URLhaus Database

You are currently viewing the URLhaus database entry for http://revmom.com/Reporting/79s2leelotf/ju0769004465645hiiwl3jvyw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:419761
URL: http://revmom.com/Reporting/79s2leelotf/ju0769004465645hiiwl3jvyw/
URL Status:Offline
Host: revmom.com
Date added:2020-07-27 10:38:06 UTC
Last online:2020-07-27 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-27 10:40:03 UTC to abuse{at}quickpacket[dot]com)
Takedown time:8 hours, 5 minutes Good (down since 2020-07-27 18:45:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-27FILE_41QLC3HRJ8O9927.docdoc 8e8c8d6fbb0a1654fc7c5b17303cd74e708db925ed43edb75424d088dcd64a2bVirustotal results 37.10% Heodo
2020-07-27BAL_OBWRDGWH.docdoc ee15b91ffaa6ccb45f34e54e28cac0313eeabf7ae3be97772023b75d65c1b778Virustotal results 37.70% Heodo
2020-07-27BAL_T7NPO1H7B.docdoc 8c34501d79ad72ce3d667b0207ccf20a512041cf3ff5b8c5b0a5226e6c5f9e05Virustotal results 35.48% Heodo
2020-07-27KA9095229450AW.docdoc 9f2af6ce30c83a7a9ffa60abec4aea20dc46d3ba79c249e1e010c5a0cdeb5d87Virustotal results 36.67% Heodo
2020-07-27VEF_65763581.docdoc b55ef1a5bf7039156fc966f9ee6029eb34adfed07eb41513323dcb531f423a9eVirustotal results 36.07% Heodo
2020-07-27FILE_HM3541756559ZS.docdoc c1b384454be18ab1bcb25dc31ee1a9432283f35544667066f60d88f2b292c53cVirustotal results 37.29%Heodo
2020-07-27DOC_06747676075.docdoc 91631b5f74221ef36cfacf1572e87d4a71c5876f16e20d1131401cf6f61f0c1en/a Heodo
2020-07-27CXZV0LCDEQG.docdoc 09f7d48ed4d70c24ee8888b1ef67071cbca500ff3fe98267923a5ff68d113b28n/a Heodo
2020-07-27INV_68665851.docdoc cfb29bce041ca72fbf97be1b608791b9d7e4fd6b632aebf4f91111ce6491cfc1Virustotal results 36.67% Heodo
2020-07-27REP_70785578201906659393.docdoc 2ae81b3cde0a7cc2ff55de0a4184f193e47817812d4f3cddcbeed1b937123958Virustotal results 36.67% Heodo
2020-07-27ESE_070120_YND_072720.docdoc 6c963e5f156a1997d05217dd2e95b78b3acc18dd0d021edef023bc2cf3da4f9fVirustotal results 35.59% Heodo
2020-07-27BAL_49933673.docdoc 7da491ebf960db553ac5406c952edb7e3f5edbf1c8a0cbac65e1ec1a7a0ee766n/aHeodo
2020-07-27BDFI98FHP717RP.docdoc 1b4e844088d36fc73b6e546b13fe5a60313c4bddfd8ab74de8471c04821040a5n/a Heodo
2020-07-27A_PUK696G48AF.docdoc 5741a2a898d4a2a3f7b29ccb694f2127a4eeca7b27a026340c6ecd396ed5530cn/a Heodo