URLhaus Database

You are currently viewing the URLhaus database entry for http://simulations.org/rw_common/DOC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:419962
URL: http://simulations.org/rw_common/DOC/
URL Status:Offline
Host: simulations.org
Date added:2020-07-27 15:49:06 UTC
Last online:2020-09-21 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-27 15:50:03 UTC to abuse{at}videotron[dot]ca)
Takedown time:1 month, 25 days, 23 hours, 52 minutes Bad (down since 2020-09-21 15:42:07 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29RRJ_PO_07292020EX.docdoc 50b748b79bdb99370387508486bfd607f302fac6a15eb7e899c6d07c520fa245Virustotal results 34.43%Heodo
2020-07-29DOC_PO_07292020EX.docdoc bd6261e1e869e0ecb65a5dd98b24fc4c71b75e51e8cf2dff74b0da42dc86b5b4Virustotal results 34.43% Heodo
2020-07-29INV_PO_07292020EX.docdoc d92e4dd34381a1b20f114dc122c6f542aebe6d7633579c8b6f1d934f25666201Virustotal results 34.43% Heodo
2020-07-29REP_KXPAI3GY6U7V.docdoc 8d9870884bb447b8a12ff0335f35d1bf700ca94e4b4b1b06534909f93586f6ecn/aHeodo
2020-07-29O_742761277.docdoc d74557f76299fc8edbb589b834ce1ee44477f4d4f1160a7b1e368648779aebdaVirustotal results 33.33%Heodo
2020-07-29REP_98747959307249299855.docdoc d32b9efd8f82427e98069b5a06bcde907a9f906406d27e85ff7741cc7d338febn/a Heodo
2020-07-2989036085.docdoc 4947e47ca102585589473567e7e3f0e8b9051aea7f9d08ee1409ddb7ad6bd2e9Virustotal results 28.33%Heodo
2020-07-29S_PEQ_070120_LMZ_072920.docdoc eef9719d24fd5e7e4f8e92e667874c426ae77519de41e4a5b0ae32f647f5a4d4Virustotal results 28.33% Heodo
2020-07-29PO_07292020EX.docdoc 35882c33b875d15f1c62d995a525bdbf80355da1abfef138e5b369c5543b2ac9Virustotal results 27.87% Heodo
2020-07-29DOC_FGX_070120_QZM_072920.docdoc 5a959afcb67ab697d8f53e2e91f7424fb274bee1600360681f6b61c26e377fd7Virustotal results 28.33% Heodo
2020-07-29DOC_RY6617290125XH.docdoc 255028b13e1798a9210c65582ec63fe7da4f42e7a9cb9f68ebd049b60ebc6219n/a Heodo
2020-07-29FILE_OOH_070120_ISB_072920.docdoc f2079fe72b86eddb5c15d9b80c2cc59076a08c0fbbacc4663d5573f5fe40e88dVirustotal results 28.81% Heodo
2020-07-29REP_KGZ_070120_GCR_072920.docdoc 5aa3782f329a744d9e986c602f77efc5a7103e056f7eb43db157d466d7268ab6Virustotal results 27.87% Heodo
2020-07-29REP_98495410.docdoc 1257945161cce1eb5a26d2ae6cd6d914e96eb7e505d3f37a281f2d091e2a7a32n/a Heodo
2020-07-297373428001.docdoc e8f499a49f0182ca1b86f7b7795f561d6739caf6baf7f884357657be05fc68bbVirustotal results 27.87%Heodo
2020-07-299152215709237.docdoc 8ae3245b9d11f03d3275763f2cb4bcd2f27af42a9b03eafa5829b0dfdf47003cn/a Heodo
2020-07-29SO2883809630OT.docdoc 9717dbbb7696ef497143d3a902bcf432a609b276d5416c302eadc752730c522eVirustotal results 27.42% Heodo
2020-07-29KF3908233974SM.docdoc 10361963fee9e09d6ecba109538947570bb5bc47275c46101f018ad1913138bdVirustotal results 26.23% Heodo
2020-07-29INV_IF5025809777TE.docdoc 92ab5fbf4827be051e260821d689c3fd5800fb03d81248cabf4812959da6c343Virustotal results 26.67% Heodo
2020-07-29XE1230202400MP.docdoc 95ddeb5b478660d0b266b024dd44aebd724fed9224811a72568ad27a0d3de832Virustotal results 27.12% Heodo
2020-07-29MS7903066429YW.docdoc 4dbbad92c8a96176270226654745d40e4df036d5e94064fa8784f48fb3124b7cVirustotal results 27.87% Heodo
2020-07-2909340579.docdoc a1774a6485655119ea70b0979992d361b648420fb0b003439e52adff57c241baVirustotal results 47.54% Heodo
2020-07-29REP_RQO0NFP.docdoc baa488f3a77d501d8ec7735d3df63912a500ac36a4daeff60abd475795b9343aVirustotal results 46.67%Heodo
2020-07-2969262888486.docdoc 9e3690a0a71dc239833dddc5b2aa94983eec61d88a636aa96f12bcfac9898592Virustotal results 41.94% Heodo
2020-07-29CBV_070120_QSU_072920.docdoc b3ffca228d4d444172e54cbafb591ce0d37193492c7775c7dbf7e8c8e6bc00dcVirustotal results 42.62% Heodo
2020-07-29REP_CIR3M9NHB13J.docdoc c2b7bf81008abd52155b00d75144e43087cf71e1171f4a0a594e2471b9678378Virustotal results 41.94% Heodo
2020-07-29PO_07292020EX.docdoc 3de845b9dc4ad5aa22fd3587bf71351eda91ae61c1003f4df40c75bf422f548cn/a Heodo
2020-07-29U_6P911YODO2.docdoc e7efbf8e260c6820d94ea6e8f46ab6bad5ba9bc28a33bf73ea420854de41caf8n/a Heodo
2020-07-29INV_952361060038792.docdoc 8592e77c1c48d939b205ebf81fe0b5903ed8d37d9738f02db0360c37442133ddVirustotal results 40.98% Heodo
2020-07-29PO_07292020EX.docdoc 1f19f1cc91f28959e4f1a099b4f6d11a2dfd3b5d5ecf73f596b764dfdc356b57Virustotal results 42.37% Heodo
2020-07-2843469735.docdoc 9e2785a9cb319ef1e1ae50d46ca804ae72583b7910a6c8fcd6bdafc8fd8ce956Virustotal results 40.32% Heodo
2020-07-28G_AQCU2F3V7XYEO19D.docdoc 26c4e8ead2701556bd3d09795db4bb4cd554b40cf9f30b9e76b7434c0e6e96fbn/a Heodo
2020-07-28FILE_02519609.docdoc 63c74b892d39492d60408cece9e71cc78d5bb63eb8f598ad5d4f1f375c2745fdVirustotal results 40.98% Heodo
2020-07-288177320974442.docdoc 50563ca2e8c59a4a909655f6fc73f1b3700042972dba5cf08ccd036321098da5n/a Heodo
2020-07-28VP0241866792QK.docdoc f11b8a55079b29b5a63d984d3c29da9b7fcc2d7a0208fd59321de596595d240dVirustotal results 44.83% Heodo
2020-07-28DOC_VXEMYB506.docdoc c46ea06e842e6d711490963a8e862a721511bb33e041fea939dbcb3ab001203eVirustotal results 40.98% Heodo
2020-07-28REP_LA2010063319MU.docdoc 040eb6591f2ab93e8868b61948d73fe36651ee8af6e4f2ee985708a9ec43126an/a Heodo
2020-07-28FILE_RB6538154388GI.docdoc 3b37651a73e7c5c4c966ac34a4b38a9e69d7eed9f17e276b8f84f43749cfc70fVirustotal results 40.32% Heodo
2020-07-28REP_PZD_070120_IQP_072820.docdoc 840a3b8168fdf4428b543d87650addb48e7373d78b0caba579d8a4e49c6cf99bVirustotal results 41.67% Heodo
2020-07-28REP_PO_07282020EX.docdoc 87135faebfc31f34c94e02ffd43281b0e6cc7055ec6ef5eb5d60b29df1009c22n/a Heodo
2020-07-28BAL_MHP2QL72LOR2MYVK.docdoc 9bf049c3356bbba6bc9e82bd698a785902daf6069e90ac638d402f83c4cd9d59Virustotal results 40.98% Heodo
2020-07-28INV_73738861.docdoc 6b53332bda15c69cb083d1fa101defcfb1675aae6392ba119aa464638697e0b6n/a Heodo
2020-07-28RMM_070120_SSP_072820.docdoc 5a5a1de568829f744aa5dafeff7301a0cd703b4815e4be3a77f7dfca352438bfn/a Heodo
2020-07-28PO_07282020EX.docdoc c2dd657c048f69cc272050ec717b2c8d31cb310b02e2fc5bd920783a0cab340an/a Heodo
2020-07-28PR4883180396VF.docdoc 3615380736188fe0625c45df6c98b644a1958e722b1ba3baf0ef861c09ae4efbVirustotal results 44.26% Heodo
2020-07-28NA_HBM_070120_DNK_072820.docdoc c0abfc654f0e7e781bed0aaae89924773004af65aa46af36b80189f7368edb64n/a Heodo
2020-07-28INV_9042193219077701659.docdoc ce54e66c7246ba448e0fcfadc08194c00262f5e3daba0f8c77f57b05d326e7acVirustotal results 43.55% Heodo
2020-07-28DOC_PO_07282020EX.docdoc aee8c34f1c430fedfc697089732e0d51939863f4253fb7455be1773ffea8de0bVirustotal results 42.62% Heodo
2020-07-28LJ8074920221NY.docdoc 0a2818ce9bfd7f5eaf2b201eeea0b4e9f4d110587584ed13017b1574324b099fVirustotal results 42.62% Heodo
2020-07-28O_GWT_070120_JQI_072820.docdoc e0c8706f01f812beb106bfb124ddad3456dd4e33159910d1c9588ac63e00c2abVirustotal results 42.62% Heodo
2020-07-28KBK_070120_MZX_072820.docdoc 9f0ff88a05a5b3cd763f233b4764cb591599142f82dfc63c3f4acf1d9d7997f5Virustotal results 42.62% Heodo
2020-07-28INV_GVE_070120_FQP_072820.docdoc cfe67567737aa3c2dcdec28c0d6873e5e340c8ad049faa917c527f54e1c1875dn/a Heodo
2020-07-28REP_MJW_070120_NBO_072820.docdoc e85502045fec3d9af13567ce4608221f4b92f8b0262e4bae4dd305385079e63bn/a Heodo
2020-07-28REP_EYBNYU66UT63W.docdoc da3bcdea8cc3b33756792fdfa11bdef92dd36e4620ada8b660fc12cc211b4281n/a Heodo
2020-07-28REP_865562495503660558.docdoc 8d27e36fe079fffb278a007a07dbcbfb37ae765b71bcefb8e0e41c4a70101512Virustotal results 40.00% Heodo
2020-07-28BAL_ZT8058079725RR.docdoc ed68893c9c4a4e3abfcfa85ca077b8d013605d2994fdd6c42b2858cdc2bd30d8n/a Heodo
2020-07-28B_13094732.docdoc 33892c4fb618745a9020642ae7ab40da499637463bad8dfde420034b8f9c92a0n/a Heodo
2020-07-28MFFF_34508607548.docdoc 3462186176f663901dcf8db6383a21ecf0995c392966bd5e17f518fb7c0f6961Virustotal results 40.68% Heodo
2020-07-28INV_95214258.docdoc 878399ac6fca1894c7e9acc48eddb6a535513a4fc7b0b8aa410b19c0f85cf361n/a Heodo
2020-07-28T_PO_07282020EX.docdoc 6277f4f92177c8a9d172a70df991b4b7d04cff62b0f2e04e78d277d2aa648411Virustotal results 39.34% Heodo
2020-07-28DOC_PO_07282020EX.docdoc dcab281c030ca8ebd833b95d2379df634eec571e1ae19b6aad70ae1a0eb2e07en/aHeodo
2020-07-28FILE_PO_07282020EX.docdoc 7880dbee79353af6a070ba20eda972b3ef7abad67d3c309d064ced44676ed6e4n/a Heodo
2020-07-28B_05553596.docdoc 23c51d3c717104427e3ee990c8db28900701083c086707b24493ad7f9968be97n/a Heodo
2020-07-28FILE_PO_07282020EX.docdoc 69314a5a40529facfde61bb78562869e4ca9a67ba69a3028d376a265e174ea6cn/aHeodo
2020-07-28DOC_73567459968233043519.docdoc 2840dbe68611c23040d1bcd78b9473dcd48de959c93280ee78f105b5af51fe75Virustotal results 37.70%Heodo
2020-07-28DOC_60CDCSPCP0K.docdoc 8b8b2829eec27c2687e1e4dfb190e65d66875564f241e73d6229909a552a510cVirustotal results 40.68% Heodo
2020-07-28INV_0A8DS8VCEGW.docdoc 26906041efdeafb6c1754eac8dff97abf079148816f1121ef92bfaed0a6e9991n/aHeodo
2020-07-28DOC_W34N0ADIXRHRE.docdoc b5ff10eaad0448b933f253da6bfde702a18b8fe967e071e92fc3587fe3e0c4b2Virustotal results 37.10% Heodo
2020-07-28O_JU7375949708NL.docdoc ba613571c6d4657eb92bf9852164f5e774f458def985b842e8594704632bb9e4Virustotal results 38.33% Heodo
2020-07-28INV_XYG_070120_KJB_072820.docdoc 03c755321460ac4015e02fbda399f9fa099bfcf9566ac0b91ff525f03bc9dca6n/a Heodo
2020-07-28PO_07282020EX.docdoc 3922ed31097dad6980d7aa3830470de434d9e128f5f37fecabf5637e7c5ab0e2n/a Heodo
2020-07-28FILE_17271968.docdoc dc7c90dcb5ec12e5b8f816048d2843dcc7c972ca78b9e48578a917666e7a2845n/a Heodo
2020-07-28DOC_UD1081895374YM.docdoc 20d81ffc64ba89a114dc4ee30c643d555945ab0ec0f3a17c96b56d6087ef3b13Virustotal results 42.62%Heodo
2020-07-28T_PO_07282020EX.docdoc 3bd36ab32026af0a6cb457a12a0ba75df13d8e6a288da64ca838af0bef9c2e24Virustotal results 44.07% Heodo
2020-07-28FILE_61340331.docdoc feb69e5e064dc9aed0fb86311321af444f6296260687339fcceb53d31201a026n/a Heodo
2020-07-28DOC_QU4FL3Z95.docdoc 7d63604e1fd27ac31666ba76b7d7d82a09c6035a6fe9bfc257a9e7b9249ef525Virustotal results 42.62% Heodo
2020-07-28PO_07282020EX.docdoc 1e687ad756dada51e71738e9b4af3eedc481d865f7df0bd32500ea50bd16233aVirustotal results 42.62% Heodo
2020-07-28BAL_56228240.docdoc 388d49d105196dea02e96ac0172560dff1d9862e5b8910e7af963585439dbde3n/a Heodo
2020-07-28FILE_87317340.docdoc 8cb2ee65b209dc77c33984c49bd4ed006fddd9fb40132c166c494f47cafbd5bfVirustotal results 42.62% Heodo
2020-07-28REP_XPA_070120_LYN_072820.docdoc 29c42aa5892fede943d2975f64abfccbcc8cfa164a85e278753f970a17d010den/a Heodo
2020-07-2865179336.docdoc 2b4263841c81074211dd59e820bf05562e5c59be8d38bf8791a0a21753cdf504n/a Heodo
2020-07-27ZIM_070120_DFW_072820.docdoc dd1fe9f11a267149ce356a768d071605c1972fd10d1f7a57a29fe8a2c8fb41c1Virustotal results 41.94% Heodo
2020-07-27H08PDKDEM87PH.docdoc 3e21349ba3bf686515975146afcebe14651b2304ec58b47bea6b87b5fbc79a69n/a Heodo
2020-07-27BAL_THA_070120_LXI_072820.docdoc 2bd01d881217785295064f5e2d94720a9d0952d1ee3888349b008bce7cf5dd8fVirustotal results 41.94% Heodo
2020-07-27058989819057079178.docdoc 0a2efb0dfe85f3fb776bdfaf83eb0b8b4f17d2f52d4a75552928b1ef7ff1f76dVirustotal results 41.94% Heodo
2020-07-27REP_WKDXFUDLX7E.docdoc 2ae67471c658ada5648053a5da6b55d64bb0f6de4ee16ebfcbc335055b398f1bn/a Heodo
2020-07-27REP_52029790818.docdoc df3f07a28988e65741321c968afd02eaf8a49fa2dcf2e2f2685d04e13a236122Virustotal results 42.62% Heodo
2020-07-27PO_07282020EX.docdoc e014e7351a4ad87f016b72570a6ea61c63069ef368ef1501bf75c019760740d7Virustotal results 40.68% Heodo
2020-07-27SL9507351620UR.docdoc b055c91beadcc69f982e372bba82ce74efcb003bb9c2fc772efae1a27beb3387Virustotal results 40.32% Heodo
2020-07-27BY3249899579GP.docdoc 5d08f7fb64c5fc4af654eed617b862ed33cd458b34326c027882d886627f96d0Virustotal results 40.32% Heodo
2020-07-27INV_58407450.docdoc 2317a555c5aabac7a3b94757661b5ca7f25d7612b4c4a93df00b35fa56fd8e9eVirustotal results 40.32% Heodo
2020-07-27DOC_CSPZ536MZKWWAG6.docdoc 0da558e5de9d2aa59b4abce50bfae6b5d6100210944d4d9f863751cf5049ab89n/a Heodo
2020-07-27E_859736623919863893.docdoc 13d7c7fcf925089145ba48d21b26bd672ce6184d990dfb487c149d912d4cd347n/a Heodo
2020-07-27REP_YS1335663940MO.docdoc a2567b74182ca4bcd6e1d71b9d97079c0e9e0b0e311f994050401968d53b2a41n/a Heodo
2020-07-2748246402.docdoc 8e8c8d6fbb0a1654fc7c5b17303cd74e708db925ed43edb75424d088dcd64a2bVirustotal results 37.10% Heodo
2020-07-27BAL_13501663.docdoc 73f18a8c44cf04ebbee8f78a84fb27af4e997c7fbf96c64f9a766abf558c6ee2n/a Heodo
2020-07-27G_PO_07272020EX.docdoc ae3fe22384694c5fb3e90b4187e3766f58f0a7cacd0d60df5b5928b8cb380c69Virustotal results 36.07% Heodo
2020-07-27REP_91252996.docdoc b466b6838413f70d7d45be04456491e75140bf1180eb7a2162049fad1bbdb8e0n/a Heodo
2020-07-27BAL_PO_07272020EX.docdoc c990553caf786b8c95f0e8357fc0e5f81c153f9463af808381b108779bd7b50dn/a Heodo
2020-07-27INV_AFL_070120_HXW_072720.docdoc cf253830c0484f6a93945b844e71d9d20ebe95c0a8e699fe12be87b07d04959eVirustotal results 35.48% Heodo
2020-07-27RH_56963470.docdoc 7ca74b3c7abb4df9b42143995e6df94e5cdc55a6736e58abee7a70bd20032c47Virustotal results 35.48% Heodo
2020-07-27L_PO_07272020EX.docdoc cce46da95472c73a2b5454ca83c55e19d71835c8c152eba821cf97e9f7bbc1adn/a Heodo
2020-07-27DOC_PO_07272020EX.docdoc 9f2af6ce30c83a7a9ffa60abec4aea20dc46d3ba79c249e1e010c5a0cdeb5d87Virustotal results 36.67% Heodo
2020-07-27I7T2CX1YJKMMN.docdoc 99fac314dd47a854ef8277c1789099edb56f00702532ca41dd2c761454ac40d1n/a Heodo