URLhaus Database

You are currently viewing the URLhaus database entry for http://closhlab.com/default/En/FILE/Account-55676 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:34338
URL:http://closhlab.com/default/En/FILE/Account-55676
URL Status:Offline
Host:closhlab.com
Date added:2018-07-19 09:30:43 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@ps66uk
Abuse complaint sent (?): Yes (2018-07-19 09:38:40 UTC to ip-admin{at}coloquest[dot]com)
Tags:doc emotet heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-07-21EEO52986810_2018_07_21.docdoc9eb5ebf4950818df9294072543535ab5bf97a9af906b2c14909a7c79445250cfVirustotal results 20 / 59 (33.90)Heodo
2018-07-20VW597971394_2018_07_20.docdoc3d731fc6870598f445c4431a3baeaf310205946928cebafb61b453f1f7f2ecb9n/aHeodo
2018-07-20XW69117_2018_07_20.docdoc78b28c11eff63b22c58f5fede556b626ad6124bf1d6f26e7e0c8ef8920a62cacn/aHeodo
2018-07-20BAJ80322_2018_07_20.docdoc180fd095fac220876a81b870f81af36d1a4b15b7cee4327354e4a06301032f1en/aHeodo
2018-07-20DD680116709_2018_07_20.docdocf2fcda5fae0579434edabdf820a8b4cfd20cb42bd5ed85eed93aaf40b1779e1bVirustotal results 15 / 60 (25.00)Heodo
2018-07-20WH19189949062_2018_07_20.docdoc08485465abe8f1fc59c14275b5a3161846601c24d5caae8a6a7d57de0c7e5a75n/aHeodo
2018-07-20ZQX3804643023_2018_07_20.docdoc8a4427a82bdc283f334eb5e0039882fd5070b88720be3e4e7be6fa768bbb2910n/aHeodo
2018-07-20GY0770509_2018_07_20.docdoc7902c588c5076b8944740c0073521bd90919355554118a582cd86ae3ed366333Virustotal results 14 / 59 (23.73)Heodo
2018-07-19WFG3997593_2018_07_20.docdocc587c71a62ab98e1c84e21be59a10e6d85b789a1794cef3528e591754eb48bf3n/aHeodo
2018-07-19MV846348071_2018_07_20.docdoce588d60741370662d5dc50eccb9272f18ae2b92260d23f87f2d5fdc2ff30d0e0Virustotal results 13 / 60 (21.67)Heodo
2018-07-19PS482037023_2018_07_20.docdoc94c9b705893c975d491fc64bf43ee8ea7b112ca9c8d850ccd7e7166fb8de3d12n/aHeodo
2018-07-19NL420878192_2018_07_19.docdoc77dc8c508bf833bf773043c989f4d80d40b5eed587a3da4a82d275d9d185592dVirustotal results 12 / 59 (20.34)Heodo
2018-07-19MPU437476352_2018_07_19.docdoc7d73990b5232be916500aa33b6d04b337f1f28a3fb145e0ec3739a48d159e13eVirustotal results 14 / 60 (23.33)Heodo
2018-07-19CH57307103553_2018_07_19.docdoc9b8661d44be560decad9d1aa0ef432bc399a90f2321a45c134204a0faa013b19Virustotal results 18 / 60 (30.00)Heodo
2018-07-19FIP017184_2018_07_19.docdoc8ee99cebbc5ff65a3506a855cb7620f3412965416853832fbec27207f1ed3397Virustotal results 18 / 60 (30.00)Heodo
2018-07-19LMA822450422_2018_07_19.docdoc5dcb15c147742a5321da1d0fbfa30d0d037ec424a6fdf5661ab94e54fda59acbVirustotal results 16 / 58 (27.59)Heodo
2018-07-19QJU92602856_2018_07_19.docdoc7b5ab9ca862b54725d802b562949b1e714585d494adb551d4391cc5c2c764031Virustotal results 15 / 59 (25.42)Heodo
2018-07-19VV0542535_2018_07_19.docdoc67d850f7e1f04113ed3210dc98ba706783e78e91fd891a7982368ad24fb621e4Virustotal results 16 / 60 (26.67)Heodo
2018-07-19MMJ445597952_2018_07_19.docdoc01b5aa2c79968d4889d5c1b9873b7b09ed7ebe482a6e8048682aeac92004814dn/aHeodo
2018-07-19XJT48048340_2018_07_19.docdoc4ce8645f7b108c81e137e971aa4b4ebb951dea8bece41e8f34593b1d20aebffcVirustotal results 16 / 60 (26.67)Heodo
2018-07-19LEQ4085567293_2018_07_19.docdoca628a0e93c89b5cc60147d49575e62517e834f8c0df33e10b147fccda7d865a9Virustotal results 16 / 59 (27.12)Heodo
2018-07-19UE53767340_2018_07_19.docdoc372b41d276a0b59449b340c13c88a8f8a9c5e40ba28835e4de50f1a46ec6a882Virustotal results 14 / 59 (23.73)Heodo
2018-07-19MW806645522_2018_07_19.docdoc67c3349e447b70faa4dd6ab7b42f5733197dc6c97172d5552e6d75f6667afd35Virustotal results 14 / 60 (23.33)Heodo