URLhaus Database

You are currently viewing the URLhaus database entry for https://ibernova.es/OLD/lZNcr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:301950
URL: https://ibernova.es/OLD/lZNcr/
URL Status:Offline
Host: ibernova.es
Date added:2020-01-29 22:56:04 UTC
Last online:2020-02-01 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-29 22:58:07 UTC to abuse{at}oneandone[dot]net)
Takedown time:2 days, 22 hours, 19 minutes Poor (down since 2020-02-01 21:17:17 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01invoice-KI5959_9683818.docdoc 31402643e512568e115388034fb750e63e8b514df1ee16bea716c119fa99554fVirustotal results 34.92% Heodo
2020-01-30Invoice_RBSR8_304956.docdoc 228960ea68978d82cf8f245946c0522095c90c78bd4a188a620e87d306c2619aVirustotal results 34.43% Heodo
2020-01-30INVOICE_Y33_5505082.docdoc 9755ef1672fe2fea84ded8999cf71bd62d9a3873bd4fa6ddafab57f59f0527f4Virustotal results 33.33% Heodo
2020-01-30invoice 950_865042.docdoc c2f41be5de64b96803bc308b3839583b6a786b8bb404aa5e2c775b595272e2e2Virustotal results 34.92% Heodo
2020-01-30INVOICE-CIS537_289833476.docdoc 0cd2361c959ed9e7e67f305e10241dac8c04cf6aa8816a02fa0ecd57f3b8e66eVirustotal results 35.00% 
2020-01-30Invoice_10_3408066.docdoc 2e05dae96f07956982b9edba6d64d8668b4ff90f56d548ce2ef2feee40a6e6d5Virustotal results 39.06% Heodo
2020-01-30invoice_CXO8036_4804657.docdoc 4817eb0931e095dcd5ad20af4725b2da9bb8bd800841f34789aee319897eac87Virustotal results 38.71% Heodo
2020-01-30invoice DRB854_06589689.docdoc 55f4b1324dcf648c873b70518a37777563890c60c108b2a3eb40eaa7f5f2f90cn/a 
2020-01-30invoice_TU52_980281687.docdoc 35b7d39e8f33f3118f3d205355b739038483d471119ac6d7712d92ad982c756fn/a Heodo
2020-01-30invoice-W0_2950479.docdoc c5a0f28856e753658d7979a6ab18b47e0a0b4166332f19e992f0091bdc09afe8n/a Heodo
2020-01-30INVOICE_Z3_702594.docdoc d204a8808c41d9dbf3ad604139c838f916986ce563143b7e41b33c85d22d5973n/a 
2020-01-29INVOICE 19_7293903.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 24.19% Heodo