URLhaus Database

You are currently viewing the URLhaus database entry for http://urgeventa.es/img/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293208
URL: http://urgeventa.es/img/swift/
URL Status:Offline
Host: urgeventa.es
Date added:2020-01-21 04:33:03 UTC
Last online:2020-02-04 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 04:34:03 UTC to abuse{at}ovh[dot]net)
Takedown time:14 days, 10 hours, 25 minutes Bad (down since 2020-02-04 14:59:33 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-23REP_CPU_010120_UTU_012320.docdoc 3a76473f4fdef818df5db0b1ba516e47f5bca5fe9907eaf153c3b8696e34ac50Virustotal results 31.25% 
2020-01-23I_14326988623.docdoc 9af2280771f435166b53ce4682f2cedf9072877a0fd338920e1a7ae4434c47caVirustotal results 30.16% Heodo
2020-01-23INV_REB1HOEDLZU45L.docdoc 9e417d5c58ae969ec35f92ad1143eb6c4aaf1928b9e9b86fa5e893fe6c007f62Virustotal results 31.15% Heodo
2020-01-23VSDJ_WNZ_010120_WWI_012320.docdoc e63aa1c3401d847d86e7d7a0183b1b09932060991feb79d6e2b775a27f30c36bVirustotal results 30.65% 
2020-01-23VMJ_010120_PYP_012320.docdoc c902819826aded735fa4ea8025d726e7b868dbee374343fde8e6b5a3fe6733e0Virustotal results 28.57% Heodo
2020-01-23INV_34HAW6WF811I.docdoc 1fc298251ecbc967c1a852ae8549568c2d11d20ff8c2fe5795d71c0701dc0d1bVirustotal results 27.42% Heodo
2020-01-22BAL_5GHG2LKQTFBL.docdoc 29487cc347b96694240c5003b2fde7f8e509ac63ea9365249aa1a23c122502ceVirustotal results 27.42% 
2020-01-22X_487646334012.docdoc 02162d1ebbd251123e389c21ac4ee348795335e3c17b1b7a79bcb6b65b2be2e6Virustotal results 28.12% Heodo
2020-01-22PAY_HFPNXB5VU4ZWF.docdoc 0fed8a6d0f31e05943d5e786c31313260f8187f838e8ee21b42c285e41df16cbVirustotal results 28.57% 
2020-01-22ST_NF4163338565DK.docdoc 31e49b1899bba2d501d48db72766686f1c0d77627dd79e5585b8f5dcf1de7054Virustotal results 28.57% Heodo
2020-01-22H_53045909940835569.docdoc 1edd209142cc223e891e8dd444c153f50de141b3239f20dfad8f44bf278752a9Virustotal results 28.57% Heodo
2020-01-22RP_JC1595429112AW.docdoc 069ef10afe63ac6665e7b1fe0caa7982f224f4c8738b455a07050d44e21ec0b7Virustotal results 27.42% Heodo
2020-01-22UWW_010120_YXL_012220.docdoc ab600b906dee873222585e34ad20f43a3eb8dbc281f88b10eac0e7ed4b8f6f8fVirustotal results 28.57% Heodo
2020-01-22PO_01222020EX.docdoc f953335933b0bfdd1a511f17473513146e45bd32b38f8279a759eae1d2dd42a1Virustotal results 33.33% 
2020-01-22BAL_37288158.docdoc 5be3e93b04906a447233525f99dffcce0d42f3559aa4ecfb866c92b5fc7f6671n/a Heodo
2020-01-22FBP_RE4546089115TL.docdoc ef44a3288d7ae90b174f66d99d6157dace138152521b46b1affc482b2ffe349fVirustotal results 31.75% Heodo
2020-01-22PO_01222020EX.docdoc 2e5f9f296d5addeabf6f8caa5e1e989363265c1ca3cba2201a933e734bcf8635Virustotal results 29.03% Heodo
2020-01-22WSB_010120_SEW_012220.docdoc 609678cf042b2eef7db729034aeb79f91c90692e7182f94ba9a08b7854909ed4Virustotal results 29.03% Heodo
2020-01-22RP_USG_010120_RBY_012220.docdoc ae732e2481c442c721b9c70bbbafde35384fc2d9c8e8426e67eabd9863b3e009Virustotal results 26.23% 
2020-01-22BV7B7SHT98.docdoc 2060f7df174027271307cce5c7a8ec61c05546b084780a80186d00fc343a2b0fVirustotal results 27.87% Heodo
2020-01-22BAL_54057377739.docdoc 336ab3a461e1a9206d529c38bf94f01e340884585fe63edd765c3fd0821f68e6n/a Heodo
2020-01-22399194626176264000483.docdoc a85351653bf9a0c8c76db9f4c1076418ba4fface5c3a7f373d29186bf46732e0Virustotal results 25.42% Heodo
2020-01-22PAY_2243600690083.docdoc 38787b38f9ed7908075086f02ec866791014775637c563d31e7926535cfad02eVirustotal results 20.97% Heodo
2020-01-22Z_PO_01222020EX.docdoc 8205eac5713b6e780f44ca0ead54f7b14258c7553e717184eee2ab927d901095Virustotal results 21.67% Heodo
2020-01-22ST_PO_01222020EX.docdoc a0855eab3940a455dc8d9abb41fe9a44d09eb1153e79da6e813565d5dac82f24Virustotal results 19.67% Heodo
2020-01-22SW_20867879.docdoc 8bb40f94230c4779d38d4849765d3c668b37c66d257ecbf89fe76f042c850958Virustotal results 19.35% Heodo
2020-01-22PO_01222020EX.docdoc f1c1ff6da408d3db36973e88b9e655de09333c432f5360ddf9ba275f6b330d46n/a 
2020-01-21BAL_0224679222536.docdoc e7cfcc5924207c0384febd2ca4125ab12dc6c893443adf4fecf44f056f3e243cVirustotal results 20.97% Heodo
2020-01-21PAY_PO_01222020EX.docdoc afc71ff2f950fe201610ccb3658ecabd28277de445f299d235048e06bb3c02ben/a Heodo
2020-01-21SW_XPW_010120_HRX_012220.docdoc 4a5b9b9742ab79ec97f03a713d79186193ea89fbdce64cc486bdfeb117c7e7bfVirustotal results 19.67% Heodo
2020-01-2167615078.docdoc 1b7b6aadbc97da71c335724f63be656d8123a8ab1633f93a53e990242787660aVirustotal results 19.67% Heodo
2020-01-21REP_PO_01212020EX.docdoc f8b7610b7621a91b5d28857ea340a864fe7c4b11e544e0a8d55b06130078f520n/a Heodo
2020-01-21FILE_314818403669238.docdoc 0ba2bc2d8ddd7c95e3a17870d34c390e31968ea645b5ca3c5978da28719eeb99Virustotal results 19.35% Heodo
2020-01-21PAY_TER_010120_QZP_012120.docdoc fff53210bdb63327220fff3391a23e72f83f7224d0732a2993a962d3214adf38Virustotal results 20.00% Heodo
2020-01-21PO_01212020EX.docdoc 2f2a0cf5f701e2014ef05a565aab080235be85106bd630e67bb5c9e1aabefad5Virustotal results 20.97% Heodo
2020-01-21REP_25902930098.docdoc f8cd0ec825c89fdfbdcebefa1756132a3f4d14e798d4b8f1833de4b6db4eeb91n/a Heodo
2020-01-21ST_PO_01212020EX.docdoc 3fd7f5dcc627af3f5f832b508d626dfa8691089e643a00c47c88bc2fe760fb23Virustotal results 23.81% Heodo
2020-01-21PAY_PI97G5BE4XNO.docdoc dfe2815ab27e806aa38d3a86f0c43e7aa9fca4b580604411f1d339c734d038e3Virustotal results 24.59% Heodo
2020-01-21ST_ER1538417776OM.docdoc ac0a043ddb5cd2ef939889a7dface6d1464766b504e1cf491e8d05d6983e0d12Virustotal results 22.95% Heodo
2020-01-21INV_RY1425181311XG.docdoc 5e98531907cc57e4b1fa31b9808e8349d25ccb173af389776484b6e12e0bda7fVirustotal results 22.95% Heodo
2020-01-21E_94651346.docdoc 3d7638d3dfb9736e90003021fd9a8a5dde3aef6a2d13539f6734043630d1d035Virustotal results 22.03% Heodo
2020-01-21PAY_75737211.docdoc 8f4c14f97223ec8f494ad5728dfc1e5667d176c2400fe9afebf812dad4744212Virustotal results 23.33% 
2020-01-21DAZ_010120_VQR_012120.docdoc b8083992ca8cf08ef3353bdea04c93eaeb2c2d9a0840119f89868e27b2261a32n/a Heodo
2020-01-21SW_44461232.docdoc 75c18f408894f1bd20cec6f8a0ee58eeafcdb92b73ab75859ce6132806d9bd4eVirustotal results 36.67% 
2020-01-21BAL_ED0073182456VF.docdoc 8b78282e6b2583bd618bbb3b6b93050deb71e7887890411c84f184e37f5c3bb6Virustotal results 32.26% Heodo