URLhaus Database

You are currently viewing the URLhaus database entry for http://argosactive.se/engl/sb3sj5tp-4b-451/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290660
URL: http://argosactive.se/engl/sb3sj5tp-4b-451/
URL Status:Offline
Host: argosactive.se
Date added:2020-01-17 05:39:03 UTC
Last online:2020-02-11 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-17 05:40:06 UTC to drift{at}binero[dot]se)
Takedown time:25 days, 5 hours, 37 minutes Bad (down since 2020-02-11 11:17:27 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-30n/aunknown 9712cc3a3011511550aa98faba8a2b15c9c12442e93722447e6f733c9c2e381fVirustotal results 0.00% 
2020-01-18Inv ETFS0367_380582610.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18Inv_U7_46360210.docdoc d4d29c6cfffdf351ad541d65a634554e0a99a4486477bb307f318499af87904bVirustotal results 24.59% Heodo
2020-01-18invoice LVW1_529359.docdoc c18f5e41c03d90485d087d382d3953e3ae125d732a5c8bb1684de08cd58d79bdn/a Heodo
2020-01-17Invoice L43_83929306.docdoc fa9e97722fc94cc65979bf0bac795c3e5c860e2b72dc977262c2b7641ab53acbVirustotal results 20.00% Heodo
2020-01-17Invoice-IU562_356936491.docdoc a8c4e3f1c16e9ff3857699615d8f6bd392a4d88dfdc6f9dd9b43b523ac3158ebVirustotal results 19.35% Heodo
2020-01-17INVOICE_R142_36204791.docdoc 9d50256ecfbc6630a03d98c2f512c1084d03a8a416aeda264c405070e9a5d3bbVirustotal results 18.03% Heodo
2020-01-17Inv_H60_715029.docdoc 3f227c11e8835a6cb877438bf4628c9b105553fa1fc681389fcf5bd5574dcfa0Virustotal results 19.35% 
2020-01-17Invoice_JB27_591191136.docdoc ba41ad73fcdce6b4e813741379ada938bdc3b9f751255d0f38bf9e39833dd000Virustotal results 23.33% 
2020-01-17Inv J9_41213264.docdoc 8135652b106f2b85795db8ea0696bc8b19b68a1fc008345df6b797e19b88084dVirustotal results 20.97% Heodo
2020-01-17invoice RB4839_899745715.docdoc 4bccfd69e2d0f9968b1a8471e9d094226f9ca6cad0fb4681943bfe1cf459a706Virustotal results 20.00% Heodo
2020-01-17INVOICE DTS4_0643604.docdoc 6a30e995f8d4b431a06066f77625efb700c679b72dd760d573016bfb6c391a87Virustotal results 18.03% Heodo
2020-01-17Invoice 5324_02432006.docdoc e09d6c6471feb40345f420439b9c6a3a12ad485be6d8be5a8568b50fcee2b422Virustotal results 18.03% Heodo
2020-01-17Inv 149_263532840.docdoc c682de9b99812ab7c470a026d17e1060364b9bf4e1890d733b05ef312452f8d8Virustotal results 19.67% Heodo
2020-01-17INVOICE-VTKR0_967045.docdoc 81e67b1fefc9adfcf367364590a04c14a8b109dafe04e935412b4f8c82ed5f64Virustotal results 19.67% Heodo
2020-01-17Inv-V5_001844951.docdoc 7a51d9e976d8778788950f5c677c677cdea8a828a49b9306cee884e85d66c448n/a Heodo
2020-01-17invoice K5_0560662.docdoc e54979318c06a7cc3d8fb5f00d32d0fa2a169f8447a224ec8822749071c550f6Virustotal results 37.10% Heodo