URLhaus Database

You are currently viewing the URLhaus database entry for http://libertyaviationusa.com/wp-content/invoice/5v7vqb2l/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295087
URL: http://libertyaviationusa.com/wp-content/invoice/5v7vqb2l/
URL Status:Offline
Host: libertyaviationusa.com
Date added:2020-01-22 18:19:06 UTC
Last online:2020-01-30 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002268829 created on 2020-01-22 18:20:05 UTC)
Takedown time:8 days, 0 hours, 2 minutes Bad (down since 2020-01-30 18:22:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24INV_FV2700573275XN.docdoc 85db98d8c0bde6612ee5f1a8ef57b8a73f353a1ec6dbcedc61859e03fa71659dVirustotal results 29.69% Heodo
2020-01-249BW81GGJ1XWJ0.docdoc 8388df2859989323c4471518332173373dbd4ef4d8d051f781b74ad808230e2fVirustotal results 26.98% Heodo
2020-01-24REP_4P0FQDK.docdoc d1ce33fa24c35c0d836fed807b804f901f3a90d80da0bb29588eaa9945795324Virustotal results 26.56% Heodo
2020-01-24REP_5217399150084.docdoc cba73ededc4676a3fd5ea386a62854670752212eedaeea52fb505d3fb96068faVirustotal results 26.98% Heodo
2020-01-24BAL_56798981.docdoc 63e55893c18790c4c43b2261932de3c375faeccee864300e5a4f72dbf45aec84Virustotal results 28.57% 
2020-01-246S3EJBDH.docdoc d2b63d414300ae2f724149929a00606653a297417e4a591368ff9c1714cce281Virustotal results 28.57% Heodo
2020-01-24INV_PO_01242020EX.docdoc 789f39cce8f34ef92a1114d703e66a8894c7d3025572c148161fa467d1b6fe81Virustotal results 26.98% Heodo
2020-01-24RP_NWJ_010120_JWF_012420.docdoc 6b70256ec87f79fca124f33a26e5f745547c178cdb9ddd66e63f073948449bb7Virustotal results 26.67% Heodo
2020-01-24SW_PO_01242020EX.docdoc ad42180e1aebb0af7c9d7513e76b038f31b88465f066f855f3098d0edf967abfVirustotal results 25.00% Heodo
2020-01-24HLRV_RM5270765945LU.docdoc 72d90821b9c20296395cc4a57a6d2d7c45851726d1c52d4154cc037816c439e6Virustotal results 25.81% 
2020-01-24BB_DU8613106821TG.docdoc e767869c387d6176cedcc00bd0ff08ba017f2f78a5244aa0ca510fd2129a2e3eVirustotal results 25.81% Heodo
2020-01-24OS_14982820.docdoc 6a538f5d087e49e06be537ade4bb480a0729b86fb9d35e34df163e81e7b10c6aVirustotal results 46.03% Heodo
2020-01-24DOC_77448168.docdoc bedffe567bdec300da442d0c24e30f94beca6e30401410ac906a60946b63fe9bVirustotal results 46.03% Heodo
2020-01-24BAL_J4BK2ESO4AHXU26L.docdoc 2c4b0f8d4c1eaa6adbac77b21a05ff32242cab116fc252c21c67fc0ab51ba110Virustotal results 46.77% Heodo
2020-01-24AFR_010120_QQT_012420.docdoc 73da5cdf0f98ea4dbedb8219ddd051b4d7a04c9750fc4b1d6f9c8e4f9e218c53n/a Heodo
2020-01-24BAL_ES9558752279ON.docdoc 2caa93025cda12c41ce7d3ac89a2e81c7db0a40a6571fb3cb406c98e2ec71097Virustotal results 44.44% 
2020-01-24AG0774570150DM.docdoc ddf866c230e59d9ca832eab360303767357ba3355a1cdc0509e069fa3234898aVirustotal results 41.94% Heodo
2020-01-23L_52541365.docdoc 5be57dfc1ec466f1be92f7b12e5623520bdd185a7ea6f50d60890f7df9cd67f9Virustotal results 38.10% Heodo
2020-01-23F_SEG_010120_MLB_012420.docdoc 826405ab23ee390f30113412530dd8fa36957b7fd600826efea19868f3f20b3dVirustotal results 38.71% 
2020-01-23SW_46728378.docdoc 86eec0c136bf128a3ecff3448b635759a3f1a59bd572354ee242b6104910bd10Virustotal results 30.16% Heodo
2020-01-23QG1B5ZWLZCHY.docdoc fc252e63169ae12bd304670fd8a56a969b89a721a64477c2f5095e9c453dc9f1Virustotal results 32.81% Heodo
2020-01-23RI8512935961KQ.docdoc be6c0143e369040588ac032db356bb21b70bda2cd730cee53440f1a52186b25fVirustotal results 30.65% Heodo
2020-01-23TN1617411942AM.docdoc 0854d5a8ba17e65aef32385c9680d29b0bf5f82a486b44ffb80fda5c8fc8fb77n/a Heodo
2020-01-23SW_65775149.docdoc c82a367077df5a08b1c5607128e658095404e2fe76bd7a0c4c17b8d74bdba0c3Virustotal results 29.03% 
2020-01-2300057886192395269884.docdoc e1380fa81c9ecf98aea7ac2b25a691e612910e8b07ce4adf982136d30d00907fVirustotal results 29.03% Heodo
2020-01-23SW_42290807.docdoc a4c0577378d402ac5f86199f8f56fae0155148be1ee3e0cd88bcc3dad348604bVirustotal results 27.42% Heodo
2020-01-23INV_LC9951412901XP.docdoc ce43998d0af42cb9a17bf220f9fe9418948e1e05c4b007cc306bfd2d4580d2a8n/a 
2020-01-23RP_523207218028493699.docdoc 667a70d5b2b7840b6e7668f011e10182bbd2103b7885111ed07392813d2af6d4Virustotal results 31.75% 
2020-01-23KOV_010120_NTZ_012320.docdoc 8f57a1a62bed296020fc8eccb69e151133940788c6b8b87ceb2d95273dcae200n/a Heodo
2020-01-23REP_SRL_010120_YFO_012320.docdoc d744c1d20947939b65a0dfa826e7b011a996521e9aea99c7a6be5531639e82eaVirustotal results 26.98% 
2020-01-23PAY_SW67X42GRM79.docdoc 3d01b5634985350eb0753da8324f05a468b2e27cfb4e7d5911f3005520bfd2f2Virustotal results 22.22% Heodo
2020-01-23BAL_7325021271215953233032001.docdoc 79950a40bf62dac08fd1adbb9c8aba2b8db0e05de9829d485ac3a51302d546a8Virustotal results 20.97% Heodo
2020-01-23SW_YP2976942775CD.docdoc 87375ae81a73bb3dc7f704b3e7e62e3e496b286fa24c145831637953f4bcd132Virustotal results 20.97% Heodo
2020-01-23FILE_WK3909216300AQ.docdoc 9cd39ce28644fb0f4e0e7dad49fed36f777b06e6950bcd98c30eb410e42cfc5bVirustotal results 20.63% Heodo
2020-01-23LT7153149659SU.docdoc e50ca42cece8459c5ed1bf0713f580775a5bea5fd9384b1e5f284e52f2db08b1Virustotal results 20.97% Heodo
2020-01-23BAL_87347212.docdoc 425dc31b9652f83260c405be0755dcc694bee850e115c19c8aab134a108c8ef3Virustotal results 32.26% Heodo
2020-01-237IQMBDRYP2H67Z.docdoc 9af2280771f435166b53ce4682f2cedf9072877a0fd338920e1a7ae4434c47caVirustotal results 30.16% Heodo
2020-01-23REP_R0X2P9NXI9F1.docdoc e63aa1c3401d847d86e7d7a0183b1b09932060991feb79d6e2b775a27f30c36bVirustotal results 30.65% 
2020-01-23INV_25967742.docdoc c78e3b88c08a9425cc9d6043a9d20e85c160e556a37f57f3f2515cb894c33316n/a Heodo
2020-01-23RP_35663742916722360036.docdoc 066b3bba6e179d954dbe050f3bd5bcdcd20e8d6957876521dab3d7dfd5226e59n/a Heodo
2020-01-22BAL_135427726940249906739.docdoc 62fb677b5e795566ed8b06713d070488a08cffaccd527993f327cb931929ea2eVirustotal results 29.03% Heodo
2020-01-22PAY_JNL_010120_POO_012320.docdoc 669eefc104d806bd76c96aea4774af65b2fdc557d7bb93f72910014b7093d9c3Virustotal results 26.56% Heodo
2020-01-22V_BVQ_010120_KOL_012220.docdoc c551f97351c13e0f158f87d3c11bbdb5b9f2b2b10576509755d225e3f3bf46c7n/a Heodo
2020-01-22PAY_12044842.docdoc 760da2cf865d8c30de733432733cd907c4d3473c8c956b337785f76899801383n/a 
2020-01-22INV_58275852.docdoc 48837191ab344d85521d4c195d900ccb894eacb24779ec2abc8464d8f2de769dVirustotal results 26.56%