URLhaus Database

You are currently viewing the URLhaus database entry for http://baatzconsulting.com/doc/EN_en/STATUS/Services-07-19-18-New-Customer-SK which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:34313
URL: http://baatzconsulting.com/doc/EN_en/STATUS/Services-07-19-18-New-Customer-SK
URL Status:Offline
Host: baatzconsulting.com
Date added:2018-07-19 07:10:28 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-07-19 07:20:10 UTC to jeff{at}sudjam[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-19VR12127_2018_07_19.docdoc ffbc71083ac2f2e794fe9483b65264544a0a8d237aa0a2a85c98299eebc1f76fVirustotal results 23.33% Heodo
2018-07-19OP65909535_2018_07_19.docdoc d486c842b7bc3178a4ef69eb778084d523036f7e48b6aa1f24efe10ed02e5ec9Virustotal results 28.33% Heodo
2018-07-19VP710025847_2018_07_19.docdoc 2794c82c13c4abeda5fb66104c8fa4c3d6a2593e168514446e46a0afe7b58144Virustotal results 31.03% Heodo
2018-07-19FM63182319938_2018_07_19.docdoc 5dcb15c147742a5321da1d0fbfa30d0d037ec424a6fdf5661ab94e54fda59acbVirustotal results 27.59% Heodo
2018-07-19CMA95522019081_2018_07_19.docdoc 7b5ab9ca862b54725d802b562949b1e714585d494adb551d4391cc5c2c764031Virustotal results 25.42% Heodo
2018-07-19XT94668630501_2018_07_19.docdoc 67d850f7e1f04113ed3210dc98ba706783e78e91fd891a7982368ad24fb621e4Virustotal results 26.67% Heodo
2018-07-19TZ822967930691_2018_07_19.docdoc 01b5aa2c79968d4889d5c1b9873b7b09ed7ebe482a6e8048682aeac92004814dn/a Heodo
2018-07-19KE76548_2018_07_19.docdoc dde1e4beb358bf4ab02fdad1e477b603c116bfa2c39d9c4c42740738304d4ed7Virustotal results 27.12% Heodo
2018-07-19WV92118733_2018_07_19.docdoc 4ce8645f7b108c81e137e971aa4b4ebb951dea8bece41e8f34593b1d20aebffcVirustotal results 26.67% Heodo
2018-07-19VX7765869_2018_07_19.docdoc 372b41d276a0b59449b340c13c88a8f8a9c5e40ba28835e4de50f1a46ec6a882Virustotal results 23.73% Heodo
2018-07-19KKP6395767550_2018_07_19.docdoc 13be5f270fae725e5dee5a1d996d306ad0b8876c11ccdc47883dff94093d3c6dVirustotal results 23.73% Heodo
2018-07-19XK3208518769_2018_07_19.docdoc 3891e36e9ca0d00daf7d94ecd4088e787123b275340d6bba1caef560f5dc2b31Virustotal results 25.00% Heodo
2018-07-19JI19586_2018_07_19.docdoc d0c62251872aa490426febca07c9bb79fc5ee686d6278953d1a40e36ae6e73b0n/a Heodo