URLhaus Database

You are currently viewing the URLhaus database entry for https://www.icda.edu.do/Reportes/84du-z16-76/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300646
URL: https://www.icda.edu.do/Reportes/84du-z16-76/
URL Status:Offline
Host: www.icda.edu.do
Date added:2020-01-29 01:54:04 UTC
Last online:2020-01-31 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-29 01:56:02 UTC to abuse{at}microsoft[dot]com)
Takedown time:2 days, 13 hours, 29 minutes Poor (down since 2020-01-31 15:25:39 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31Inv-AEJ816_723534.docdoc 2cc6d361b7e889383030328341adee04da05700cfe74c15b8fefb707f07f6c87Virustotal results 39.68% 
2020-01-31INVOICE A908_196264579.docdoc 1c2d2dcc9e0140fd9e9055a697ec4c2c969590ba93a2f5ebf75bde37cc7ba0f1Virustotal results 33.87% 
2020-01-31Inv_GGYI20_81205555.docdoc ae370246a5b55b8f9dc4d3d0d7041d03f466f3d4260bf0beb48ff4dfa85a5b11Virustotal results 34.92% Heodo
2020-01-30Inv_E3077_84016459.docdoc c7970448dd12285750ec5d562765c8f494b15914f9699cc95a46f4b249f5f370Virustotal results 35.09% Heodo
2020-01-30Invoice VNN553_21093780.docdoc 9755ef1672fe2fea84ded8999cf71bd62d9a3873bd4fa6ddafab57f59f0527f4Virustotal results 33.33% Heodo
2020-01-30Invoice_650_71017741.docdoc 343861d1fd20a1d81dfe2015bacc7d3af7bce6b55515449f9053a6f15d6e4171Virustotal results 34.38% Heodo
2020-01-30invoice 5980_171690.docdoc a2c25cc5e8f8afa23325d5cd041fafa25cf6407882113ec43fe75ac3548ea8eeVirustotal results 35.59% 
2020-01-30INVOICE-WTEW669_396286.docdoc e2511be44651aece200405b1e826c57ea3f3e0fdfd2335e457b7c6a70628f1b0Virustotal results 38.10% Heodo
2020-01-30Inv-XBN9_050458077.docdoc 17a7596a2561b8ff8cc3bf7daffec3ebf35525aa363d4659cb420d42f4af92f3Virustotal results 38.10% Heodo
2020-01-30invoice EJYK06_40319212.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30INVOICE_MYOJ80_9532536.docdoc 444380961c88bf398e9078529bf648cf7f4cc69a583fea9d036c4427e533d8c5Virustotal results 34.92% Heodo
2020-01-30INVOICE-SA5328_710399.docdoc 9440498706f2d925d78ed85c677ee615fe3fdf05c7188cf59cadf543e59e0c32Virustotal results 32.81% Heodo
2020-01-30INVOICE_LU1_251944939.docdoc e88c11fe26e7cad165df54049eeb12ea47f3cbb684fb6f8a5235d4a379e646ddVirustotal results 31.75% Heodo
2020-01-29INVOICE-FVJZ56_7429743.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29INVOICE-2155_28853555.docdoc 41ef384c11051e3b98c409f476aca9a2f5a0433e0cb411f547133b5d5727044aVirustotal results 31.75% Heodo
2020-01-29invoice_TVM715_5949099.docdoc 8f114fa9732298d525aa216d90905f24142f129d79e62500f139a3c09db00fd2Virustotal results 29.03% Heodo
2020-01-29INVOICE-FSXB257_469271350.docdoc 4491676350c083084299affa5206946e8a9d6b63632f236d119e24cbd1239a38Virustotal results 27.42% Heodo
2020-01-29INVOICE-UKMH8_145931615.docdoc d965b7c533614e4ad1f1a9090edd5e83a4f4aae50a67b1ab1158ceaa31cfe7c0Virustotal results 29.03% Heodo
2020-01-29Invoice-EBG99_60390947.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29Inv-6663_160262760.docdoc 3be00db967f63065494037f5de7659deb23f83c948d103057222421fc50cc775Virustotal results 28.57% Heodo
2020-01-29INVOICE_FXW049_718356731.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 26.23% 
2020-01-29Invoice-XE287_358229643.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29Inv-TMA854_98104296.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29invoice EOJ33_779035.docdoc b9b47debd4d9fb932401d580847e8c3f82b770c5163dbc7d405aefb5cc704a1bVirustotal results 31.75% 
2020-01-29Inv-TS8922_99814277.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29invoice-FVXP0_7428520.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-29INVOICE 2537_5181902.docdoc 11b4519b76957b0758381f8e19c5e15d8744f7974716642aeb586c615dde38faVirustotal results 48.39% Heodo
2020-01-29Invoice_7944_71372856.docdoc 7a9f249978c959e1f11f2992a8ce4a70ba333c8dbdc2638c780bbbe62de4808eVirustotal results 46.03% 
2020-01-29INVOICE_I048_13428168.docdoc f6879431b901df789082452c1c4ffa29e857d247886e421df6dda5fb3d81ca5eVirustotal results 46.77% Heodo
2020-01-29INVOICE-83_29631438.docdoc 4a821bdd3d078f334c0bd64c125a412ad54ce14cdf5216cfed93b6ac8401d318Virustotal results 46.88% Heodo
2020-01-29Invoice H5741_317754421.docdoc 849aedf219a4f6ab15e2c5c653a8bbd6fce909c51d2e95984bf6241f6b939e89Virustotal results 48.39% Heodo