URLhaus Database

You are currently viewing the URLhaus database entry for https://ibernova.es/OLD/open_box/corporate_cloud/KlU6x6BeHLEL_zqaidjJ5G/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307235
URL: https://ibernova.es/OLD/open_box/corporate_cloud/KlU6x6BeHLEL_zqaidjJ5G/
URL Status:Offline
Host: ibernova.es
Date added:2020-02-03 22:05:19 UTC
Last online:2020-02-04 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-03 22:06:15 UTC to abuse{at}oneandone[dot]net)
Takedown time:22 hours, 54 minutes Good (down since 2020-02-04 21:01:05 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-04dat-20200204-W0192.rtfdocx 226e3d9397801a0c20fc12e65373887d6b8e32d5d47ea818a8b891be4513e330Virustotal results 33.87% Heodo
2020-02-04inf-U788271.rtfdocx b652230d0ab5eba2fd05573b7ef10013f6563c1bb9f64d5f5106b15cc8a5ade7Virustotal results 31.75% Heodo
2020-02-04file-2020_02_04-782.rtfdocx 265e4a2697fbfecc43edb76419d9e4a8928492d01b548cd7d6804226d6b2a593Virustotal results 37.10% 
2020-02-04ARC-20200204-H348666.rtfdocx 12edeef0065331ab3b8644b9c14a1267b266a96e33ad20e9055315c454b750a4Virustotal results 37.10% Heodo
2020-02-04Doc-20200204-CR04016.docdoc a22639097a957b8debdfb4ff182eb2b6a288368b09b8427853ed91346b687737Virustotal results 35.48% 
2020-02-04File_2020_02_04_AN20587.docmdocx 8abe3476f2e6ec41653192f2adc6b6095371ddb2fa46044e4e8644c6e5d9694eVirustotal results 36.51% Heodo
2020-02-04arc.rtfdocx 167323f590c8eea01e897581a3de8e00606c176ff6518fd3ac0a3d64dd2e7d9aVirustotal results 36.07% 
2020-02-04rep-K19649.docmdocx 4797cddac2f4b88206c147e98842f78fb081f26db474df81a02a7a05c59865ben/a 
2020-02-04MES-6918984.docmdocx 66fbfabc52fac899652f0e490be589ec3d3c5d3cf233ca24171ab6d8ff55a50dVirustotal results 34.92% Heodo
2020-02-04File 2020_02_04 I87461.rtfdocx a2af1039b0c9e8636d89d189de0aad64528f566301920152cf493d54409dac79Virustotal results 34.92% Heodo
2020-02-04LIST-20200204-1302.rtfdocx 29d71c405f029109b5b6a5eb51f5f957a706b5130105c3abd7e3e97cccc66c2dVirustotal results 36.67% Heodo
2020-02-04ARC 20200204 BLH1596.rtfdocx 002d694ef8bf683023d2285a4a16c1673c4ac35874c13d7cfd9c9dc9cee5854cn/a 
2020-02-04INF_20200204_XJD07422.docdoc ad8378e53d696009088bac02740db29e5b3dff662dfa7428beac4579883ec894n/a 
2020-02-04INF 2020_02_04 23630.docdoc 7769ae1cce4e29c3e8bd982600d46a07804c1f66a2772bf00ea100aa24c227baVirustotal results 40.68% Heodo
2020-02-04DAT-20200204-11721.docdoc 29491ddd0bc6524e587ecd0b96b028af1e3a7996aba626f810e4e1ee04f233a2n/a Heodo
2020-02-04Doc 20200204 4697.docdoc 0c5326e304b5b23196b990d4ba1000e7a34150acbfa3b3cd8aaa35a12f124e26Virustotal results 38.10% Heodo
2020-02-04Rep-0017209.docdoc 821d5e01c6a22bf01f87a2cc063615e17a74dd2599e21bb6ec2de779f77c8d08n/a 
2020-02-04Doc 20200204.docdoc b5bdbfe46cbe25168c809c0da1cd3018bef7e7821ead2808e7b22f4a01d76a34Virustotal results 38.10% 
2020-02-04File.docdoc b0bb80de572b15a0b0de99bed596703ce05859027b0b5a001b36eb8927608155Virustotal results 35.48% Heodo
2020-02-04list_2020_02_04_8524.docdoc 96ca41fe85593ec2adee71cbe9ddeae3c084689d3bd049ba0b3a548895583c11Virustotal results 33.87% Heodo
2020-02-03Arc-2020_02_04-ZXP401687.docdoc a958c01598fe12500a80df8027f579420835f95b60f2d55b885127d396e6196bn/a Heodo
2020-02-03file_2020_02_04_264.docdoc 32601541d9a5b0512df0c2ac1811b636c97e5fec9f916ba37810c0afa605b06dVirustotal results 32.26% Heodo