URLhaus Database

You are currently viewing the URLhaus database entry for http://ravenproductionsltd.com/private/90652/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:419765
URL: http://ravenproductionsltd.com/private/90652/
URL Status:Offline
Host: ravenproductionsltd.com
Date added:2020-07-27 10:47:10 UTC
Last online:2021-06-26 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-27 10:48:04 UTC to abuse{at}ihnetworks[dot]com)
Takedown time:11 months, 4 days, 11 hours, 14 minutes Bad (down since 2021-06-26 22:02:17 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29INV_W9AVWIJU9A.docdoc db9b63cdcaff706197aea2e1a576f55006b3513170c106f6e2ee66586482b6f6Virustotal results 27.87%Heodo
2020-07-29DOC_VJT_070120_LZG_072920.docdoc 0e07a965c3590bf322b05d1cef1d77ecfb44f0af9c1932dea9e5e7014b5b9b4dVirustotal results 27.12%Heodo
2020-07-29INV_70644053.docdoc 07e52d952fad4d01da29f568d5fcbe57574ab3f02abea82936716fc9c1671b2cVirustotal results 29.31% Heodo
2020-07-29INV_PO_07292020EX.docdoc 10361963fee9e09d6ecba109538947570bb5bc47275c46101f018ad1913138bdVirustotal results 26.23% Heodo
2020-07-29ZIQ_Y7HHJVSWWYUZ1.docdoc 9ab92090f841355a66c7a8807dd706180f5326f0ac8711a80b36953821641740Virustotal results 26.23% Heodo
2020-07-29REP_KGONSJ0XXNLJNF9T.docdoc 85d095862eac57f9468543eca0c155a633dcbe0258599cb769b157125686fd88Virustotal results 27.87% Heodo
2020-07-29REP_CFL_070120_SOG_072920.docdoc 9f358574eb7a51cf4bb7d24de400a5ce72211b45471c448b33a457c9a9e360e8Virustotal results 49.18% Heodo
2020-07-27Q_PO_07272020EX.docdoc 091c7db7d68767950328e64b4574e0ccb394c6362ae3ffba9458abb4d2eb549cVirustotal results 39.34%Heodo
2020-07-27BAL_WZNEKVJ0MYM0ZQ6.docdoc 6f897aab655e9d25966fbfbffd2855933c78ea167b2092cd239acf29ac12d51aVirustotal results 39.34%Heodo
2020-07-27BAL_44740068.docdoc 7da491ebf960db553ac5406c952edb7e3f5edbf1c8a0cbac65e1ec1a7a0ee766n/aHeodo
2020-07-2778236108.docdoc 39ad03bb0aeee481c7a7a5e63f5461f2af3e66e8e1b9d9e1ac05cc2de8985919n/a Heodo