URLhaus Database

You are currently viewing the URLhaus database entry for https://motavera.com/wp-admin/balance/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:414223
URL: https://motavera.com/wp-admin/balance/
URL Status:Offline
Host: motavera.com
Date added:2020-07-17 20:16:05 UTC
Last online:2020-07-17 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-17 20:18:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 5 minutes Good (down since 2020-07-17 23:23:05 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-17DOC_BT0L31F7IR2.docdoc 5f6d8525a28494c7eda3df2fbb04bcacc9ec20abd2884a8e690d91a2de033807Virustotal results 37.70%Heodo
2020-07-17ZSK_070120_YTQ_071820.docdoc 80fdf1be057aeeffabf88cc551c7c54430259f75b413391064642f8217eefa36n/a 
2020-07-17H_HTV_070120_ZLW_071820.docdoc 9733e04aff3f386bf6dddf3dd39186c03f4d4e5a842b85898877bc75202125e3Virustotal results 30.65% Heodo
2020-07-17EUHX_UF9064477223IG.docdoc 93a32c3e66cbc2cf825f94cbc698cf9f2bde89f46cbfdae33a83f009b6eb6cf3Virustotal results 28.33% Heodo
2020-07-17FILE_MOXAK62FWR.docdoc 841439a2ad14784959d57c8b1ad8fb09014fbb03b41aedee51947e8f31e5c4a4Virustotal results 27.42% 
2020-07-17FILE_CO8K101J58W.docdoc 973b004896e71141aa2b073101a02712ba7cf9d9c15ed7371a338d05ec725106Virustotal results 27.42% 
2020-07-17BAL_BDC_070120_VCZ_071820.docdoc dfde8cd4643dbcfd7b4325886992e40da9c2877b7678735ae8262353a602518cVirustotal results 27.42% 
2020-07-17ZIC_SP1215050968WP.docdoc 6e6bf8344fb9473bb6804815ea6162440c958a04e41ce815f048034b6f4d4f3eVirustotal results 27.87% Heodo
2020-07-17PO_07182020EX.docdoc 6aca150abeab5401a28dcbc61bc52bc8deb268e7c9df9698ae957fecea368d50Virustotal results 27.42%Heodo
2020-07-17BAL_500945325193362.docdoc 53aac2de99cd3a61b9452daf5c4bdcf6ef979f98155d9cb773055bca5033be46Virustotal results 27.42% Heodo
2020-07-17BAL_7R6BLAQ4RV.docdoc 2107707a5f10d329d96ef8aff1dc26362634aea94d5e0e5a9e9f5cefcaa0bcdbVirustotal results 26.67% Heodo
2020-07-17INV_MV7Z6UDY3WOX53W2.docdoc f909c6fc593985a3df36c86b32588edbbf3e2c43a7020a8a32b081ec3153139dn/a 
2020-07-17FILE_02477419.docdoc 0df5c512f9cae0cc043d8f969a770b3083214c46d9a51a71a9c36b128d69eb89Virustotal results 27.42% Heodo