URLhaus Database

You are currently viewing the URLhaus database entry for http://fft.cl/monitoreo/gUp/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:302304
URL: http://fft.cl/monitoreo/gUp/
URL Status:Offline
Host: fft.cl
Date added:2020-01-30 08:22:06 UTC
Last online:2020-02-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-30 08:24:02 UTC to abuse{at}zamltda[dot]com)
Takedown time:22 days, 10 hours, 26 minutes Bad (down since 2020-02-21 18:50:56 UTC)
Tags:doc emotet link epoch3 GandCrab link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01invoice O572_4526902.docdoc 970df6100d8375af169bb259df2c7bb1ad641294e34ed57dc3ad02a38371b4c7Virustotal results 36.51%Heodo
2020-02-01Inv-63_411967.docdoc b225d3511dd0119fa72b7116c46dcc71459483e37ecfe6b8d33ddf8b304f69ecVirustotal results 35.48% Heodo
2020-02-01INVOICE-016_734739.docdoc 33b3ec4162e08d960a63f59db559c88ea8d64d270e61f84b3df6c1e712447831Virustotal results 36.51% 
2020-01-31Inv SFY7277_140603150.docdoc 0e515b40fbfacc6e1f632f89fda79c5bc01fce11baf9bb015aba19ede05b2775Virustotal results 38.71% Heodo
2020-01-31Inv 7924_6925119.docdoc c2cf1067ebd6d88341955a7ddf3a112cdda3f996446122f38a9e104b9eae9967Virustotal results 31.25% Heodo
2020-01-31Invoice_TNGN587_6741783.docdoc df3b6aaa924ed3e9a2eba95dac5813980820281a3c2d6d6c1c91c0a0c5294ecfVirustotal results 31.75% Heodo
2020-01-31INVOICE-VU0_219212372.docdoc 7d36bd087bf192b32fc6a40a94b79081e1d7d25d356a9697a158b29bcc1d073an/a Heodo
2020-01-31INVOICE R64_44006748.docdoc 7f63ac26d5fec1558b8261f76c16ea58e8787e2fa179df2844136feb2ce0c650Virustotal results 34.92% Heodo
2020-01-31Invoice_07_666192408.docdoc 250a161c07fa21af99dcc7a9826c78e3d508de4d26221d5bf17bf16b20abdfc4Virustotal results 32.26% Heodo
2020-01-31Invoice-FSA08_154637843.docdoc 2041559b24b2289ef8263b1c8335bd87424dc62061a72b4bfdd5525b98da6b54Virustotal results 28.57% Heodo
2020-01-31Invoice-47_797316.docdoc e01b9d1ec39ab6b746fab54011b045e107974f3d979db52766632eec495d9b59Virustotal results 33.33% Heodo
2020-01-31Inv-Q21_2311900.docdoc cf5dba5032b0f5bb0d64f3622bfeb7e35d27c6892d6ba1daa6f07cae87b1566eVirustotal results 20.31% 
2020-01-31Inv-0942_2209499.docdoc 02d0fca16499272621f28342b9c41dfc3c6133eb9cc3d485b8334de09bc9825fVirustotal results 22.03% Heodo
2020-01-31Inv 2815_555266863.docdoc 9d887063a7f3798027fe7987b0bc2141ddefde963883c48e1d3ad602fda96e0dVirustotal results 20.31% Heodo
2020-01-31Invoice 4_083754078.docdoc 8bf46746f229c482b5dbffb56a3f43f3f4b6f6dbc4be21a289e8056508bcde8eVirustotal results 21.31% 
2020-01-31invoice-TWK5_78734290.docdoc 44b0100daa5d7db6900911e8ae9c923d3c3d3490dbc7be73dab2f3206a97b74aVirustotal results 20.97% Heodo
2020-01-31Inv_5582_16320601.docdoc f550359c63fd772e162a96b872ac0926638ffc5a7e32fb1b1f8bc163d4a9f23cVirustotal results 20.63% Heodo
2020-01-31INVOICE-R219_457259.docdoc 14ff3e420b1aab26fd8d2bd41c237e96c80ec8d0423317afef8f2764dadd6a2bVirustotal results 20.63% Heodo
2020-01-31Invoice-HIJS8084_408559655.docdoc 605d7a3139166d8f5ef7e7c7acea745d2c208df433a07e161d991fd71275e763Virustotal results 34.92% 
2020-01-31INVOICE-KVCG1846_19860670.docdoc 27d755aa7bf58559ed73cec0d481fe32fe0d81d2f18da774763c0da9e5c15b5bVirustotal results 33.33% 
2020-01-31invoice-W888_5980019.docdoc 797c8a01976f70efa8f735c4a8f0d80a805578978d7f025c204d3e99a1a67d29Virustotal results 33.33% Heodo
2020-01-31Inv-7_4649690.docdoc 5f956252e9f433a4b7675b2422ef016eac5627672a114bfafbc0c667a22db5ddVirustotal results 34.38% Heodo
2020-01-31Inv-IFJE8_252729.docdoc e663621ff749e2033b4a4cda21d7cb98e6a4efbb1c21080b5238c718e9000b4fVirustotal results 34.92% 
2020-01-31Inv-GFE897_5344043.docdoc 0af8d518c01ba62f4ab1797e291f6959f027008aa5899a8ef72a85cab4830de1Virustotal results 35.94% Heodo
2020-01-30invoice-WXM471_5046371.docdoc b93c176b25e95c8538cc6e80bf1dca7b57ab9a7fe306415caed9989f1c306dd3Virustotal results 33.87% Ransomware.GandCrab
2020-01-30Inv-427_65840759.docdoc 68338a3e8777d1f7b2d7e8a7a5235a01194c8219503bb5a16ec83d01aeb5ce37Virustotal results 34.92% 
2020-01-30Inv_HB91_1504591.docdoc c2f41be5de64b96803bc308b3839583b6a786b8bb404aa5e2c775b595272e2e2Virustotal results 34.92% Heodo
2020-01-30Invoice-2_16950043.docdoc ad23200b4b35cf861876a41444203cb74f57e2be7bfddbc92b3fc7a07ecfe056Virustotal results 34.38% Heodo
2020-01-30Inv YR0039_17481603.docdoc 2e05dae96f07956982b9edba6d64d8668b4ff90f56d548ce2ef2feee40a6e6d5Virustotal results 39.06% Heodo
2020-01-30invoice VY37_673461446.docdoc 4817eb0931e095dcd5ad20af4725b2da9bb8bd800841f34789aee319897eac87Virustotal results 38.71% Heodo
2020-01-30INVOICE ZZB0404_155318.docdoc 55f4b1324dcf648c873b70518a37777563890c60c108b2a3eb40eaa7f5f2f90cn/a 
2020-01-30INVOICE_6751_996364.docdoc 35b7d39e8f33f3118f3d205355b739038483d471119ac6d7712d92ad982c756fn/a Heodo
2020-01-30INVOICE-U77_65180476.docdoc 9440498706f2d925d78ed85c677ee615fe3fdf05c7188cf59cadf543e59e0c32Virustotal results 32.81% Heodo
2020-01-30Inv 2087_212994835.docdoc 55f8abe1aef52cd16f277aa39133736e083cd33b4d8e8599df61b13e1bf9f3f9Virustotal results 31.15% 
2020-01-30invoice SILN37_459620.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 31.67% Heodo