URLhaus Database

You are currently viewing the URLhaus database entry for http://cisco.utrng.edu.mx/wfpagconemail/qz-n9j0v-35/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300351
URL: http://cisco.utrng.edu.mx/wfpagconemail/qz-n9j0v-35/
URL Status:Offline
Host: cisco.utrng.edu.mx
Date added:2020-01-28 20:04:48 UTC
Last online:2020-04-13 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-28 20:06:09 UTC to abuse{at}uninet[dot]net[dot]mx)
Takedown time:2 months, 15 days, 10 hours, 10 minutes Bad (down since 2020-04-13 06:16:15 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-30invoice Y6_5346836.docdoc 4dc4fe4384631b43917164df8030cc23abb5e5a81ea9e03cc22418650399697bVirustotal results 34.38%
2020-01-30INVOICE_097_984605.docdoc 2e05dae96f07956982b9edba6d64d8668b4ff90f56d548ce2ef2feee40a6e6d5Virustotal results 39.06% Heodo
2020-01-30Invoice-SPWG8723_35355887.docdoc ea0054ea77bae531dfe21c9c57ed960e3fdea5d9d5472e752c8cb6e12589e6f1Virustotal results 35.94% 
2020-01-30Invoice-O05_47479237.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30Invoice-QG5829_697027246.docdoc 9e09d9765d276107e2b31f2d02ad5e09e72dd259f6dfe01401ec33ee1343f659Virustotal results 35.94% Heodo
2020-01-30INVOICE_K27_324609788.docdoc 4a3077b819873dbaed2f26fd4cddd843ea14f4c339f797b60eae4543fe33971fVirustotal results 31.75% Heodo
2020-01-30INVOICE_LDUO5142_133401.docdoc d204a8808c41d9dbf3ad604139c838f916986ce563143b7e41b33c85d22d5973Virustotal results 31.25% 
2020-01-29invoice_47_773789.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29INVOICE K7452_0315291.docdoc e14bd51bea91be160aefdfd75c853ce85ef348e87400f0d1e14b64c7d46eb748Virustotal results 33.87% Heodo
2020-01-29invoice-N967_090173867.docdoc 829a7809009f98e48474acb1055638a301574dc66340f546a4f96029e8a6cb9aVirustotal results 29.03% Heodo
2020-01-29Invoice_SCU7640_725815.docdoc 3bdbcccc69e55ca69203cb80868675eb9aed4e2e9f880d181e51bb341905b8b7Virustotal results 28.57% Heodo
2020-01-29Invoice RMV87_6340091.docdoc d965b7c533614e4ad1f1a9090edd5e83a4f4aae50a67b1ab1158ceaa31cfe7c0Virustotal results 29.03% Heodo
2020-01-29Invoice_EI3_428636.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29invoice-UXB2_92089564.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 26.23% 
2020-01-29Inv_26_3317499.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29INVOICE-LFSW43_55936192.docdoc e8eb03b874c14f0429931aa7f367e9b480b593c28963c964049ea04f6670caf9Virustotal results 30.16% Heodo
2020-01-29Invoice 31_562457360.docdoc b9b47debd4d9fb932401d580847e8c3f82b770c5163dbc7d405aefb5cc704a1bVirustotal results 31.75% 
2020-01-29Invoice_X913_531339182.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acn/a Heodo
2020-01-29Invoice-KI3_967293294.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-29INVOICE-WS8_113625885.docdoc 11b4519b76957b0758381f8e19c5e15d8744f7974716642aeb586c615dde38faVirustotal results 48.39% Heodo
2020-01-29Invoice-0_241615454.docdoc bdcef0f16c70086414ff95b69fdbbe7eb0c9814308d3d60143b6c04dfc077257Virustotal results 45.31% Heodo
2020-01-29invoice-WN0815_012040611.docdoc f6879431b901df789082452c1c4ffa29e857d247886e421df6dda5fb3d81ca5eVirustotal results 46.77% Heodo
2020-01-29invoice UIZ351_9219153.docdoc 4a821bdd3d078f334c0bd64c125a412ad54ce14cdf5216cfed93b6ac8401d318Virustotal results 46.88% Heodo
2020-01-29Inv_WUJ9205_7498666.docdoc 625e7b72b661f68bbc6f9a8a239493da25a89950c889cccd2b932caa1c4c262aVirustotal results 29.69% Heodo
2020-01-29Inv-AWZ7_8428641.docdoc c25db0a6d33ba3de2ea0ea992b98117d92ef8cc0a1dc6d9ff79788db6ce7e06eVirustotal results 47.54% Heodo
2020-01-29INVOICE-3_7505343.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42Virustotal results 43.55% Heodo
2020-01-28invoice_ONJ6_9451349.docdoc 2670e2793f3201f878062eec012e75339c95dc6a1227841ef1bf5b4d75f80525n/a Heodo
2020-01-28invoice-EODN1038_894507083.docdoc 3c87c41114630323c1a79456c39fa136247e72658a8705be092b29bec2a5b374n/a Heodo
2020-01-28invoice_LONC822_1075706.docdoc ce91dee8cd26edf5a8b2284d0c4cf386715f7e9385fbea5a17b3f3af941ff8a4Virustotal results 40.32% Heodo
2020-01-28Inv_KC2966_61713766.docdoc 6b6b55a8699e5412e3cafc9af9ad6a4aa5fe584da243510c904ffdf20241506fn/a Heodo