URLhaus Database

You are currently viewing the URLhaus database entry for http://healthandsafetyevolution.com.au/2vqjz/attachments/b083p507483844725c9mgx4jd8ejmjp3uslo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415317
URL: http://healthandsafetyevolution.com.au/2vqjz/attachments/b083p507483844725c9mgx4jd8ejmjp3uslo/
URL Status:Offline
Host: healthandsafetyevolution.com.au
Date added:2020-07-20 15:57:35 UTC
Last online:2020-07-21 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 15:58:02 UTC to abuse{at}microsoft[dot]com)
Takedown time:1 day, 5 hours, 38 minutes Poor (down since 2020-07-21 21:36:19 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21SBB_PO_07222020EX.docdoc 7e19bd9fb89d319412d1ebf8ea34ac130a54b3b07921976713b1585dd2d25071Virustotal results 25.81% Heodo
2020-07-21DOC_XLK209LIU.docdoc 98838ac3371620d27bb1934833850cb50098197f8f45a137d1ba94ebb92104afVirustotal results 26.23% 
2020-07-21HDUI2JECBFN14G.docdoc dbda4797cc002eeb66a87ca2dc004b353d72aff451eb3ba1010bd900cac133ddVirustotal results 33.90% 
2020-07-21BAL_PO_07212020EX.docdoc 25d8674a9a9f8dc39e05c8625561abfa731d499fa4fcf8ef72bb9dadb1d4c156Virustotal results 32.79% Heodo
2020-07-21OH_EF8893964276QU.docdoc adc75d7a700b766503c50f538a24148656ae2c500683944ad15c8a2c8e42b567Virustotal results 32.26% Heodo
2020-07-21HMD_1VT76JXFY.docdoc 1eb40695aac83a3f528f16af863be6327354d555eadf1695c53904c523ac9a86Virustotal results 31.15% Heodo
2020-07-21REP_9717824583360791255094242.docdoc 4b9e26f2c63d249bd9be365f44513691d3aa8461f77b10638c5f27fcd5144568Virustotal results 31.67% Heodo
2020-07-217V1OIGM1R8PXID.docdoc a79260a2130cd207d41c21e4675a28c84d838212eb973d2434c642819a2e30bfVirustotal results 30.65% Heodo
2020-07-21KCUJ_30492576.docdoc ffc575665829ae7905ee6e5f2194883080c4ec8d2fa69ac1770319767a1b5456Virustotal results 31.67% 
2020-07-21NK7946722490TN.docdoc c3db961b04941123b6924d69f2c5b149df9b54835cffe9dc0f693fd0dfca31bcVirustotal results 31.67% 
2020-07-2162392486.docdoc 74db9fac3d9a684b81ce1975d06d184a85bc67d24466aed35ff6ee475e21d16dVirustotal results 31.67% Heodo
2020-07-21BAL_35786286243727290975.docdoc a543b622ebcc58314854fa85473ce89753b8c30877e2562d607aa9483023d16fVirustotal results 31.67% Heodo
2020-07-21A_8150167791881327934224437.docdoc 5d776bf9cafd76e79aaab31bfc6c44f43e4dafea532c69aff3875e0f8d253baeVirustotal results 31.67% Heodo
2020-07-21REP_K3FJC8A.docdoc 75ef42ac18f4e0b5e1ae3476f03a760b2efa15e2a578c7cf8898bdfebabcf07bVirustotal results 28.81% 
2020-07-21L_GU5405016038VR.docdoc 26d6a947ace5dc20b8511699014a7230d627b181f37246807ea85cdeadea61feVirustotal results 27.87% Heodo
2020-07-21NH6910635973SG.docdoc e59ab4e1a047866cf6ad7eea19330ef2c3ace4086662158f0e46d07333ea11ebVirustotal results 29.51% Heodo
2020-07-21LP1297440638AF.docdoc eea895f78d31fab11d485cdedb1938309a53c01bcbad7657c9695879ab1f0979Virustotal results 30.51% 
2020-07-21ZXM_070120_THH_072120.docdoc e8eff9852fefe1a01b140600735f3b9abecfd2f1bb93929c8955778bb11d0681n/a 
2020-07-21K_51606901.docdoc 1dad4de7cb45876fd076def8d214824ef1d8fe10d8b202ee220930ba6ed989b8Virustotal results 27.42% 
2020-07-21INV_HSW_070120_MYT_072120.docdoc 8d53a88575b2b26b3fe78df74205c739baf12ccbe1d51e27853d2ec4ed6aea5bVirustotal results 27.87% 
2020-07-21ZZRS_63811275.docdoc ced32d6bf400cc3bb59aa1929efa4c17228064153ca0615288fc1fefde35f11bVirustotal results 27.87% 
2020-07-21BAL_BW8374494889WZ.docdoc 6aae57a7a60c8c2529948a9290becdc90f10be950ad2133ef7cbb1c366693f4en/a 
2020-07-21Q_NHK_070120_WHE_072120.docdoc 5f79033b6a54db8f8075b5fa3c0629142bb73e654e4aabb10f5e905942a4871dVirustotal results 24.59% Heodo
2020-07-21T_31536573.docdoc b4f865e3011a63a5b8a0da14876282d97d5144e153f8316025555d276602d335n/a Heodo
2020-07-21DJVHYVKXCDY.docdoc 8f5c9735c5189f1b809aba58ae06fa7432eaff2ca15ec97d918d82dc6082a69bVirustotal results 24.59% Heodo
2020-07-21ZQYK_12676984.docdoc fe7bb6362bb3a11a4579b9c0c36fb7d1df5b57d43ff14b8b4ada2254224180e2Virustotal results 25.00% 
2020-07-21INV_382743936748773442935.docdoc a77f0d09a07d8f85b737d25216501b343e22c4e04a6f88b16dc1ab9ea1b2a222Virustotal results 25.00% 
2020-07-21DOC_NL1035718618WN.docdoc b1a935c9a64f8a2191e613e696c6df7a5892c608ec14c6f72c3459c4a62f2865Virustotal results 25.42% Heodo
2020-07-21DOC_0329471731805831.docdoc 3f65143957146edc136d123a62507f50497de812d31cf82785b88dc67c7f4792Virustotal results 22.95% Heodo
2020-07-21DOC_62035645.docdoc af5e7fb37b6e00d487dfe968b928d24db3a786c75b530be1f46c3b228fa940ebVirustotal results 22.95% Heodo
2020-07-21E_OV1T52GLI6.docdoc 8969bcaa62533ea3d1c200c02009112d2d21e5b51ec3500698935d4689d46265Virustotal results 22.58% 
2020-07-21DOC_23KU8YWBCQS.docdoc 76135328ce70dd5755fa54408d962b10954d6bb5c47f883a7c2bdd1defbebb9cVirustotal results 22.95% Heodo
2020-07-21REP_29698409935242729666.docdoc 9560e6e3b0d652ebeb93460213b2441adeda06783b641d59101d2cfe2c227307Virustotal results 22.95% Heodo
2020-07-21E_PO_07212020EX.docdoc f2e0593ca696ec36f6b813e857b8fe6741252d7b65df42e5e16bb3c80bc7a90dn/a Heodo
2020-07-21BAL_PO_07212020EX.docdoc 49e7f3d18db1b3402794fa15a11d36c41d2857d4a668834b6178d0c739e2f821Virustotal results 22.58% 
2020-07-21FILE_341324030833906602237.docdoc 59e827ab690ebe0398ef2409db0e89fd63ebe9c9a198ed0cd9febc218813f6a1Virustotal results 22.95% Heodo
2020-07-21HLN_UZR3BZM0RJIBR.docdoc b946948073ee057b1f1cdf3b7c54098e9eb35bb8736104d13e2f3febb038f2b3n/a 
2020-07-21BAL_TNP5D9D9EU.docdoc 8b448dc2b315f49801c7b4d4b20a2d3163f9c9376a3c36dc4dc7a52513a101f0Virustotal results 22.95% 
2020-07-2179139678.docdoc 660ff4d3124a99db58894556a3461eda17393ca94c27e075185e72536eb6735en/a Heodo
2020-07-216174266881.docdoc fc2bb7719f33ff249113e3c05c4b2b6fdbc99190e250b3073295e271c553f0d0Virustotal results 32.26%Heodo
2020-07-21DOC_14573711.docdoc d604f20c04d25e448176ddfdf3e01865091590cdf5f2cd2c42eb9af7cf41c718Virustotal results 33.90% Heodo
2020-07-21FILE_JB8295538588VU.docdoc 53b9a409018adc25ac26a608d9fae417659211d8754dbf7f07c3e4710a026774Virustotal results 32.79% 
2020-07-21KGS_070120_EXI_072120.docdoc f23c88283a5b29e45eb6658afb904be03923f73895e4f6b232f3e04e288bb715n/a 
2020-07-21Y_SO4794692384RB.docdoc 41239e9448583b6a09ec8574d34295b254dec60348e219d0a1355467c3ab37a4n/a Heodo
2020-07-21FILE_ADQ_070120_FZS_072120.docdoc 9e8362c34f689302d747bee833e604d4d7e10c7d519b401e9c9fe257bc241197Virustotal results 32.20% Heodo
2020-07-21BAL_03967506.docdoc c9d9cfb4d6f95d66b6480f5dfb60edf7b0c4581895b68dbf25a830f9006b2d3bVirustotal results 31.67% 
2020-07-21FILE_VK8425697485UO.docdoc 798bef025be5953e7e96ca59398667ca056420d1bed67221390de9d122f40165Virustotal results 31.15% Heodo
2020-07-21QBR3BZYOYB.docdoc d6c5ff0dea2cbabf074ec5c1f7ca759925d9f469a37d4265919edf2414c60d5bn/a 
2020-07-21KXHK_WAMM0SOQA15361T.docdoc 6d7c0327ef758d90e34d8e64f95ea11431fc630f904b95f33141ced30a743dc1Virustotal results 31.15% 
2020-07-21PO_07212020EX.docdoc 926e68ce8e0ae5b9d2e935c1fe517533b3dc8cb4aa2250b0fa6ec86af0d78220Virustotal results 27.42% 
2020-07-21REP_T50K6632NC.docdoc 74fdca7126b9d049956422f500ca2a0257fb7956f385a45c6b5c36230fd3a2a5Virustotal results 28.33% 
2020-07-21INV_37121648.docdoc 0d1316502220cb6dd888dfe5bf248b70b28dc8eb3518f1cf98737edd5b62aa74Virustotal results 28.33% Heodo
2020-07-21W_BL6883390277ME.docdoc a7f4f8b9dddb70414bfdbbffd5c446c88b517c104a441be19151c8a711133686Virustotal results 27.42% 
2020-07-21FILE_IBL_070120_PQY_072120.docdoc 9f082f2eeb02660ab639991cade576f8a7f72990579ddb87315b51374e11fc18Virustotal results 27.87% Heodo
2020-07-21IVS_070120_GJB_072120.docdoc cff09d732ea9fe1f128dc29bff9f5d5d8ff78ea22eadb52fa4b5b8d7c056928bVirustotal results 27.42% 
2020-07-20RI_PO_07212020EX.docdoc 1d9333d44f7442890d84cbc3972b9d00c93bf1556042f7b58c1386365eae3c76n/a 
2020-07-20JNXP_PO_07212020EX.docdoc 49f90436f418a86b0f4e55e14bcf74793954cc90596ad08dfb6355a1e50a8f27Virustotal results 27.42% Heodo
2020-07-20REP_PSBMK9XHYMWI.docdoc 2a7edcd4009ca88459bd2ec64af866f700abb7acb68cc5b13a40315c51976df7Virustotal results 28.33% 
2020-07-20S_VD3272161288CA.docdoc 80b27b3a7242ea8cdfbcc0d266c4fe489cc0b035fb614b755e2546c80cdfbed5n/a Heodo
2020-07-20BAL_52094359.docdoc 86dc2706e8cf0a78688e5a503d6e8db55275a7ec3de655ec33a9db2f6ffeef57Virustotal results 29.51% Heodo
2020-07-20T_PO_07212020EX.docdoc f073a991092d0dc2ca2d7308e64b58992ce0cb00fe5da928b65b58530c10e7a9n/a Heodo
2020-07-20INV_88761114319395812903783.docdoc 4ec7f2a0359b740dbbc849705f2856818bccc8fafa5a2237fd79640e61423255Virustotal results 27.42% 
2020-07-20NXGH_74192217.docdoc 53dfc48b5b049b05895bc4e2e5fca037946e69d083cdac2e6c222b76c86f4763Virustotal results 29.51%Heodo
2020-07-20INV_KL6928409715TP.docdoc 148aa06dceabdc99c7588bd48277867f3d0528fcf04463562707fd66f953045dn/a ZLoader
2020-07-20REP_M86JEM96.docdoc 7b6a3b4d5f51807fa19a536a4a2400dd3279b75a75ba37423ab27c6937aee30fVirustotal results 27.87% Heodo
2020-07-20GXC5V2EXWOBHRQX2.docdoc cfb6588d9181a97aa1f93b2b9f8af82134836e916938a80a217cd03fe4294811n/a Heodo
2020-07-20PO_07212020EX.docdoc 401dadd7c1211dae181b8767949d274790aa4fb72e78a3d57ae92ac2cf925da8Virustotal results 27.87% 
2020-07-20UGS_070120_HCG_072120.docdoc 33c897cc3c1d11687231644af13032e24358c594f4b484a7040a3eeecfae7145Virustotal results 27.87% 
2020-07-20INV_ERI2WK5.docdoc 4fdba539896383e37ec2383fb569df4f17395dd40115ba8caba62127b7ebe949Virustotal results 28.33% Heodo
2020-07-20DOC_XQV_070120_DFN_072020.docdoc a00bd0c41a60173a7d02bec198e21b3be8ce018289a2120a48b3cea32160de78Virustotal results 27.42% Heodo
2020-07-20OWG_HO0475046683HI.docdoc 6f07729a0d38233363651ce3760f506ded756ffb5010218df70d03bba767e7d5Virustotal results 27.87%Heodo
2020-07-20B_NTQ_070120_JTZ_072020.docdoc 8811f4498f1b1d8729556a61a5683ce20c4270a64ee5ad0223185110adac5f2cn/a Heodo
2020-07-20P_96569420.docdoc f479686dfc59c7e2cf8607ef958b067288d47d2de6a92db1b0c1268b9862f42bVirustotal results 27.42% 
2020-07-20TC2678693409EZ.docdoc 69167697c3c077b3ca6449ae55750d1712c20bc33196537fdbbe05e463aab195Virustotal results 27.42% 
2020-07-207097736923058494403.docdoc 1e146c18d65265b27e23f9ee84a8f1d20c046aa76c30ed386710a10cb0da2960Virustotal results 27.87% 
2020-07-20REP_58208252.docdoc 9ea223e9251e17c155c00e320f9f1008c6872573da7a16d524213225ebec9addVirustotal results 25.81% Heodo
2020-07-20DOC_9668617137.docdoc 4a12475b07d363c78dedd7070df1730851f1871bd0951f703375692801ad2f97n/a 
2020-07-20OFA_070120_JYD_072020.docdoc d2357823bd33f106343cf781864392d133112d09386148aeec801d016dde2d47n/a 
2020-07-20PW7MKNMGQT8.docdoc 1a328aa48b0ba77e6965043cc7dc2d97edd5ac325b193b1f102a50a492444948Virustotal results 26.23% 
2020-07-20REP_ILT_070120_CIC_072020.docdoc de77fe86034d9281adb201f8d4d906343d622467a133d5ef3d0e8cfe50dd4061Virustotal results 25.81% Heodo
2020-07-20M_PO_07202020EX.docdoc 73ec1e7316f940c2f81b1372760692b29c86b72855aa04b2e9e27cce2c9e316dVirustotal results 25.81% Heodo
2020-07-20REP_HH1328562249MO.docdoc 49a503bf7c2281565500c611ddcd637063436524390805e4a871560ba792e1ebVirustotal results 25.81% Heodo
2020-07-20INV_PO_07202020EX.docdoc 339483bcbbf9f51611d79358797318f66d88eeb7a561eb5ee3dd5fbaacc31531n/a Heodo
2020-07-20Z_26864919667.docdoc 932c549927ea5c0ce827253fcb26978c1361cfbee3495d9dde5130ba190dd3b5Virustotal results 24.19% 
2020-07-20INV_58072671.docdoc 1e7876167b890b5fef7dd8cb965be95ef2adaab8a7c06bdb8b1fee0b34d90534n/a Heodo