URLhaus Database

You are currently viewing the URLhaus database entry for http://montegrappa.com.pa/DHL-Express/En_us/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:36237
URL: http://montegrappa.com.pa/DHL-Express/En_us/
URL Status:Offline
Host: montegrappa.com.pa
Date added:2018-07-26 13:07:26 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: ps66uk
Abuse complaint sent (?): Yes (2018-07-26 13:15:08 UTC to abuse{at}godaddy[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-27DHL_number_4112008876072.docdoc b02053680a5f0426e11bb4fb679d5d598aebd0427307a48575779329f20d593cn/a Heodo
2018-07-27DHL_Tracking_11334423.docdoc c5e72c01e9af1c8bdc1ac8196fd9d7264c3412d457ed5a3a940b19f031e50893n/a Heodo
2018-07-27DHL_Tracking_2050830227.docdoc 1b5c17ff7144d80dab8c48ebd0900138acfd4d5c7131f3d687a9b804caf62024Virustotal results 30.00% Heodo
2018-07-27Tracking_277328465158326.docdoc f6f57dfd2a6ff59a9f8f34c8bcc6058ee58ff13bfdfa0152a91fc31b05cff68dVirustotal results 29.31% Heodo
2018-07-27Tracking_733579714790.docdoc ec38d89afa887d9880e7097a5c73479df06dd06402e6fbb17d637c9e94349f1bVirustotal results 27.12% Heodo
2018-07-27DHL_Express_47226053889942.docdoc 5b82e7f9aa125894bad57e35170732a41f6823f507f3c1a63a0adb1c0da2d6c2n/a Heodo
2018-07-27Tracking_00698508160501.docdoc bc809606a312c3d97fd69772b07f91f18accc212954cdd5d35d0192dc44ac7c1Virustotal results 31.03% Heodo
2018-07-27DHL_Express_9410242.docdoc c48bad5ccee9eca0d86313fb25c39913d55d6ec1000d66b98758365a999778ebVirustotal results 27.12% Heodo
2018-07-27DHL_number_185984484.docdoc 11e0b81e04e28b9749a6a8d0df35e4d5fc11528be5a54802958b1e3d8e954ab6Virustotal results 29.82% Heodo
2018-07-27DHL_242776971626.docdoc 351df39fa91ac1b92688ed7c52efce7541ec78cd5f070545d170927b6bee51a1Virustotal results 28.33% Heodo
2018-07-27DHL_number_06837147240875.docdoc 191c5092b8b1e37ad1d6a6394d2b9aa04dd12a29a888ac1210ded7f93ac2cacbn/a Heodo
2018-07-27DHL_number_5625723187.docdoc 06f3528100cd5d4ddc7f06d35d26918e30f723755e342f583d8bf5f791e8a21en/a Heodo
2018-07-27DHL_Tracking_169893844.docdoc bbd808b9ae468f0fd7611ed28d9c32ff61116a64095ab2da02877b44b59966e3n/a Heodo
2018-07-27DHL_Express_179303201822427.docdoc 6e99fd801a91014662c3606af72e677b21ef291a487861c576c1d19955699da7n/a Heodo
2018-07-27DHL_Express_234949448399575.docdoc 91ec3d555e8cd980bbc636147b9bacf94ce6e2ed736cf879e2d7d30693f182can/a Heodo
2018-07-27DHL_464393368346642.docdoc 183bcaf3b2bff3b5b01952769ff713036ba5ecdb34f579c7c8bcadb3ec4673d0Virustotal results 36.67% Heodo
2018-07-27DHL_Express_684410422109.docdoc a04e6195e8b52db47e7e88401a4daa431ccdb00c959c3ecc2b26743ba47e97c6Virustotal results 38.60% Heodo
2018-07-26DHL_number_439077078981306.docdoc da949e88f8e20caff806d1c8201777571991a2701bdc2f3e44815d0e18ab948cVirustotal results 36.67% Heodo
2018-07-26DHL_Express_125804866061.docdoc a8e856a69c9eb0074a418c67d575b91b49caea488574529a40e3b129cefde689Virustotal results 40.00% Heodo
2018-07-26Tracking_831759305.docdoc 8f0dae9f191c55289ab80783e68c0e03e97f391cd86ae283304555f20d8f2d31n/a Heodo
2018-07-26DHL_Tracking_4296836285988.docdoc 11f7710f8cabe988168078cd6ba83c2544d1d06c9a8a3583fabe164e87f7048bVirustotal results 39.66% Heodo
2018-07-26DHL_Tracking_3650806.docdoc 73d4c1dafc168a36218d215548bdcc87b0ecb667acaf685b044b680f4f678dcaVirustotal results 35.59% Heodo
2018-07-26Tracking_580821625931.docdoc c77196231630b535ef5f0d46f78b7be22a27954daf395065b8f448829bcbbdffVirustotal results 35.59% Heodo
2018-07-26DHL_number_027645413306.docdoc 2fca591f3a53ae78f6205f0fdbc3ac7b76cc36c9cd614d74bd62ff278d59eb54n/a Heodo
2018-07-26DHL_number_296774336.docdoc ae9906780f635486c8ad44c8e72767bcd2bbd5b5dc8c4ae021239584e9c4ffa5n/a Heodo
2018-07-26DHL_Express_3664461267610.docdoc f31b10a0262b339800fe10d224f275639679abd58a0114c643fef822c60a14ecVirustotal results 28.33% Heodo
2018-07-26DHL_number_2109252.docdoc cae201c0186ce7a7772512776f9cc768861fd18c7ac96d1c65cbe72304e86b57Virustotal results 30.51% Heodo