URLhaus Database

You are currently viewing the URLhaus database entry for http://barbearialumber.tempsite.ws/5qbqm/payment/qu7cblkms/z6345030ofdbpx281x3ji1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307211
URL: http://barbearialumber.tempsite.ws/5qbqm/payment/qu7cblkms/z6345030ofdbpx281x3ji1/
URL Status:Offline
Host: barbearialumber.tempsite.ws
Date added:2020-02-03 21:36:05 UTC
Last online:2020-02-06 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-03 21:38:02 UTC to abuse{at}locaweb[dot]com[dot]br)
Takedown time:2 days, 16 hours, 25 minutes Poor (down since 2020-02-06 14:03:08 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05FILE_YDU_020120_KRR_020620.docdoc 4a8b904c0e37f5d18ac7b2253fbdac96104cdbe8d6abb59931755d421acd0323Virustotal results 28.33% 
2020-02-05DOC_95756801.docdoc 673c797d98f51cde7646ced229bfc6659c113e31034164ca4b98ec2fb7fb962cVirustotal results 27.42% Heodo
2020-02-05PO_02052020EX.docdoc 51f2b93199de9c30c9bfbd4d61ff8f2e8023316889f5d5fd89feeb6628609c5fVirustotal results 28.33% Heodo
2020-02-05REP_LX0613131146TR.docdoc faedc21081745a1610af2e805463f2f03e4cde28994a053c89c45ef4857f6367Virustotal results 26.23% Heodo
2020-02-05PO_02052020EX.docdoc 856a01cde80deb29aa6ccd3a49b1cbc04e7d99397cb9406413362309f1eef033Virustotal results 27.87% Heodo
2020-02-05REP_PO_02052020EX.docdoc fcb570d8d855f669580ff9de27c85f2a0bcbf2563ea608b49f4bd44846e2fe4eVirustotal results 28.33% 
2020-02-0547681977701835.docdoc e8172a18f6d7f0bd45a2e199d48ed24cba4c034a6268aa3312dfe6649a8b3c9aVirustotal results 28.33% Heodo
2020-02-05J_PO_02052020EX.docdoc 94a32d5b1828fea51d1567667ef6ad3b729c447ea079a49439e9a327f9dc2c13Virustotal results 30.00% 
2020-02-05PO_02052020EX.docdoc 1c96dc2ca50755af8de45649f800c5bc8afe690dec831035e2c9c004447e2e63Virustotal results 35.94%
2020-02-04B_PO_02042020EX.docdoc 360ffe599f41e4707c6584c2b44f4818de16367d5f4e7f2f8f46ee374dfe7b24Virustotal results 35.48% 
2020-02-0497633954.docdoc ace8c92e451556996c866189669d1e1366891923c167590ad67a29f46a35e250Virustotal results 34.92% 
2020-02-03BAL_BTF_020120_RVB_020420.docdoc 7e6804aae6a6cb80304cf2e4c3ac3302a2b9a95418063cf427cbd6823b8faf8fVirustotal results 31.75% 
2020-02-03TBXF_PO_02042020EX.docdoc 4d8af33fb65279b99b6e5cbb73083b8b96f74af4fe3197bfb3a21fa71d9b86a5n/a Heodo
2020-02-0377674568.docmdocx b5df694c837bbc541082fb7f88283effad9524b3449c71b5a02e30a4d9201261n/a Heodo