URLhaus Database

You are currently viewing the URLhaus database entry for http://3tcgroup.com/fooddemo/statement/7syu3t3vvu/ipmf-768459-33836-p0kepsc-h3j11dyty9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:292730
URL: http://3tcgroup.com/fooddemo/statement/7syu3t3vvu/ipmf-768459-33836-p0kepsc-h3j11dyty9/
URL Status:Offline
Host: 3tcgroup.com
Date added:2020-01-20 14:08:15 UTC
Last online:2020-02-25 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-20 14:10:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 6 days, 0 hours, 13 minutes Bad (down since 2020-02-25 14:23:26 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-22FILE_61154554.docdoc 4c80edcbb0062e3b1f50fd07de05afa15805203131f6a34ae1dd4f4591dfcf20Virustotal results 30.65% 
2020-01-22I_215633468995091880.docdoc f69c27021097cddffe80a78ef5eaec605efba6caf58203495243093f9e8af161Virustotal results 31.15% Heodo
2020-01-22D_PO_01222020EX.docdoc f3d0d66f75e7208fde5a74908acb95794e6d6bb2b7b878d59d560e3c4189b503Virustotal results 30.65% Heodo
2020-01-22SW_SY0378386399SP.docdoc 609678cf042b2eef7db729034aeb79f91c90692e7182f94ba9a08b7854909ed4Virustotal results 29.03% Heodo
2020-01-22R_NM7758491681RP.docdoc ae732e2481c442c721b9c70bbbafde35384fc2d9c8e8426e67eabd9863b3e009Virustotal results 26.23% 
2020-01-22REP_NHR_010120_QKK_012220.docdoc 2060f7df174027271307cce5c7a8ec61c05546b084780a80186d00fc343a2b0fVirustotal results 27.87% Heodo
2020-01-22FILE_8U87F9ZDXG.docdoc 38787b38f9ed7908075086f02ec866791014775637c563d31e7926535cfad02eVirustotal results 20.97% Heodo
2020-01-22GGMHVATE804.docdoc 8205eac5713b6e780f44ca0ead54f7b14258c7553e717184eee2ab927d901095Virustotal results 21.67% Heodo
2020-01-22PAY_G1RI8YQ41LIHU.docdoc 6dd831fbe1f601834039bd80bbaf9b2bbe45f08d144b5d4ad5caa0e8135df998Virustotal results 20.00% 
2020-01-22BAL_UTEHBWQJE.docdoc 6321d13c864a5af9a0a39e72120db0999714232489e7bf8461b8a795db19a222Virustotal results 19.67% Heodo
2020-01-21DOC_VX3996610963DQ.docdoc 73ae92b67a773aeb211f7520d6d98ff0b4f01babd23ad51535129e1c09c78e97Virustotal results 21.31% 
2020-01-21ST_PO_01222020EX.docdoc b5d3d28c7cf031aca9149a40e293973df4908b797894f03fbcb558fb2c7878c4Virustotal results 19.67% Heodo
2020-01-21PO_01222020EX.docdoc 616b942341fb4aa9e7ef9a9812fc490798f6d57020915c7fdeeb4d6abd868b77Virustotal results 19.67% 
2020-01-21PO_01222020EX.docdoc 616b942341fb4aa9e7ef9a9812fc490798f6d57020915c7fdeeb4d6abd868b77Virustotal results 19.67% 
2020-01-21FILE_PO_01212020EX.docdoc 3971d2f8dad1df7ae025551c02c685cf456405eb7ba164f380e38518f2d228eaVirustotal results 19.67% Heodo
2020-01-21SW_79998190.docdoc 4e578642e48a682151e6b78297df0f7112766260e70723e848b22473395b214eVirustotal results 19.35% 
2020-01-21RP_KB2IDVWF.docdoc 0ba2bc2d8ddd7c95e3a17870d34c390e31968ea645b5ca3c5978da28719eeb99Virustotal results 19.35% Heodo
2020-01-21PAY_157226408487316150695869.docdoc 3d3251db7fdf4ce69cd096e40ec64f5a29e379f209e810a7d1b617f23307a38fVirustotal results 20.00% Heodo
2020-01-21JIR_010120_MVD_012120.docdoc 2f2a0cf5f701e2014ef05a565aab080235be85106bd630e67bb5c9e1aabefad5Virustotal results 20.97% Heodo
2020-01-21RP_2521268559360821608318.docdoc 3fd7f5dcc627af3f5f832b508d626dfa8691089e643a00c47c88bc2fe760fb23Virustotal results 23.81% Heodo
2020-01-21EF65B7S3.docdoc b3027e1a517aecd6ce516879fe1f0b6ccb4565a07aedac1df279f168ab71abd4n/a Heodo
2020-01-21WXX0SKSUI.docdoc d1117a28a75e18b39ecab237339947455fc2f362df875ff30e726b14dc16ee62n/a Heodo
2020-01-21FILE_PO_01212020EX.docdoc b4357b15ba2d5ddf69c371351fa7e9e3028caef09f64d5f0056d1e39bc8bdd47Virustotal results 22.58% Heodo
2020-01-21VGM_010120_MMT_012120.docdoc 02ffafb9df3c1817c1407b645b452bf63dea66ee2992bd41a6a1dbc7ffed0bd3Virustotal results 21.31% 
2020-01-21REP_QN6933706010YR.docdoc b8083992ca8cf08ef3353bdea04c93eaeb2c2d9a0840119f89868e27b2261a32n/a Heodo
2020-01-21INV_JNA5FTP.docdoc 75c18f408894f1bd20cec6f8a0ee58eeafcdb92b73ab75859ce6132806d9bd4eVirustotal results 36.67% 
2020-01-21SW_96306041235.docdoc cddc497a79392c497f8be4a7013f1d3f403743a2cf5b3896a3b83bb5ec17e1e4Virustotal results 32.79% Heodo
2020-01-21REP_NHO_010120_ELZ_012120.docdoc 97f55cd9a4169904bb304d25dec8f7e772082dc8c1aa3468206307bb6e95df26Virustotal results 28.33% Heodo
2020-01-21JI9052563489FF.docdoc 6f95ea0f92c00748e1215edfe2c7b4c7e772776fc5e4c48e67ead100f4c5c835Virustotal results 26.67% Heodo
2020-01-213456071863068584502586.docdoc 852d7c2fe2e50b54bcc8b4bd89978251dbcf736f134ce9226fbb287d77394db9Virustotal results 26.67% 
2020-01-21RP_70893997.docdoc 6322d1c243c7934b2ff794162d1e2e94f5c7b12be2a0e628e57749fb5be530can/a Heodo
2020-01-20RP_PO_01212020EX.docdoc 22396867fdac01104cf39ac62c3bae2f0137d249c9bebc8cc1bfd2f8933f5c5cVirustotal results 26.67% Heodo
2020-01-20SW_86919560.docdoc 8c315ebf4829f97717eb97eda8aaa254483ebaf7f43e3250d0efa8990f2ffa40n/a Heodo
2020-01-20ST_LL1RL67QTVVSN.docdoc 4447b642ce2918954ed6caadd8f62d5dc8b65c5a888673e5f9b921a7ec51c9e8n/a Heodo
2020-01-20RP_FKS_010120_DGW_012020.docdoc 678ade151e9690c4e5554104212bb97160c5fd2fc610bf2097a6f3fe4276657eVirustotal results 27.12% Heodo
2020-01-20D_SBX_010120_TKM_012020.docdoc aa3c760924ba7c9087decd46d2af6ac7b5790dc6724f87102b5c9f3dcca76da0n/a Heodo
2020-01-20INV_PO_01202020EX.docdoc f350c10ed558dbc0d0579d36debe971c189a0be9edaa526e6c335f5a85063626Virustotal results 27.87% Heodo
2020-01-20D_D20HLFD5C.docdoc 77f470766022173e04ada1e7ba6d5d27999b7383cd72fd3665cfc564f9177b27n/a Heodo
2020-01-20PU_PO_01202020EX.docdoc 85f52ce0700048ef21e9b73d225f0466d5860521768a50f9f10bbf35836f5c60Virustotal results 28.33% Heodo
2020-01-20Z_7921944851207.docdoc 11f7435dab6e4404e33c8bcaf1804f42d466274b8568f998dc2f3ae30f0a1fc5Virustotal results 25.81% Heodo