URLhaus Database

You are currently viewing the URLhaus database entry for http://hqsistemas.com.ar/cgi-bin/Overview/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294205
URL: http://hqsistemas.com.ar/cgi-bin/Overview/
URL Status:Offline
Host: hqsistemas.com.ar
Date added:2020-01-21 22:54:15 UTC
Last online:2020-05-05 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-21 22:56:02 UTC to soc{at}ifxcorp[dot]com,abuse{at}ifxcorp[dot]com,abuse{at}ifxnetworks[dot]com)
Takedown time:3 months, 14 days, 7 hours, 23 minutes Bad (down since 2020-05-05 06:19:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01ST_77792361929.docdoc 6f1778f8d85766731dcb42f37016b7d4ef4e394f88d76ccde47034071505ba74Virustotal results 65.00% Heodo
2020-01-23ST_47117783.docdoc a985bd8cf1c8cf13e1e52a689e15368860aa0dfafd232dc3a3738e4858089f2bVirustotal results 34.43% Heodo
2020-01-2350775195928.docdoc 0c5fa3a9b92158a64ca9f11b4a7a9b70b3087455aa932783d293d065b49924bcVirustotal results 31.15% Heodo
2020-01-23FILE_9267636445736708289490.docdoc be6c0143e369040588ac032db356bb21b70bda2cd730cee53440f1a52186b25fVirustotal results 30.65% Heodo
2020-01-23PAY_HTF_010120_MKD_012320.docdoc af2b0742fa0766988ed7610f170e906320f17554f57b4830bac5c8e6ad71ead8Virustotal results 28.12% Heodo
2020-01-23FV1775637429HE.docdoc c82a367077df5a08b1c5607128e658095404e2fe76bd7a0c4c17b8d74bdba0c3Virustotal results 29.03% 
2020-01-23B_119722458253124811308764.docdoc e1380fa81c9ecf98aea7ac2b25a691e612910e8b07ce4adf982136d30d00907fVirustotal results 29.03% Heodo
2020-01-23PAY_D9N4AWG47VF.docdoc a4c0577378d402ac5f86199f8f56fae0155148be1ee3e0cd88bcc3dad348604bVirustotal results 27.42% Heodo
2020-01-23K_28T2CWEQ.docdoc e81dc8d25679f4fea9a21338bd9612d079418003d3304029950f146696624ff7Virustotal results 28.33% Heodo
2020-01-23SW_QS4838503298XJ.docdoc 667a70d5b2b7840b6e7668f011e10182bbd2103b7885111ed07392813d2af6d4Virustotal results 31.75% 
2020-01-23BAL_PO_01232020EX.docdoc 3dfc6fa01e58672ef6645b09c90fbe06f24467be30e4281523ba01775c698dc1Virustotal results 33.33% Heodo
2020-01-23DOC_JOH_010120_KEO_012320.docdoc d744c1d20947939b65a0dfa826e7b011a996521e9aea99c7a6be5531639e82eaVirustotal results 26.98% 
2020-01-23RP_FO1149251120QA.docdoc 3d01b5634985350eb0753da8324f05a468b2e27cfb4e7d5911f3005520bfd2f2Virustotal results 22.22% Heodo
2020-01-23L_FK3967567300RB.docdoc 9606d8dc2f0dfb10656d44b2cf56d6e4c37ed143602cda16cc87ca46ac0f6405Virustotal results 20.63% Heodo
2020-01-23RP_PO_01232020EX.docdoc 87375ae81a73bb3dc7f704b3e7e62e3e496b286fa24c145831637953f4bcd132Virustotal results 20.97% Heodo
2020-01-23REP_GR3833568638OS.docdoc 627970068806ee557b861c46c5f66f04f0985ad9caddd21dc3c8e4682108042dVirustotal results 22.22% Heodo
2020-01-23EJQ_7241157137316.docdoc e50ca42cece8459c5ed1bf0713f580775a5bea5fd9384b1e5f284e52f2db08b1Virustotal results 20.97% Heodo
2020-01-23ST_720192730012.docdoc 329cef98b814d926a6f4a2c9635fce3e09e91e9545665914971007acfa9eddbfVirustotal results 30.16%Heodo
2020-01-23DOC_57854293.docdoc 9af2280771f435166b53ce4682f2cedf9072877a0fd338920e1a7ae4434c47caVirustotal results 30.16% Heodo
2020-01-23INV_79680661796561325558776.docdoc e63aa1c3401d847d86e7d7a0183b1b09932060991feb79d6e2b775a27f30c36bVirustotal results 30.65% 
2020-01-23F_VS0843125946UQ.docdoc c902819826aded735fa4ea8025d726e7b868dbee374343fde8e6b5a3fe6733e0Virustotal results 28.57% Heodo
2020-01-23REP_22766928.docdoc 57f80688fb69b44c38dc1526796d523074e95761263f1c762f83cbb491b369a6Virustotal results 28.57% Heodo
2020-01-22U_NF8525799832JO.docdoc 29487cc347b96694240c5003b2fde7f8e509ac63ea9365249aa1a23c122502ceVirustotal results 27.42% 
2020-01-22ST_F41CXOV.docdoc 72bd6822c6587d7476c2bce9cbb767b7f392c8c960c6a5f08b75f5ef154f6a2aVirustotal results 27.42% Heodo
2020-01-2287340671.docdoc c551f97351c13e0f158f87d3c11bbdb5b9f2b2b10576509755d225e3f3bf46c7n/a Heodo
2020-01-22ST_3RJU0TNQZ4CIH.docdoc 696eb463a71f1e49e463dde08cd523507439d5a8b27bc5adc7a95c5fc1746816Virustotal results 27.87% Heodo
2020-01-22BAL_OF4946631462DL.docdoc 760da2cf865d8c30de733432733cd907c4d3473c8c956b337785f76899801383n/a 
2020-01-222Z6M3O3S26P0CI.docdoc 6ae88a641c3cf227c2db6bdc728158b97d4b9f912b642fc6c41e453eda9c27b4n/a Heodo
2020-01-22ST_PO_01222020EX.docdoc 5f685d49710e07b7bf6d016e2e75676bcba151a6f2af4c7f08f826261f7fce75Virustotal results 28.12% Heodo
2020-01-22SW_PO_01222020EX.docdoc 478f1dc50e192ecb20ebcdb9a37e7c312e9a8cc20766a5f86f95b3d9c09cc0b3n/a Heodo
2020-01-22U_39018985.docdoc 52421339a07e7f572a5ceda6a1ae7ede4e7bf976d5e74e3089ff4d2039c147a2n/a Heodo
2020-01-22INV_37587372.docdoc 88bf8d08abbaa434038e444a69dff9877dbadf1ef53e5e09b640adce1996cc03n/a 
2020-01-22ST_05082338650201463993019.docdoc 2e5f9f296d5addeabf6f8caa5e1e989363265c1ca3cba2201a933e734bcf8635n/a Heodo
2020-01-22FILE_48691119.docdoc c4b215a59659e1c91fffadf971f2d9f6a0865a757e23c4ded707e894927c7837n/a Heodo
2020-01-22REP_QR2515214309XK.docdoc 78ccf76669f5a2bee9b21435419ae9a674d35c1e68a75f44f943b9c71ba7c41dVirustotal results 26.23% Heodo
2020-01-22Q_PO_01222020EX.docdoc 65a1628ef9bc3362fb43fdae7776948360a3fe80ae3fb6f8f03a5d2a68e8694dVirustotal results 27.87% Heodo
2020-01-22MD1161502578UU.docdoc 336ab3a461e1a9206d529c38bf94f01e340884585fe63edd765c3fd0821f68e6n/a Heodo
2020-01-22INV_6SZUFOKVY.docdoc 96e71ebc8855336f1ff5006afcd5167486abf09cebca7b194da01a83388a9053Virustotal results 21.43% Heodo
2020-01-22RP_344333823411476885500.docdoc 38787b38f9ed7908075086f02ec866791014775637c563d31e7926535cfad02eVirustotal results 20.97% Heodo
2020-01-22RP_IU9263269764RR.docdoc 8205eac5713b6e780f44ca0ead54f7b14258c7553e717184eee2ab927d901095Virustotal results 21.67% Heodo
2020-01-22REP_041671134657636590875.docdoc 6dd831fbe1f601834039bd80bbaf9b2bbe45f08d144b5d4ad5caa0e8135df998Virustotal results 20.00% 
2020-01-22PAY_RWIWS4SDRQTV.docdoc 8bb40f94230c4779d38d4849765d3c668b37c66d257ecbf89fe76f042c850958Virustotal results 19.35% Heodo
2020-01-22RP_233451024890997314.docdoc f1c1ff6da408d3db36973e88b9e655de09333c432f5360ddf9ba275f6b330d46Virustotal results 20.69% 
2020-01-21BHI_010120_FUX_012220.docdoc e7cfcc5924207c0384febd2ca4125ab12dc6c893443adf4fecf44f056f3e243cn/a Heodo
2020-01-21SW_NL7843939511XN.docdoc b5d3d28c7cf031aca9149a40e293973df4908b797894f03fbcb558fb2c7878c4Virustotal results 19.67% Heodo