URLhaus Database

You are currently viewing the URLhaus database entry for https://icapture.app/wp-content/plugins/privado_177171353699_zIOUL6yDKQzNOZ/individual_warehouse/93483240_zbijVHw4WFLti1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:306648
URL: https://icapture.app/wp-content/plugins/privado_177171353699_zIOUL6yDKQzNOZ/individual_warehouse/93483240_zbijVHw4WFLti1/
URL Status:Offline
Host: icapture.app
Date added:2020-02-03 10:22:33 UTC
Last online:2020-03-13 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-03 10:24:02 UTC to abuse{at}microsoft[dot]com)
Takedown time:1 month, 9 days, 5 hours, 5 minutes Bad (down since 2020-03-13 15:29:14 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05oferta R2S85193096592 210401762934.docmdoc 98dc3cf8f0160c57b835094dd12a384ec44961938a9876d13a87bb1e444d4036Virustotal results 24.59% 
2020-02-05OFERTA 02_05_2020-553569.docdoc 46529e473f1dc76c028e9d23e9b51ab7dca3b2f86cab1cf88db1fc504aca4705Virustotal results 25.86% Heodo
2020-02-05FACTURA-nn2n642o250.docmdoc 2680ccc11a0001f2af126f851b3389dd62ebf81afd0e72ce2dde130c37a48578Virustotal results 25.00% Heodo
2020-02-05Factura 5635.rtfdoc a9d9d090c46571aac592ac8ab969a6c1f70c729927d1c863b3ed327c286b3b5dVirustotal results 23.33% Heodo
2020-02-05Factura-45p0104qpp77q87.docmdocx 49935d065197043a5954f5c0af2fde686f0dc8e83a648ca5377b249246310ddeVirustotal results 36.07% Heodo
2020-02-05FCT 02052020.docdoc aef911d16e36d3d8410cec34d4f72340a3e3d7614f0547588132f79b66935e5fVirustotal results 35.48% Heodo
2020-02-05factura_K97095655-8403.rtfdocx af1accc87f852c4f806095f124f7e9c581c7f305338551cadce72b80c02ab373Virustotal results 34.92% 
2020-02-05facturacion-02_05_2020 C2524736.docmdocx dcdcefae226e1eccadad30728bc5d5a86fcc042676c0e98078e62ccd82b564d2Virustotal results 33.87% Heodo
2020-02-05fct-7708513.rtfdocx a25acb77ff59454781d30445e527d286c6b22fb2040cc8e0c0ae31e14c603e5eVirustotal results 30.65% 
2020-02-05FACTURA 868781444.docdoc 0eeaeab309fee32e71f3c9e221e6583285eac868bd06ee8bd594d06621c97e16Virustotal results 30.65% Heodo
2020-02-04FACTURA_48249890-356584313607.rtfdocx 6464ea34b63546f7d2cdcb780b772b1250731bd38c105c2feb70e0928d49b1abVirustotal results 32.20% 
2020-02-04fct 02052020.rtfdocx 3e807f7cb48c71df4ce8ba0a0024238ec14712f1e68e7d0c959ab376f2fbd524Virustotal results 32.76% Heodo
2020-02-04fct 02042020.rtfdocx 03657e4b0103d718978b4736846da1ebdd18f8ba892ff4709eabbae4d7f14c10Virustotal results 32.81% Heodo
2020-02-04FACTURA_B14956567760.rtfdocx 6773f2d12cac7fc60b6b05a0ad90ea189f3479d0c7e8eb0ed642722077ca9bd5Virustotal results 35.48% Heodo
2020-02-04Factura 02_04_2020 EA79791104.rtfdocx b652230d0ab5eba2fd05573b7ef10013f6563c1bb9f64d5f5106b15cc8a5ade7Virustotal results 31.75% Heodo
2020-02-04FACTURA 02_04_2020_4A593898474.rtfdocx 265e4a2697fbfecc43edb76419d9e4a8928492d01b548cd7d6804226d6b2a593Virustotal results 37.10% 
2020-02-04fct CI603341 52323473134.rtfdocx 786563efb876e891aa804967d96e0a176417ad2c731e93a1fd788cc7d15d57a7Virustotal results 37.70% 
2020-02-04factura_791mpop0q1p70.docdoc bcd2e7bff910e30d17d51c87683d5d167b62abe697d788a5e188ecc0aa3e938cVirustotal results 37.10% Heodo
2020-02-04Factura 5R91919296.docdoc eae488ffdb03ebc22a57d1d52d7800cd8353390239b1572d79632416250516b0Virustotal results 37.10% Heodo
2020-02-04Factura-02042020.rtfdocx 4797cddac2f4b88206c147e98842f78fb081f26db474df81a02a7a05c59865beVirustotal results 35.48% 
2020-02-04FCT-02042020.rtfdocx 3e2e9a5442d6c6826dad3dd23433234eb8d095c3ee6f0cde53e92e675e6f8822Virustotal results 36.67% Heodo
2020-02-04fct-002136069.rtfdocx 688882f12cad25b5869ed921e7bccf6be7bf06dd9aaab5d15bb25ba0b9091e16Virustotal results 35.48% Heodo
2020-02-04fct-97183851437.docmdocx 984f78a258a00908226548dffffe34e73ede38e1eeab45004cbab8430d705c71Virustotal results 34.92% Heodo
2020-02-04FACTURA 75637094194.docdoc 29d71c405f029109b5b6a5eb51f5f957a706b5130105c3abd7e3e97cccc66c2dVirustotal results 36.67% Heodo
2020-02-04FCT-02042020.rtfdocx 858ee445063f1b88571bdab7e35dd7dcd5a6d9eee82259333dc76b277a2c4c81Virustotal results 33.33% 
2020-02-04FACTURA-J8077771440.rtfdocx 3df4c20b912377bb69db29aaf085b27d9eadd660678c6c0d113a502c36257532Virustotal results 33.33% Heodo
2020-02-04Factura WR3135779416897.docdoc e0003bc39eb6a8c1288eabb6b7de7c0f6d65c4e1cf27ef6080454807fd8a0726Virustotal results 38.71% 
2020-02-04facturacion-02_04_2020_EG8456954157.docdoc c1930d674cd5a16025ce8267497e1c2f5004cced1042af0dc4106caadb5db41aVirustotal results 38.71% Heodo
2020-02-04FACTURA RL9369.docdoc 8143fbcde0aa33fda4259a4da03b0f205f9577ebc92d9dc186cb20a1219de133Virustotal results 38.10% Heodo
2020-02-04fct_26017922.docdoc 05ead2ea8d0ec1dfd4f5b491661af731b41e275c0471f7f733cd097b544413ddVirustotal results 38.10% Heodo
2020-02-04factura-A89501.docdoc b5bdbfe46cbe25168c809c0da1cd3018bef7e7821ead2808e7b22f4a01d76a34Virustotal results 38.10% 
2020-02-04FCT 02042020.docdoc 133d966b980eb291760a47d0e9344a2900a4917c5983c098292115d55f6c8bc4Virustotal results 36.51% Heodo
2020-02-04Factura-0q44nqqmm57547.docdoc aa3931cb2f3ab736b14ffab1da3e306231e5ca42842da644913c4ba7ed5730b2Virustotal results 35.48% 
2020-02-04FACTURA_O8006348.docdoc 96ca41fe85593ec2adee71cbe9ddeae3c084689d3bd049ba0b3a548895583c11Virustotal results 33.87% Heodo
2020-02-03fct-5YV37065.docdoc f1ca3ac8b29ff318670eb9fec48430c20bfd5c159a0e78ea322110f711f0b3caVirustotal results 32.26% Heodo
2020-02-03Factura 02_04_2020 413908.docdoc d48d382a360c44f8990a525f7ee79c00056b9091d438e3d641396d8353374bben/a Heodo
2020-02-03Factura_02042020.docdoc 638b50da8c574f4785910dca412d1afe1520c754d676c4f8838455d0de5d637cVirustotal results 32.26% 
2020-02-03fct-YAF0435 99323273.docdoc a76a7c2029ae2435701beb379d26d8d9d8d033af5dc49715a117b071173d4da0Virustotal results 32.26% 
2020-02-03FCT_02032020.docdoc 07203376cb50ab736270e81db3c3c4503371a701b5015e88407c407326388750Virustotal results 31.75% Heodo
2020-02-03FACTURA 942135043.docdoc 5f570674404dafed0028b479c8a05c8d21186b07e803f2837cc21ed2e4708139Virustotal results 31.75% Heodo
2020-02-03FACT-o9o74p9nm6m0606.docdoc 9681ccc3cf58b12d30d0c4be40f0de86eaa804c3f72922a4e654956134e1b831Virustotal results 31.75% Heodo
2020-02-03factura_4989.docdoc 0768e6328bee4367126b667fb15ade01f9437381461015bc3b02ab3f79331e92Virustotal results 31.75% Heodo
2020-02-03Factura_54579057.docdoc d33c0e00439f2ef24087636b3317355dee8eb2fa050ec652a5b795c996bb9b03Virustotal results 29.03% Heodo
2020-02-03facturacion 0055197.docdoc c395f4d101a2ad5ed466a19426a403517c2bdc222651eaa30a43f69f4018b239Virustotal results 30.16% 
2020-02-03fct-292760162.docdoc b4665fed3f0c1383a203a68b4e4363b2ffe0b0f8228bfed2918b348bc3ffb3c9Virustotal results 30.65% Heodo
2020-02-03facturacion 02_03_2020_742840813812.docdoc 54142f6a4088f1e334d28ce28d0eb17d62a9f16b5b330bdec8385c0fad13410dVirustotal results 28.12% Heodo
2020-02-03facturacion_02_03_2020 83073182456.docdoc cf002d8e3a082ed12669b0a95e70005be5370c27373b2ea6d34f4a28f21ee89eVirustotal results 27.42% Heodo
2020-02-03facturacion_02741973587.docdoc c908b4456eedd3d4dfe7c3927e3c60a671bebac4a03c64cf040e61ba615da1aeVirustotal results 26.56% Heodo