URLhaus Database

You are currently viewing the URLhaus database entry for https://grafikos.com.ar/Scripts/2wi3b-3i-864/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308962
URL: https://grafikos.com.ar/Scripts/2wi3b-3i-864/
URL Status:Offline
Host: grafikos.com.ar
Date added:2020-02-05 11:32:34 UTC
Last online:2020-02-06 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 11:34:02 UTC to abuse{at}ovh[dot]net)
Takedown time:19 hours, 39 minutes Good (down since 2020-02-06 07:13:23 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06Inv-A83_830246.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06Invoice-3143_726627.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06invoice-IZAV186_1434167.docdoc 7bfbdbf8dda70b20e5d40d50d878d970a765a65fc39e856fb26e8c525a4a45e1n/a Heodo
2020-02-06INVOICE-5925_961316602.docdoc f64c7b18189347af96b402b6f3cb3294d4dbbc7cad63748805727ac4d2a83997Virustotal results 32.79% Heodo
2020-02-06Inv_TU2_8479458.docdoc 955266fef242bce6acb2e20a60ae98fcbe68846f196fbbabfe5304bf7c56aacbn/a Heodo
2020-02-05Invoice_QJ5564_96690098.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05invoice Y56_410215691.docdoc 2e6d60c0292605697751fd56084cb10b9ab90c135dd863bf3e428a185e050142n/a Heodo
2020-02-05Invoice-36_355171.docdoc 9a6d2baf1a6f63a692b3584aecb501ab9d2c4cf6cc5e97ed5390454ec60bc466Virustotal results 26.23% Heodo
2020-02-05Invoice-EJ0_337362.docdoc 0730eae02471503c7ab9c5f470a916f7f1578c78676c2c401ecd562214e25d37n/a Heodo
2020-02-05invoice-B7_47005120.docdoc 8376a8de56a8cd62866c0f71c3a36f91ff4af5b9d16f9056aaa8e8360af854a9n/a Heodo
2020-02-05INVOICE-13_38834926.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05INVOICE-EVP21_426674533.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05INVOICE-CK6_905590.docdoc 0eec086429d01d234eaf0e7acd8311e45b743cf859e043f9216ee77bfdff6400Virustotal results 26.67% Heodo