URLhaus Database

You are currently viewing the URLhaus database entry for http://barbearialumber.tempsite.ws/5qbqm/open-section/special-area/0364830393-lnL4Z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307206
URL: http://barbearialumber.tempsite.ws/5qbqm/open-section/special-area/0364830393-lnL4Z/
URL Status:Offline
Host: barbearialumber.tempsite.ws
Date added:2020-02-03 21:18:16 UTC
Last online:2020-02-06 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-03 21:20:03 UTC to abuse{at}locaweb[dot]com[dot]br)
Takedown time:2 days, 16 hours, 43 minutes Poor (down since 2020-02-06 14:03:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05MES_20200206_6945.docdoc 3e6d13ced0c59f5cce346c73c16a55e8e21d776c8202b53d0582dbc4e3a413c6Virustotal results 26.67% Heodo
2020-02-05Mes_2020_02_05_4886.rtfdoc 1566745273aeac5249400c456f82b70e870825a50ee2457479f734c7686dfb54Virustotal results 26.23% 
2020-02-05inf-2020_02_05-43702.rtfdoc 59dd4e381b291b460fa9a19705f59aa130ec42495f72ac9010d417197166b58cVirustotal results 26.23% Heodo
2020-02-05Arc_053555.docmdoc c0b9c90ce017a4e5196e744c7948464ff57431da4a1d820793c5aea57cc0a095Virustotal results 26.23% Heodo
2020-02-05DAT.rtfdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05Arc-2020_02_05.docdoc 4e9d937166cd42420f614c15815437f51a3f4495168be46b033e76783976e180Virustotal results 26.23% 
2020-02-05Arc_2020_02_05_656.rtfdoc e9de053b8046e662771b320b25a49cd709591ac896fb6bd4c324ba0b13f37b35Virustotal results 25.00% 
2020-02-05List 2020_02_05 934.docmdoc ab556aef3f7baf74127e682541cd5bb674af38a62c4c1f89ff43f09388894af2Virustotal results 25.00% Heodo
2020-02-05rep-20200205-IV0273.docdoc e017e89646b0d091bc67504f4318ea078b5a279edd898f418ff735e40c432e28Virustotal results 25.00% Heodo
2020-02-05list_2020_02_05.rtfdoc 4a45120dce1cd34a211f66e94d6a16a0e567d8aa85527c6fa830f99691cd1816Virustotal results 24.59% Heodo
2020-02-05Mes-20200205-EW7244.rtfdoc 4e82c0983f4287199416515585b3322785209242527d21f73fc1213fac0da816Virustotal results 25.00% Heodo
2020-02-05mes-20200205-DK122.rtfdoc 544e09d5a19e01f91c458d3b56a2dd3aa5d6623ea0857a3a56662454bd417dedn/a 
2020-02-05Doc 2020_02_05 CY522.rtfdoc 8da9b64f05685802f69618feda838a3f4331363e5e7ad48cc004353b8a4dac2cVirustotal results 25.00% Heodo
2020-02-04file 20200204 SUQ96586.docdoc ce8eb63345280d1325f0c238ee972e035dae857560a8092478c2d7029db2b81cVirustotal results 34.38% Heodo
2020-02-04LIST K853628.docdoc 96ca41fe85593ec2adee71cbe9ddeae3c084689d3bd049ba0b3a548895583c11Virustotal results 33.87% Heodo
2020-02-03ARC_EY31597.docdoc a958c01598fe12500a80df8027f579420835f95b60f2d55b885127d396e6196bn/a Heodo
2020-02-03Doc_7567.docdoc d48d382a360c44f8990a525f7ee79c00056b9091d438e3d641396d8353374bben/a Heodo
2020-02-03FILE-2020_02_04-465.docdoc 9c9fadcae991b82a9da862deb49c4a788b2632132d4a8c82b61512fdf86bc32bVirustotal results 31.75%