URLhaus Database

You are currently viewing the URLhaus database entry for https://benjamin-moore.rs/js/bSR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308865
URL: https://benjamin-moore.rs/js/bSR/
URL Status:Offline
Host: benjamin-moore.rs
Date added:2020-02-05 09:30:41 UTC
Last online:2020-02-08 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 09:32:03 UTC to abuse{at}oriontelekom[dot]rs)
Takedown time:2 days, 18 hours, 4 minutes Poor (down since 2020-02-08 03:36:37 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07Invoice-OC6248_107089.docdoc dd04af02f66e58ab249d6557bb5bab0093b815b7a27bc31d524bde99ee180631Virustotal results 22.95% 
2020-02-07Invoice 90_8629255.docdoc 00b524435a1e4b70e1783600f6ba01545628bacd15c00154b232bd464f1de19an/a 
2020-02-07Inv-ITM12_255614.docdoc 87cddb2b6d7ac63adb0e2d442b7cf006247f8eb8f7e7f7518c9f7524a9ec5fdcn/a 
2020-02-07Inv_CJ76_131521102.docdoc da55d54edd3021ebaf41530e1ec8dd18fb5541bb09c3cc9d10c88e9da0351409Virustotal results 32.79% 
2020-02-07Inv RBND775_361272.docdoc fabe5daadc59a858e5152921d00a9134c5f3202570daf8fa151f214455e84879n/a Heodo
2020-02-06Inv-KFUQ5_2830319.docdoc 092cafc5eaeb0e2d80004cf333e8e2d5898f25562f86323a3b31cbc1ec7b5d7aVirustotal results 29.51% Heodo
2020-02-06INVOICE-IYV8234_5318313.docdoc 0d52884323396c99de2994a867ebe7ccb325a7a33a6ae3317f4290517232a3edVirustotal results 29.03% Heodo
2020-02-06INVOICE-FYC788_701929.docdoc 4a24444820e9cbd0c73e0d97f291e4679d283f5c6fd44db547c58a37d62b4b83Virustotal results 29.03% Heodo
2020-02-06invoice-H39_5800296.docdoc af68f95640411edf06350ddc5f697fa63501dad1a427026652ba7a411e87c258n/a Heodo
2020-02-06Inv-717_9971027.docdoc 6c06954cbc088900ecf406f49cd3620cb6152c02121a754986fb65f7935bd043n/a Heodo
2020-02-06INVOICE-EOHG195_258619515.docdoc 08a17a2ca774e5d63d00d6347ab8569354e6fc33b9e65cd55db64f088125e77fn/a Heodo
2020-02-06Invoice-WY1493_9893080.docdoc a6f83c36cfcb51c3f166faff124cada228ef05461001847944061e18a897c01bVirustotal results 27.42% 
2020-02-06Invoice 720_301977.docdoc 1e5acda3a47d1de59fdc64a167095799fc156e2abd55fffad615ed48c5f6dfbdVirustotal results 27.87% 
2020-02-06INVOICE-JQDA720_86779473.docdoc 515c3515f3728002f957e469f6d30be479f3db347968856134e1f0287ad0438eVirustotal results 24.19% Heodo
2020-02-06invoice QK183_46434207.docdoc be66dbd0df63fc5a8674655349f37bec9c2b0f5299fe8227dfae94c86d2ebcffn/a Heodo
2020-02-06Inv_ZH7_1762264.docdoc d8a98e712d6775091bbcdbe1e2b1ed30135d7fcb59a9ec4ce71bd80823438c5aVirustotal results 23.33% 
2020-02-06Inv_EEY232_25833368.docdoc 1ffc37048962c0a22202bc9de2da7dc6a958458986126b58248ab622cd695f7dVirustotal results 21.67% Heodo
2020-02-06Invoice 6_74378712.docdoc a8c18ebbebf32d827afe272c7dea149e8ae38cfe2ff94043e2af6e82cad5a396Virustotal results 21.31% Heodo
2020-02-06invoice-RDGU09_2726110.docdoc c137f96ad20933f15cbd33dd13a59de4aa1b0e84ba2d9ffeca8835eb21d271e8n/a Heodo
2020-02-06invoice HI6669_707056.docdoc 12368c93f93b5feac92d01c7f620337dcbaab18dc50b27dfe2a50ebae513d355n/a 
2020-02-06INVOICE AKUQ47_149961509.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06invoice-WZ9_203350.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06INVOICE_I644_93040621.docdoc 9eca08bea00fec73f8bdc769abf28f857d39de7d922c4d0dfd4017dc5981d2b0Virustotal results 33.33% Heodo
2020-02-06Inv-ZGA7_7436212.docdoc 90250acf44f763164182f91d1d9e734ea442e491965e1c3883ed40fea09f0d2fn/a Heodo
2020-02-06INVOICE HHIW629_297332167.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05INVOICE-4015_603927.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05Inv-RT07_80095331.docdoc 2e6d60c0292605697751fd56084cb10b9ab90c135dd863bf3e428a185e050142n/a Heodo
2020-02-05Inv-4_54401860.docdoc 9a6d2baf1a6f63a692b3584aecb501ab9d2c4cf6cc5e97ed5390454ec60bc466Virustotal results 26.23% Heodo
2020-02-05Inv-Q1675_928797.docdoc 0730eae02471503c7ab9c5f470a916f7f1578c78676c2c401ecd562214e25d37n/a Heodo
2020-02-05INVOICE_2_696636502.docdoc bac64a981e3fddb119868ac4b6c14005db9b3c64f608849911d6c08947267dcan/a Heodo
2020-02-05Invoice-0292_2901103.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05invoice-YHDA722_456886.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05invoice-SHW71_9542937.docdoc 927609b9f9efb576a2233015595d50cfecd6d736c6fda23e8742330c6051e64cVirustotal results 25.81% Heodo
2020-02-05invoice-ZQ1025_63533242.docdoc 3d86715a18dc19cdf1364d58ff7deee2c387cde502de5b43166a7c0d98b2a24an/a Heodo
2020-02-05Invoice_ZR5569_419481.docdoc 4a3728fe0024a204fcc77f63d90b8963631e8e074478dcb1c5be79afaf89c639Virustotal results 27.12% Heodo