URLhaus Database

You are currently viewing the URLhaus database entry for http://lp.terra-sensum.ru/cgi-bin/ds2-z1w-37545/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300317
URL: http://lp.terra-sensum.ru/cgi-bin/ds2-z1w-37545/
URL Status:Offline
Host: lp.terra-sensum.ru
Date added:2020-01-28 19:08:04 UTC
Last online:2020-01-31 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-28 19:08:15 UTC to abuse{at}abusehost[dot]ru)
Takedown time:2 days, 6 hours, 37 minutes Poor (down since 2020-01-31 01:45:44 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-30Invoice RW9_65137667.docdoc 161eb9ce03a6b2a7a3a41e83574d4ff655038d2a8bcdeabba93b4a7be7912808Virustotal results 38.10% Heodo
2020-01-30invoice EWER741_756697419.docdoc c0ef60e9ae4ffd63004837885e296e68eae72f32531f67e363d5715b86d63da5Virustotal results 39.68% Heodo
2020-01-30Invoice_34_588220.docdoc ea0054ea77bae531dfe21c9c57ed960e3fdea5d9d5472e752c8cb6e12589e6f1Virustotal results 35.94% 
2020-01-30invoice-G4_83978547.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30invoice-BJO8662_142733.docdoc 4b182383cb7c2e1101c24fd3f98e78422feed3d38c125e77cd28c990e3cb4a1bVirustotal results 35.48% 
2020-01-30invoice_MRCU41_147541.docdoc 4a3077b819873dbaed2f26fd4cddd843ea14f4c339f797b60eae4543fe33971fVirustotal results 31.75% Heodo
2020-01-30INVOICE_C13_2558564.docdoc b6cafc43f6ad8188327733b7b11ff1fd69533a8af466c03c8c3d20c71777749dVirustotal results 30.65% Heodo
2020-01-29Inv 35_681882866.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29INVOICE-64_99984370.docdoc 41ef384c11051e3b98c409f476aca9a2f5a0433e0cb411f547133b5d5727044aVirustotal results 31.75% Heodo
2020-01-29Invoice-KAIO933_464779099.docdoc bd1eac417a2f82f5ed9f7dc86783678343738758322a16a7d21d77cd587a4f55Virustotal results 30.91% Heodo
2020-01-29Inv-M8456_341114400.docdoc 0e7d6a780c7dedc2d2625158cde219a2df7eb7b37a509c810644085e1781eb12Virustotal results 29.69% Heodo
2020-01-29Invoice BEBS304_4683113.docdoc 8a502f32c4e9b027761b883615a99071262858fe124e0f76a51ee65583ff4c59Virustotal results 27.42% Heodo
2020-01-29Inv UO8913_871934.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29INVOICE-BBM00_428444913.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 26.23% 
2020-01-29INVOICE S5_667454131.docdoc 6eb3be35a52b1bbd297eec41d1d5871bb1f27a225f381a75a1040eea80a20ae4Virustotal results 26.56% Heodo
2020-01-29Invoice 95_354661.docdoc 992e6e5ceb5ec8864b03020268729a5498549bd9c9067fbed53b8f3ca5474142Virustotal results 30.65% Heodo
2020-01-29Inv-ZU761_245273805.docdoc b9b47debd4d9fb932401d580847e8c3f82b770c5163dbc7d405aefb5cc704a1bVirustotal results 31.75% 
2020-01-29Invoice 58_2516257.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice_IOJE1090_787627379.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-28Invoice DW66_0125283.docdoc 8d9baf4765f0461f7f4a9079b26505d09d8657c54a3ce0f249e28b9f3d0fbf67Virustotal results 44.26% Heodo
2020-01-28INVOICE ROU7_476765.docdoc 0617b35ff84886cd395bbf20745f3b82a830d97b07b0085b0f4aa056bcd57cd9Virustotal results 42.19% Heodo
2020-01-28Invoice-0_67829339.docdoc ce91dee8cd26edf5a8b2284d0c4cf386715f7e9385fbea5a17b3f3af941ff8a4Virustotal results 40.32% Heodo
2020-01-28INVOICE TV20_36782467.docdoc e8c780bbb1f9fd071b00776b138b3cf27c3815c7203593068e78774d4dbdb36an/a Heodo