URLhaus Database

You are currently viewing the URLhaus database entry for http://falcannew1.nncdev.com/fkejsh742jdhed/uWyJV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303739
URL: http://falcannew1.nncdev.com/fkejsh742jdhed/uWyJV/
URL Status:Offline
Host: falcannew1.nncdev.com
Date added:2020-01-31 07:03:05 UTC
Last online:2020-02-01 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002288821 created on 2020-01-31 07:04:05 UTC)
Takedown time:1 day, 0 hours, 7 minutes Poor (down since 2020-02-01 07:11:31 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01invoice DQ66_28395021.docdoc 95844f4f136d6f40bcfb49dbec7bf5a74bf6bfd460fbe68b5781251921d4f3d7Virustotal results 39.06% Heodo
2020-01-31Inv_AY4983_9213917.docdoc 7f63ac26d5fec1558b8261f76c16ea58e8787e2fa179df2844136feb2ce0c650Virustotal results 34.92% Heodo
2020-01-31INVOICE 18_188605.docdoc 1c1ee91ce47a73525fb005c941777860af76c0ce946b7e56c26d920e9cfd2c25n/a Heodo
2020-01-31Inv-SBNJ9389_95005403.docdoc b777b2c1bf49b5a05bd8241ae61fbcfa3c3c96cd899ef9ff4215bc6121945da2Virustotal results 22.22% Heodo
2020-01-31Inv_GGSA203_98170375.docdoc 8e0afd2fa4abbe847f9ff21eb7ac55c920eb69a98ebf7d214cd28aa32d5a5eccVirustotal results 26.56% Heodo
2020-01-31Inv-YV91_84707613.docdoc cf5dba5032b0f5bb0d64f3622bfeb7e35d27c6892d6ba1daa6f07cae87b1566eVirustotal results 20.31% 
2020-01-31INVOICE X361_2122588.docdoc 02d0fca16499272621f28342b9c41dfc3c6133eb9cc3d485b8334de09bc9825fVirustotal results 22.03% Heodo
2020-01-31Inv_GWX204_787419.docdoc 322bc97effba52663f35f592be159313057162f0b75287845c440a3971648cb7Virustotal results 20.31% Heodo
2020-01-31Inv-64_15978135.docdoc 0668a44b54d70499bb0ba03c8fc66fe388ac0acdbb91c6284ea3683c00aad183Virustotal results 17.74% Heodo
2020-01-31Inv-404_779996838.docdoc 21b6e7719a2afa773453d60937aa333af8e41f515ecf2f2f50301c235971e447n/a Heodo
2020-01-31Inv-TZO2266_446202515.docdoc 64fed04221b3089f9ca965d7265619bad9d87b2d65ce2f55c04e3f3f95c5db4dVirustotal results 20.31% Heodo
2020-01-31Inv_E72_56317804.docdoc 3787564ed34e427bb2a2d38b16eb007660f36dffcbb6a32b4f38768073b582feVirustotal results 20.31% 
2020-01-31INVOICE-1983_9732785.docdoc 5e9f66f7ee673f539d6a0794dde83bf8650fb3f4071f1a1df569f39f2ff49bcdVirustotal results 20.31%