URLhaus Database

You are currently viewing the URLhaus database entry for http://relprosurgical.com/wordpress/HoBvvbwOa/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300577
URL: http://relprosurgical.com/wordpress/HoBvvbwOa/
URL Status:Offline
Host: relprosurgical.com
Date added:2020-01-29 00:18:05 UTC
Last online:2020-01-29 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002283560 created on 2020-01-29 00:20:05 UTC)
Takedown time:18 hours, 50 minutes Good (down since 2020-01-29 19:10:51 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29Invoice LVJ4370_68968151.docdoc 3bdbcccc69e55ca69203cb80868675eb9aed4e2e9f880d181e51bb341905b8b7Virustotal results 28.57% Heodo
2020-01-29invoice-DVRM1914_900229.docdoc d965b7c533614e4ad1f1a9090edd5e83a4f4aae50a67b1ab1158ceaa31cfe7c0Virustotal results 29.03% Heodo
2020-01-29Inv_M732_7930190.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29Invoice_HXL6_85710204.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 27.87% 
2020-01-29Invoice-27_466203185.docdoc 9ab92e41150dd1c132be3b79097a4b4fff2a151a9a5d77bd3e0aaeb41a5b862bVirustotal results 26.23% Heodo
2020-01-29Invoice-N1067_566835166.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29Invoice_JSAX8_95852123.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29invoice-6_6043540.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29invoice_BHL19_811945.docdoc c135f36d3346699e6d2bf9f5f5f638fd9475c0b12144a15a0652b8f1ebb25c12Virustotal results 40.62% Heodo
2020-01-29invoice-HKSY644_639841.docdoc 11b4519b76957b0758381f8e19c5e15d8744f7974716642aeb586c615dde38faVirustotal results 48.39% Heodo
2020-01-29invoice-V5_4655777.docdoc 4a821bdd3d078f334c0bd64c125a412ad54ce14cdf5216cfed93b6ac8401d318Virustotal results 50.85% Heodo
2020-01-29Invoice-TQE0786_494381881.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42Virustotal results 43.55% Heodo