URLhaus Database

You are currently viewing the URLhaus database entry for http://ferrylegal.com/uploads/Document/u4vl8y2qxs/wpof6u-6847142744-33-mf1tg-t72iznqj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293261
URL: http://ferrylegal.com/uploads/Document/u4vl8y2qxs/wpof6u-6847142744-33-mf1tg-t72iznqj/
URL Status:Offline
Host: ferrylegal.com
Date added:2020-01-21 06:13:16 UTC
Last online:2020-02-04 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-21 06:14:04 UTC to postmaster{at}myhostcenter[dot]com)
Takedown time:14 days, 13 hours, 17 minutes Bad (down since 2020-02-04 19:31:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-23SW_VKH_010120_CVO_012320.docdoc e8388161aa26b58a1e284fb5d1fc027f9dde88daf73a217a1aeb33c2679bb7a1Virustotal results 31.75% Heodo
2020-01-23PO_01232020EX.docdoc 329cef98b814d926a6f4a2c9635fce3e09e91e9545665914971007acfa9eddbfVirustotal results 30.16%Heodo
2020-01-23FILE_47079780.docdoc a7da95cc5af2d5b4e1d2b4e16f96007855b5783f4383c199878f2230aaf11453Virustotal results 32.26% Heodo
2020-01-23PAY_FC2NI0GPTQ73.docdoc cf72901c6f393919be6a0bed5ca2671fca36d5705fd639d1722cdfeb3ff93c24Virustotal results 31.67% Heodo
2020-01-23SW_VX3467351363IU.docdoc c78e3b88c08a9425cc9d6043a9d20e85c160e556a37f57f3f2515cb894c33316n/a Heodo
2020-01-23FILE_93444425666825.docdoc 57f80688fb69b44c38dc1526796d523074e95761263f1c762f83cbb491b369a6Virustotal results 28.57% Heodo
2020-01-22DOC_O7UM457XBYG.docdoc 62fb677b5e795566ed8b06713d070488a08cffaccd527993f327cb931929ea2eVirustotal results 29.03% Heodo
2020-01-22DOC_955105001990285946.docdoc 669eefc104d806bd76c96aea4774af65b2fdc557d7bb93f72910014b7093d9c3Virustotal results 26.56% Heodo
2020-01-22ST_FEBYPN8MUJ6S6.docdoc 0fed8a6d0f31e05943d5e786c31313260f8187f838e8ee21b42c285e41df16cbVirustotal results 28.57% 
2020-01-22INV_II3621988729DP.docdoc 31e49b1899bba2d501d48db72766686f1c0d77627dd79e5585b8f5dcf1de7054Virustotal results 28.57% Heodo
2020-01-22REP_UL1FIX5U.docdoc 760da2cf865d8c30de733432733cd907c4d3473c8c956b337785f76899801383n/a 
2020-01-22RP_RHYSW1TEF21CX.docdoc 6ae88a641c3cf227c2db6bdc728158b97d4b9f912b642fc6c41e453eda9c27b4n/a Heodo
2020-01-22ST_M3AIAKE.docdoc 5f685d49710e07b7bf6d016e2e75676bcba151a6f2af4c7f08f826261f7fce75Virustotal results 28.12% Heodo
2020-01-22RP_VQ0002584981FH.docdoc 478f1dc50e192ecb20ebcdb9a37e7c312e9a8cc20766a5f86f95b3d9c09cc0b3n/a Heodo
2020-01-22FILE_AMX_010120_UVF_012220.docdoc 5be3e93b04906a447233525f99dffcce0d42f3559aa4ecfb866c92b5fc7f6671n/a Heodo
2020-01-22YWH_010120_IPC_012220.docdoc a8e86ce1edef7bad9f725d8f9b127d50d0a80a4e3477a2294f61bd2be001bfc7Virustotal results 31.75% Heodo
2020-01-22VK5XBN1O2.docdoc 2e5f9f296d5addeabf6f8caa5e1e989363265c1ca3cba2201a933e734bcf8635Virustotal results 29.03% Heodo
2020-01-22DOC_AJ1Z43F.docdoc c4b215a59659e1c91fffadf971f2d9f6a0865a757e23c4ded707e894927c7837Virustotal results 26.09% Heodo
2020-01-22RP_2987686886.docdoc 78ccf76669f5a2bee9b21435419ae9a674d35c1e68a75f44f943b9c71ba7c41dVirustotal results 26.23% Heodo
2020-01-22LM_3206634376563175298.docdoc 2060f7df174027271307cce5c7a8ec61c05546b084780a80186d00fc343a2b0fVirustotal results 27.87% Heodo
2020-01-22RP_BZWH149.docdoc f4537190336568e84c9ba01fcf8b21c50da4bc7b0eecaafd25acc762bbb1d1dcVirustotal results 26.67% Heodo
2020-01-22BAL_28614361.docdoc a85351653bf9a0c8c76db9f4c1076418ba4fface5c3a7f373d29186bf46732e0Virustotal results 25.42% Heodo
2020-01-22IB3I5SDMS.docdoc 6386c6fdd8a1eb4f6fc7bf14c51236c53a6d7dc8419ff7add51d3a75c46d3610n/a Heodo
2020-01-22T_OYY_010120_IHO_012220.docdoc 8205eac5713b6e780f44ca0ead54f7b14258c7553e717184eee2ab927d901095Virustotal results 21.67% Heodo
2020-01-22E_BS4084287438ET.docdoc 6dd831fbe1f601834039bd80bbaf9b2bbe45f08d144b5d4ad5caa0e8135df998Virustotal results 20.00% 
2020-01-22SW_PO_01222020EX.docdoc 7a2981d0930261cea557f3e13fe0f3c8789b4c3d07ceecf861481ab926156b0dVirustotal results 21.31% Heodo
2020-01-22FILE_WVN_010120_XEI_012220.docdoc f1c1ff6da408d3db36973e88b9e655de09333c432f5360ddf9ba275f6b330d46n/a 
2020-01-21BAL_Z8CYXIUWNY.docdoc 73ae92b67a773aeb211f7520d6d98ff0b4f01babd23ad51535129e1c09c78e97Virustotal results 21.31% 
2020-01-21PAY_AAB_010120_DGN_012220.docdoc afc71ff2f950fe201610ccb3658ecabd28277de445f299d235048e06bb3c02ben/a Heodo
2020-01-21R_WSN_010120_TTQ_012220.docdoc 616b942341fb4aa9e7ef9a9812fc490798f6d57020915c7fdeeb4d6abd868b77Virustotal results 19.67% 
2020-01-21SW_PO_01212020EX.docdoc 1b7b6aadbc97da71c335724f63be656d8123a8ab1633f93a53e990242787660aVirustotal results 19.67% Heodo
2020-01-21SW_34701027.docdoc f8b7610b7621a91b5d28857ea340a864fe7c4b11e544e0a8d55b06130078f520n/a Heodo
2020-01-21INV_279955514.docdoc 87f198aab109437e66b753398ed36d61115bcd349c900750ed31b89952b9f3bcVirustotal results 20.34% Heodo
2020-01-21PAY_GO6258445053OD.docdoc 0ac7a98f0bbf451a51cb75aa5b065d00e46c0860c7cd1c90a194e8a40a56aa93Virustotal results 19.67% Heodo
2020-01-21DOC_73237025.docdoc 2f2a0cf5f701e2014ef05a565aab080235be85106bd630e67bb5c9e1aabefad5Virustotal results 20.97% Heodo
2020-01-21DOC_PO_01212020EX.docdoc f8cd0ec825c89fdfbdcebefa1756132a3f4d14e798d4b8f1833de4b6db4eeb91n/a Heodo
2020-01-21REP_455772912903906688129.docdoc 61507dd50818260d95aaadcd23ed886f445d5c1afe613e53e1633c08ee5bdab8n/a Heodo
2020-01-21PAY_LH8953039226GH.docdoc dfe2815ab27e806aa38d3a86f0c43e7aa9fca4b580604411f1d339c734d038e3Virustotal results 24.59% Heodo
2020-01-21PAY_EW0659342602NH.docdoc d1117a28a75e18b39ecab237339947455fc2f362df875ff30e726b14dc16ee62Virustotal results 25.00% Heodo
2020-01-21UKC_010120_IZB_012120.docdoc e4932995a94e0c841f96d023503d1a1bb8e8278fe5478a736b9a4cbc83283ab7n/a Heodo
2020-01-21FILE_6CG2E5V5Q.docdoc b4357b15ba2d5ddf69c371351fa7e9e3028caef09f64d5f0056d1e39bc8bdd47Virustotal results 22.58% Heodo
2020-01-21REP_PO_01212020EX.docdoc 02ffafb9df3c1817c1407b645b452bf63dea66ee2992bd41a6a1dbc7ffed0bd3Virustotal results 21.31% 
2020-01-21INV_78030196315458353974866.docdoc b8083992ca8cf08ef3353bdea04c93eaeb2c2d9a0840119f89868e27b2261a32n/a Heodo
2020-01-21BAL_02818791.docdoc 1a54c57512dbcac388648552cf8ec7536827af1c60f032cf6b3b6fc3197033c4Virustotal results 38.71% Heodo