URLhaus Database

You are currently viewing the URLhaus database entry for http://cantana.booster-testing.com/quotes/eTrac/03ia-6716-92-c1y2ntv-k3j4tljvtg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293563
URL: http://cantana.booster-testing.com/quotes/eTrac/03ia-6716-92-c1y2ntv-k3j4tljvtg/
URL Status:Offline
Host: cantana.booster-testing.com
Date added:2020-01-21 11:57:05 UTC
Last online:2020-01-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 11:58:05 UTC to abuse{at}ovh[dot]net)
Takedown time:5 days, 20 hours, 35 minutes Bad (down since 2020-01-27 08:33:06 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-23BAL_4202245919.docdoc a839b86676fe6ed7bad10374faae1810cce8f20d67a24ea08e4a702c8b4710e8Virustotal results 29.03% Heodo
2020-01-23DOC_22381207.docdoc 5c5abae014b0b9a7ce03a1ae3d2c46c81ff18764fcd3f8e62ade1ab7c570deb3Virustotal results 25.81% Heodo
2020-01-23QUW_QNAJKH5.docdoc 3d01b5634985350eb0753da8324f05a468b2e27cfb4e7d5911f3005520bfd2f2Virustotal results 22.22% Heodo
2020-01-23W_DE8820090481XM.docdoc 79950a40bf62dac08fd1adbb9c8aba2b8db0e05de9829d485ac3a51302d546a8Virustotal results 20.97% Heodo
2020-01-23ST_47255712877274960.docdoc 260b5a47eceb11eaeaddda02644c85294da44e3eaca951d45152e1db6b9f1c79n/a Heodo
2020-01-23PX3534694046KA.docdoc c66a254b5cf8419c673e64cacdef02261eac06a02105f1ac0b0a10000542a7dcVirustotal results 22.58% Heodo
2020-01-23WSZ_010120_YQJ_012320.docdoc 369488460f5d15f277924ca8f7c9da9046f082c111d528e799ea1d2e9407c794Virustotal results 21.88% Heodo
2020-01-23REP_19431153003207396929854.docdoc 425dc31b9652f83260c405be0755dcc694bee850e115c19c8aab134a108c8ef3Virustotal results 32.26% Heodo
2020-01-23BAL_6206919888090917.docdoc 9e417d5c58ae969ec35f92ad1143eb6c4aaf1928b9e9b86fa5e893fe6c007f62Virustotal results 31.15% Heodo
2020-01-23ST_EU9250932367ZX.docdoc cf72901c6f393919be6a0bed5ca2671fca36d5705fd639d1722cdfeb3ff93c24Virustotal results 31.67% Heodo
2020-01-23BAL_PO_01232020EX.docdoc c902819826aded735fa4ea8025d726e7b868dbee374343fde8e6b5a3fe6733e0Virustotal results 28.57% Heodo
2020-01-23SW_J0LHNO49.docdoc 57f80688fb69b44c38dc1526796d523074e95761263f1c762f83cbb491b369a6Virustotal results 28.57% Heodo
2020-01-22ST_LJ2806091883OV.docdoc 29487cc347b96694240c5003b2fde7f8e509ac63ea9365249aa1a23c122502ceVirustotal results 27.42% 
2020-01-22PO_01232020EX.docdoc 669eefc104d806bd76c96aea4774af65b2fdc557d7bb93f72910014b7093d9c3Virustotal results 26.56% Heodo
2020-01-22INV_3984WQGTF.docdoc 0fed8a6d0f31e05943d5e786c31313260f8187f838e8ee21b42c285e41df16cbVirustotal results 28.57% 
2020-01-22REP_EL7641384981FF.docdoc 31e49b1899bba2d501d48db72766686f1c0d77627dd79e5585b8f5dcf1de7054Virustotal results 28.57% Heodo
2020-01-2280TPF89T4XB4Z58.docdoc 760da2cf865d8c30de733432733cd907c4d3473c8c956b337785f76899801383n/a 
2020-01-22BAL_TC7582174839BU.docdoc 069ef10afe63ac6665e7b1fe0caa7982f224f4c8738b455a07050d44e21ec0b7Virustotal results 27.42% Heodo
2020-01-22NJH_121635447214.docdoc 5f685d49710e07b7bf6d016e2e75676bcba151a6f2af4c7f08f826261f7fce75Virustotal results 28.12% Heodo
2020-01-22FILE_87407147.docdoc f953335933b0bfdd1a511f17473513146e45bd32b38f8279a759eae1d2dd42a1Virustotal results 33.33% 
2020-01-22BAL_779604728720335.docdoc 5be3e93b04906a447233525f99dffcce0d42f3559aa4ecfb866c92b5fc7f6671n/a Heodo
2020-01-22M_21188402.docdoc ef44a3288d7ae90b174f66d99d6157dace138152521b46b1affc482b2ffe349fVirustotal results 31.75% Heodo
2020-01-22DOC_KNH_010120_WQH_012220.docdoc 2e5f9f296d5addeabf6f8caa5e1e989363265c1ca3cba2201a933e734bcf8635n/a Heodo
2020-01-22DOC_PO_01222020EX.docdoc c4b215a59659e1c91fffadf971f2d9f6a0865a757e23c4ded707e894927c7837n/a Heodo
2020-01-22SW_RN7358536713GM.docdoc ae732e2481c442c721b9c70bbbafde35384fc2d9c8e8426e67eabd9863b3e009Virustotal results 26.23% 
2020-01-22PAY_KFA_010120_HRM_012220.docdoc 65a1628ef9bc3362fb43fdae7776948360a3fe80ae3fb6f8f03a5d2a68e8694dVirustotal results 27.87% Heodo
2020-01-2213010187.docdoc 336ab3a461e1a9206d529c38bf94f01e340884585fe63edd765c3fd0821f68e6n/a Heodo
2020-01-22RP_8784804764296823888651347.docdoc a85351653bf9a0c8c76db9f4c1076418ba4fface5c3a7f373d29186bf46732e0Virustotal results 25.42% Heodo
2020-01-22REP_89175446.docdoc 38787b38f9ed7908075086f02ec866791014775637c563d31e7926535cfad02eVirustotal results 20.97% Heodo
2020-01-22CR3V0PYH73FP2JS9.docdoc 8205eac5713b6e780f44ca0ead54f7b14258c7553e717184eee2ab927d901095Virustotal results 21.67% Heodo
2020-01-22HI8386826154RN.docdoc a0855eab3940a455dc8d9abb41fe9a44d09eb1153e79da6e813565d5dac82f24Virustotal results 19.67% Heodo
2020-01-22BAL_PO_01222020EX.docdoc 8bb40f94230c4779d38d4849765d3c668b37c66d257ecbf89fe76f042c850958Virustotal results 19.35% Heodo
2020-01-22FILE_15905750440328051971.docdoc 6321d13c864a5af9a0a39e72120db0999714232489e7bf8461b8a795db19a222Virustotal results 19.67% Heodo
2020-01-21ST_ZJV_010120_RPC_012220.docdoc e7cfcc5924207c0384febd2ca4125ab12dc6c893443adf4fecf44f056f3e243cn/a Heodo
2020-01-217100809255908602428.docdoc afc71ff2f950fe201610ccb3658ecabd28277de445f299d235048e06bb3c02ben/a Heodo
2020-01-21A_UR4599258597HP.docdoc 5fd6ec312654d263689e335748f1296c2e1cc8b5d84f2f28e4f0af1686d55715Virustotal results 19.35% Heodo
2020-01-21DOC_71305ARTE.docdoc 4a5b9b9742ab79ec97f03a713d79186193ea89fbdce64cc486bdfeb117c7e7bfVirustotal results 19.67% Heodo
2020-01-21ST_PO_01212020EX.docdoc 1b7b6aadbc97da71c335724f63be656d8123a8ab1633f93a53e990242787660aVirustotal results 19.67% Heodo
2020-01-21ST_8737605114153.docdoc b27efe734620499ff72dafb2bd9cf0650ea42d6b08f670e80149d1a7087d4f51Virustotal results 19.67% Heodo
2020-01-21KQ7897395758CM.docdoc 0ba2bc2d8ddd7c95e3a17870d34c390e31968ea645b5ca3c5978da28719eeb99Virustotal results 19.35% Heodo
2020-01-21FILE_MYF_010120_XUN_012120.docdoc 0ac7a98f0bbf451a51cb75aa5b065d00e46c0860c7cd1c90a194e8a40a56aa93Virustotal results 19.67% Heodo
2020-01-21ST_Q93G1OALQ.docdoc 2f2a0cf5f701e2014ef05a565aab080235be85106bd630e67bb5c9e1aabefad5Virustotal results 20.97% Heodo
2020-01-21REP_DYC_010120_VBU_012120.docdoc f8cd0ec825c89fdfbdcebefa1756132a3f4d14e798d4b8f1833de4b6db4eeb91n/a Heodo
2020-01-21X_PO_01212020EX.docdoc 3fd7f5dcc627af3f5f832b508d626dfa8691089e643a00c47c88bc2fe760fb23Virustotal results 23.81% Heodo
2020-01-21Y5G8I6MCSSV.docdoc dfe2815ab27e806aa38d3a86f0c43e7aa9fca4b580604411f1d339c734d038e3Virustotal results 24.59% Heodo
2020-01-21BAL_UF9574038702EZ.docdoc e9192c62520e20c5b224bff7b12aa26959425899e804e2a4e86440e3523ccaa0n/a Heodo