URLhaus Database

You are currently viewing the URLhaus database entry for http://3.6.234.92/ddk/private-zone/additional-cloud/21869143416746-rmYC2YE8J/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417176
URL: http://3.6.234.92/ddk/private-zone/additional-cloud/21869143416746-rmYC2YE8J/
URL Status:Offline
Host: 3.6.234.92
Date added:2020-07-21 22:37:11 UTC
Last online:2020-07-27 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-21 22:38:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:5 days, 13 hours, 26 minutes Bad (down since 2020-07-27 12:04:43 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23Inf_JU865972.rtfdoc aec05999d3751d7cfd9ade2316388ee6da303748401fb7eada3edaf2b37a18a3Virustotal results 43.33%Heodo
2020-07-23LIST_20200723_WAT564766.docdoc b60064c8db21645429edab0b94dcb5dc93c7325774e13b65c0bd79497eef8296Virustotal results 44.26% Heodo
2020-07-23DAT_UD183.docdoc b27dff26a97f18384d8db6b7e5a3c5006d66ed61bba5313f802ebf96543c1c5eVirustotal results 44.26% Heodo
2020-07-23Rep_20200723_A874232.docdoc 5a2ebbb1273d774d883ccc80441f1c0a31352cca7114330d6272919625c803efVirustotal results 44.26% Heodo
2020-07-23dat-2020_07_23-X316.docdoc 1a49241764ba049de98c9d050dd57d0c9089402768b9a1206e09dedde0282d0bn/a Heodo
2020-07-23doc_CV460.rtfdoc c685dc92b2f626e331f4d31a5db4b218823c143b7c5338fe29b8518455179cfan/a Heodo
2020-07-23LIST 2020_07_23 46871.docmdoc 0f79dd6c7bd7490955e93399a3e660272c22f6f7f5e97a24ff33d1d1af714941Virustotal results 45.00% Heodo
2020-07-23ARC_LW817995.docmdoc 38605c5d0d30db916a981219d70903a6f64df4d78ee59580a295104d700d6b88Virustotal results 44.26% Heodo
2020-07-23dat-20200723.docdoc 654e6bd6920ccd6177242d7e58e504e354a9e5fc0be08816ce3afaa64b0dee93Virustotal results 44.26% Heodo
2020-07-23mes-2020_07_23-JPA724216.rtfdoc c16f62ec18e9ca91236dfbab6da3e98fc15a8574e3c66dcb4c652ba820bac07fVirustotal results 45.00% Heodo
2020-07-23dat-20200723-7882.rtfdoc ac7930487897476241e49fbc630ae0da49daa5efde7a3b8f017ec4e1a6d97133Virustotal results 45.00% Heodo
2020-07-23Doc 2020_07_23 MV89936.docmdoc 907cdbd0036f8c72ef0830f26aee15b16f5498fe3fb88c9ac852fecebcfd2771Virustotal results 44.26% Heodo
2020-07-23File.rtfdoc 1b96d3881a05f141dca8c4cc847ff24cf5e03d3e37e67333351cf7cf4bb9e32aVirustotal results 44.26% Heodo
2020-07-23mes.docmdoc c4ddc964c0d911deab5fe24136c588c63d4fe247aeedd42d0ea37491e44af3e5Virustotal results 44.26% Heodo
2020-07-23ARC 292.docdoc cec6250fbf5fb227dd2bdf92b7031f41fa3d65fe1f1d5a441229c14913884ea0Virustotal results 43.33%Heodo
2020-07-23Doc-20200723.docmdoc be54ea255823d2c2fe8c22dafdb74a751989764842566d88b189138351d1adc4Virustotal results 42.62% 
2020-07-23file-20200723-533.rtfdoc 3871eed6206b0a99254d0c9687c02a628857c89231e009285a476dacff80d98dVirustotal results 43.33% 
2020-07-23list-20200723-380.rtfdoc 769b01f8c9dd10732e0a5d287a38b2946260496bcb17be7319e7070e4f3a62b0n/aHeodo
2020-07-23List-20200723.rtfdoc 9a3ea141f8d72bc76545f030fe43d91476ce753bd525ed872269184599692c81Virustotal results 42.62%Heodo
2020-07-23File_2069791.rtfdoc 49700dd4aae08be36bff9524c53990a3f170568a9e5e56b7148ef982d9f3bcb2Virustotal results 42.62% 
2020-07-23List_Y5407.docdoc 1b9e74162d42d570c37b7fb5cae6e43929257833fbbfd3fbc9d26579650840ddVirustotal results 44.07% 
2020-07-23INF_0669.rtfdoc 9a85400cf019aec876aa8f402aa493488a4baabd22e521a73a69397b09854156Virustotal results 42.62% 
2020-07-23Inf MON8625.docmdoc afaba3e7c44f16cafd700c3cf2bb48367f1319234da31884c14d364c90c15700Virustotal results 42.37% 
2020-07-23MES-20200723-W3683.rtfdoc 275106731a63f606b2872a59c94e63ab81c43795ae62521e8c3083d113060c01Virustotal results 43.33% 
2020-07-23Rep-2617.rtfdoc e50229adad96d87fc334ebdc7b337d1d90eb8fbcac675be16f14bd72254aa0e3Virustotal results 43.33% 
2020-07-23Rep.docmdoc f90d92c5c4d8e67b7332df917d99caa81a46a3fde2e3686f43af146265bdd6b2Virustotal results 43.33% 
2020-07-23DAT 2020_07_23 XH853839.rtfdoc 3479ceef59526d78569e37da10322c1230cbd27228b79fc3d57bcac836896f94Virustotal results 43.40% 
2020-07-23File_2020_07_23.docmdoc 1a2486d1109323b6b9e00bcfb625af22c1bd1c3538a97870d4e96b9a95648a0eVirustotal results 43.33% 
2020-07-23File_20200723_DA6385.rtfdoc 8d52990eb4b83e90b44ee30643fd95f19f9388ee75c00be6df5599390ad4e60cVirustotal results 43.33% 
2020-07-23File 2020_07_23 5172.docmdoc d112ebefe37af03ea837d3e0c1d8649cc81fd4340141163b072c8e1df2df3529Virustotal results 41.67% 
2020-07-23Doc-2020_07_23-IWN65555.docmdoc 9d0012fea01df26cfc4c35de504723054fe05b21727960ff8dfa77dcb27bdc3aVirustotal results 43.33% 
2020-07-23Dat-20200723-FU030.docdoc a33dd73bdb7ea44a14ba44f8f9316d8b4b9f36c62f7cb5aed940f70713955a1aVirustotal results 42.62% 
2020-07-23Mes.rtfdoc 1fd1cac3c782288baeb2c1b23dce8e5bbddd7d5b8ee10ee798017eddee05db3bVirustotal results 40.98% 
2020-07-23Doc 2020_07_23 TTD402395.docdoc 4ece67785ff57d602ca2e5c69538ef2b7118da45f20bad760bb950556ede54b6Virustotal results 40.98% 
2020-07-23mes 2020_07_23 BR580613.docmdoc 04f164be53df8877786862bdc212d2138e66e3d3eec4669585165b8957de5897Virustotal results 41.67% 
2020-07-23INF SQN73677.docmdoc db63760903d7321d485e5e4de4871219bcf280aa8d10a5b45adcba8968650ab0Virustotal results 40.98% 
2020-07-23Arc_20200723_353275.rtfdoc 2baeb9021538a6e46d0f337320965c7765bec4f69047f0cb249fff3c51972a81Virustotal results 41.67% 
2020-07-23FILE 2020_07_23 YHZ008385.rtfdoc 57dfd33d9f1ac2d1ac1e989fc1f64affb20aafc1530591370203e9bd13be3e82Virustotal results 40.32% 
2020-07-23inf-20200723-7937.docdoc 19fb3f434975d157f252494d3d919bdc412e6018df10f3b5b293f7bb65ae1d32Virustotal results 40.32% 
2020-07-23Rep 20200723 G26727.docmdoc 6042f1b7f7bc35380db47233f01f51564c5f1dd87e38e1c7f0af9605d557ccafn/a 
2020-07-23Arc_20200723.rtfdoc 33c154cefec10fc509dc5502bf3632658935229cf47994b249d2c528c0c5bbcan/a 
2020-07-23arc_2020_07_23_AKT318.rtfdoc 12c4f7a51f3a0e32a279891ac5335593fefca0f48434247ce0054a568d7afe7bVirustotal results 40.98% 
2020-07-23list-2020_07_23-D148901.docmdoc e4c0c53d2566fd3d639ce00a49816d813b56df5c37b964bbc9a551a411f8873cVirustotal results 40.98% 
2020-07-23DAT_20200723_75909.rtfdoc 74bd3d0b665c51b3517da40d77beefa5dbe6983292640c44650a350187dcfd9aVirustotal results 41.67% 
2020-07-23List_J14874.docdoc 57c701ff4952c9b4178af5689028a04b38a2db1ff57b28ad534d1b1d804ee028Virustotal results 40.00% 
2020-07-23Rep 20200723 KG3939.docmdoc 72d01c86f0d425a4f2bb8b4bf5e4321c7f49cc1283bcbc074d66c366f6ffa324Virustotal results 40.00% 
2020-07-23file-20200723-YUY183.docdoc 79b3b0ed83202e34b8f1e3030face4fc7df332281b16802674bc0cd0dd27bf5aVirustotal results 39.34% 
2020-07-22REP-20200723-ZP32728.docdoc b936ca1824141941696f21188294398f23a5bf8f6dc5211f7a89d68996eb1496Virustotal results 39.34% 
2020-07-22MES-JT77432.docdoc 85c9b8464b14bbfbc90c01fe540a9ba134191dd42668aebfb5c09e35b1887dc0Virustotal results 39.34% 
2020-07-22Doc-2020_07_23-AKU122.docdoc abecaece2a01d6e8d9a77368929fb4d818a0b836c5fd5b075a251b7833e72116Virustotal results 39.34% Heodo
2020-07-22REP_20200723.docmdoc 8fba8be080f896187be7d544013e3a3b8f26704a23d447ae88a76bbcc11c917bVirustotal results 37.70% 
2020-07-22rep 20200723.docmdoc be720b7a706eae0e4fb267e2ed1709351ae68658728bc8e55a774921eb79a81cVirustotal results 38.71% 
2020-07-22List-2020_07_23-5241.rtfdoc 06ea16c8f47256c5551752bd00c34d5cb30e9b5ea7daa3434e35ca178ca75c2bVirustotal results 37.70% 
2020-07-22list-2020_07_23-693811.rtfdoc 9ca7a8bb979b122572d3ac88c0a7098b351bdc0146d1a2d1e0b37bb133d9c427Virustotal results 36.07% 
2020-07-22file-20200723-410.docmdoc f0c435e77ffa71b2c40109d083b689c870f13ba21021562482e0c1bd6fd7df6eVirustotal results 37.70% 
2020-07-22MES_YJ893.rtfdoc 86ef20dcbdc30f082e16816d3281b197b1e34d03d05c1098a867b9d840802cabVirustotal results 35.48% Heodo
2020-07-22inf_20200723_857001.docmdoc 41386a0cbdfd22f4a7d46f44c00c2e393e548a2c722a7287046bd76f946c386eVirustotal results 35.48% 
2020-07-22list_2020_07_23_363025.docdoc b7443aa0dd6d738e32a1c4fcd5990b7ca23d2fa98f65c703514e3e82d72d7843Virustotal results 35.48% 
2020-07-22Rep.docdoc e5b1755803e1fd990e3747b22c5b2e5dd674c403a309b2931ca7b5ae74262d91Virustotal results 37.29% 
2020-07-22Mes 20200722 UWE0832.rtfdoc 61ac92f083c25879585954c7ade43b7b17fefbfadc38a09fa9793f769f33f9f4Virustotal results 36.07% Heodo
2020-07-22Inf 2020_07_22.rtfdoc 73d6cf5248a0604eba81bfe1a1f55473820a97df0c5746014dd47e3d10071cb2Virustotal results 35.00% 
2020-07-22list 20200722 069140.docdoc cf53854628d9e95bf9c5b164c75908fcd42e2de87401607eaa617f331d376864Virustotal results 36.07% 
2020-07-22File 2020_07_22 45283.docdoc 4e5ca71ab308655fe2a2430dfbba2c2f7633fbda4a0e4c44714724f00e27dc51Virustotal results 36.67% 
2020-07-22REP_20200722_967.docmdoc 0909752f9e8cf877b820f107687a6dc12e42ab76f995635a56116d94fa3cc86aVirustotal results 36.07%Heodo
2020-07-22inf L220746.rtfdoc ef64e139ac5120bcb2be7ca49559d2e39d9a00d5007ba03f7745618a805d08cbVirustotal results 40.00% 
2020-07-22inf.docmdoc 0eeaea647018150c88d5f2e63cdcdba4dbae14ad5e23b7ac5ae1a632965674c7n/a 
2020-07-22ARC 20200722 QO350815.docmdoc e3a151fd0c1efbcd3873fb1cd5992e620ab4d82343fea02cdd59df1fd962bb2cVirustotal results 37.29% 
2020-07-22ARC W054508.docmdoc 9386f4a822f6bb11eb7588717ea43c765b9501a32ca42607846f8f577ea7a8eeVirustotal results 36.07%Heodo
2020-07-22Rep 2020_07_22 466.docdoc 8377d8c4302ad8a31a44fa320938d524ba143b4b076ad91fda4c5c1b73aa804bVirustotal results 36.67% 
2020-07-22Dat 20200722 38472.docmdoc 2f70b16353998d59b23275fd2ce681d5b5a4ee90b2637c6417d3fd8c5cfb49f7Virustotal results 36.07% Heodo
2020-07-22Inf.docdoc 96836e41326e43b6568b375f848f490a866b35aa2247df397caa46a4f00961d4Virustotal results 37.10% 
2020-07-22Mes 2020_07_22 4868552.docmdoc 5f934443860f4ada8773989bf4ef1a4f9b25d5b0b8449222afdcc5ed0f44748bVirustotal results 37.70% Heodo
2020-07-22ARC.rtfdoc 3cdc4b152007b8583277c7ae4ad9e2df4b455d70ea68db4e16537a0354c97362Virustotal results 38.33% Heodo
2020-07-22Mes_2020_07_22_4442002.rtfdoc 00f9030cbfb095139a4e8f6fc9e282149fb32fa202c75dd95063951b237bdcb3Virustotal results 38.98% 
2020-07-22file_2020_07_22_WL7210.docmdoc b30860973bcdcd040d50b0bb6c2ea01eaba9b34856e80b02074b7366a047438en/a 
2020-07-22DAT-2020_07_22-PL2114.docmdoc 8ab6f085ec3bc42bd4cea7ba63a8f6c9005a1dd198a73976abdc8c749556fe14Virustotal results 45.90% 
2020-07-22FILE_2020_07_22_015439.docdoc aa7523ce6f985896168053604865601a6537f096f85d21d211b1c8d69f3a70a3Virustotal results 42.62% 
2020-07-22Rep.docmdoc a4730c2913b245ccb77ed0c4a10031a10360828ea6681eb4f9831c502bf0c2dcVirustotal results 43.33%Heodo
2020-07-22Mes-39984.rtfdoc b6d61e35726e8b3a7b927301d0577dc610610104d94432cced3a6d063920b865Virustotal results 45.00% 
2020-07-22Arc-20200722-NVL44336.docdoc f075848ad6d384c4cf68d031f2acb0454e37bc993fc8fba6a111d8e744fac9dfn/a 
2020-07-22DAT_20200722_208692.docmdoc d17c29d68d4af4033a871a4bfee1affb3ba3b34aaf54059f3062fc0f78ce318aVirustotal results 43.33% Heodo
2020-07-22arc_20200722_DQE059.docdoc 38ff0a4a502e7e0992adc7b5078f916bd301d0769dcba3bf19008581f73fda52n/aHeodo
2020-07-22File.docdoc 20f74eb9f7e8f81ee1b611f0655bdf258670b368a814815b75af9ddc0a34073bVirustotal results 44.26% 
2020-07-22file_AYJ8808.docmdoc 997f3689474b1e1be428b19fa9eb6927ccf37889b64e7cb0814a1effb83d6912n/a Heodo
2020-07-22Mes-20200722-QB19328.docdoc a01d4df7ec965c82ea4ba5fa2d607e1fc1c14ee2ce6e6eed9bc5508be71769a0n/a 
2020-07-22Inf 2020_07_22 4535714.rtfdoc 7dbe324e0d12ad78dce60ff5e9cd95569b85088bdc2d6a21671c60e099767b7fVirustotal results 40.98% Heodo
2020-07-22Inf_K84082.docmdoc 663a5cc4bea53e83055d9c30b3724798add62c0a512896dac94c3366578d426dVirustotal results 36.67% 
2020-07-22list 2020_07_22 49653.docdoc d89c2b2131e03e4f8eac35b8cb25de8095bafff8642629e1a4b64b391a014a77Virustotal results 34.43% 
2020-07-22rep-20200722.docmdoc 0d2b2e5794724ab6ae57c685edec0b231442d3fcd013fe7ef774aed48cc97bfen/a Heodo
2020-07-22Arc-11544.docmdoc d715c6eef4229b24c8312f01e82a92ec69026046d8b8560f7778f3793f6f88a4Virustotal results 35.00% 
2020-07-22doc-77996.docdoc 933c7f05b56492f880e1716a1240b0bf1679fb740c973b5adff2f3575ae2a3b8Virustotal results 31.03% 
2020-07-22ARC 20200722 U230900.docmdoc fb1530a751799859585501c02c6cce39addd2e4572d8df0149ae14735eb2f113Virustotal results 30.00% Heodo
2020-07-22rep 967.docmdoc bcefdd2db5550c86f7721b4324328f45370dd06b6fc7434278387d60ab7443a7Virustotal results 27.12% 
2020-07-22rep-2020_07_22-3791646.docmdoc ad0b84b38f613391231e63d53e800947407c72b0e2b87c9a79cb58d7d3520146Virustotal results 27.12% 
2020-07-22REP_20200722.docdoc 6babaa931bc26a787edf3d1d3118c0a45416f2e9deb01bc741decf522a2bda49Virustotal results 26.67% 
2020-07-22LIST-20200722-264.rtfdoc bda45a277d1d57050ac2f680f22b728a35eb2aa5d67471ea2b55817d66a982c8Virustotal results 26.67% 
2020-07-22doc-9413.docmdoc 3df05f387f43858fdc3530301f6dc27b9ac2a89560059a40ee635b6a1f25497fVirustotal results 26.67% 
2020-07-22ARC-2020_07_22-924.docmdoc b35d6f30710cd9faba8bae89a03e685b49544da9744821e0123e6585740a0e3cVirustotal results 28.81% Heodo
2020-07-22LIST_G18501.rtfdoc d831521ed1fd89695ea1f405aea9680401dc470716ead9076e1c428afc608093Virustotal results 26.23% Heodo
2020-07-22List-20200722-GUM969784.rtfdoc 21443c68d64ecddd740c7966067a4bed9de79aa081c06b9ad97fe8d8d0e0716bVirustotal results 25.00% Heodo
2020-07-22rep 2020_07_22 Q30934.docmdoc 3ddd3251b6460b9b8fc544ad79d56857861363651da3d1b0c4054d54777366e7Virustotal results 25.00% Heodo
2020-07-22INF_2020_07_22_5594.rtfdoc 8a4dd2564fb906334e1702628a5b52b6ab20497d1a5522332c4879a1eb778c7aVirustotal results 24.59% Heodo
2020-07-22inf Y577934.rtfdoc ab94ce7c4673e1e4f599bb543f7fe1ccd17d8b3f96ca4469b82d0b98883148cfVirustotal results 25.42% Heodo
2020-07-22MES-2020_07_22-JGJ96124.docdoc a018bebb6f4d713eff5d16c6b80d20df72bab7d5e055c287018f1f842f952e1en/a Heodo
2020-07-22DAT-2020_07_22.docmdoc 737f7e0557c9203033464070e06e23e7675c8325abd0083d1ebbdaca3f7eac2eVirustotal results 37.29% 
2020-07-22REP 2020_07_22.docmdoc 8aec85cd8e1f0f312d2a3442272e4634ea845690457c6a516b51378c868a1c34Virustotal results 34.43% Heodo
2020-07-22File-20200722-G31975.docdoc eed180c709224d892fa8a82e0c51bf623d7057a65ca483d45e3d005984dc6588Virustotal results 32.79%Heodo
2020-07-22Dat-VZX2688.rtfdoc 7eb51f8c4719f0171a98650b63385c15908628fc4ef7838c410fc53c46a0b8a6Virustotal results 33.33% Heodo
2020-07-22Mes-20200722-4802676.docmdoc 84ee9ec33d16ade130e8842b327ab3d4b8480fada3bb6fb25ad854dea738e9beVirustotal results 31.15% 
2020-07-22file 2020_07_22 2693.rtfdoc 3113c9be4e91ab866a9d0a0a3a71236962f0598a11a4345f114dcf1e3feae621n/a Heodo
2020-07-22arc 92240.docdoc b58dbe82f7a65596a2277d1c5ef1e42945e45cd0ad84c35872e1ed404607b9b6n/a Heodo
2020-07-22dat 20200722 14276.rtfdoc ca232fffc32f90a27bb9e8f4cef3966e1e0511ea34323aa76060ac1992774a5cn/a Heodo
2020-07-22Dat 2020_07_22 XTW61352.docdoc c20821e80c5ce943d4b87b9416329f0502a4da3c97044c8fd7016172353e1626Virustotal results 26.67% 
2020-07-22dat-20200722-AJG261.rtfdoc e70e7b20d9e23e2639abe447b3d8d93dd81d0aacf5a4805f4a39a1a6f042a068n/a 
2020-07-22doc_GVN6283.docdoc ebdc8f40febf78564180a0f4a84f3ec60622fdb13e5a18b627ecd8f86f4e1b85Virustotal results 26.23% Heodo
2020-07-22File-2020_07_22-VMK755816.docdoc ecec36458fac5fdf0031917d979c2539b70801bdee88e022ee090a48109e63b0n/a Heodo
2020-07-22file 2020_07_22 326979.docdoc 8d70f6580cf02bcae5c4c14396951b6e6c1ea10bcbcbb89f835c29dc7d2c8cebVirustotal results 26.23% Heodo
2020-07-22Inf-20200722-E9257.docdoc 3e65642f10d2b821a0c08b74d0ddfd34717dca5f9918551779815db934ae7963Virustotal results 26.67% 
2020-07-22list 88827.docmdoc d7b8fec9f533a9c31e7fe587b89552973d00bff30e4c7d8f7d4f2d93bc0eda1fVirustotal results 26.67% 
2020-07-22Inf_20200722_232.rtfdoc ea444cde5a8ef5b6165a348732af41e4c634669259036caae42e242c5a7c9b1cVirustotal results 25.81% Heodo
2020-07-22Rep_L518.docdoc 7fb831a6988b9e816af85e485721d4e44b500b6a9d30af5b82cf9ec4d28eb584Virustotal results 25.81% Heodo
2020-07-22INF_20200722_6538.rtfdoc d3bfea33a12c522ea8faa7840613e14c78035362c064c858c1467513a68ac9a7n/a 
2020-07-22dat-A349630.docdoc 812ed74f92912f98accd025c7c64b9c943032b3379fe1c9654a9deeac6d8b981Virustotal results 27.12% 
2020-07-21Dat 20200722 E43744.docdoc 435f4fc1e9a6888f671e834bbdce6aafc5928c7dcffbbbe728f18573b73da965n/a 
2020-07-21Dat_2020_07_22_5820016.docmdoc 3ef294ca4013371b69d6af647114806b71bb3dc07fd56f12c078703411d61b3dVirustotal results 25.81% 
2020-07-21DAT-2020_07_22-3207360.docmdoc 3e24c4373b1e2ba1e3d16925cd0d4a1752452402ae4aaa8ad8ce498bbff5335cVirustotal results 26.23% Heodo
2020-07-21Dat 20200722 JFW87229.rtfdoc cbccd20b9bc23454ec01bec4a0094e77dcc43d577666259f8d97aa30a118ac35Virustotal results 26.23% 
2020-07-21FILE_XKD0712.docdoc 2027e8348e8d2f364d55b2bf47f9a4b37fd2ff7aabdda5ed056e3f6cd42cf777Virustotal results 26.67% 
2020-07-21list_2020_07_22_IWE7965.docmdoc 139f5bcf4c7fcbe0a8a5d940c5d38dd847e2c979df74dcf680208e73b8ac668dVirustotal results 26.23% 
2020-07-21List-878.rtfdoc a8eaeae150c0c2f63c21f90adf8634bbd7653092f06a273410a5c26df3f0e25fVirustotal results 25.81% Heodo