URLhaus Database

You are currently viewing the URLhaus database entry for http://cflaval.org/quiSommesNous/multifunctional-module/external-portal/6mm7rv-5xsyx12v1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420029
URL: http://cflaval.org/quiSommesNous/multifunctional-module/external-portal/6mm7rv-5xsyx12v1/
URL Status:Offline
Host: cflaval.org
Date added:2020-07-27 17:36:16 UTC
Last online:2020-07-28 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-27 17:38:02 UTC to abuse{at}ovh[dot]net)
Takedown time:11 hours, 40 minutes Good (down since 2020-07-28 05:18:10 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-28list 2020_07_28 6195269.docdoc ef6ef0f8ef438897b207562f0d8b11883e9f757636f1a59848d19d93549a1eeeVirustotal results 45.00% Heodo
2020-07-28arc_O7612.docdoc f17c0f459fab0492c863e99c1a5792ad48d11acddb5e049a6b4c39f99ce8b344Virustotal results 43.55% Heodo
2020-07-28Rep_CX494.docdoc 36a2dcdbe270ab3526bdea28407cfdec949c82215605a7d871c95f6803ef2eb0n/a Heodo
2020-07-28REP_20200728_FLH395858.docdoc 9daf8a671b527a71c8a7a17a95ee2828e782aeb81f3e718acb747945a617bb2cVirustotal results 43.55% Heodo
2020-07-28LIST-2020_07_28-IKM689112.docdoc 1a96354d5160003954ee2b2cda62e5aeb5d637ff5783111aa169ec5c84b4a422Virustotal results 43.55% Heodo
2020-07-28Mes_20200728.docdoc 4ca4d1e4470fc34af7ba6930b887d43ae19fcd3a58253e8e08dfca1543e49c7aVirustotal results 44.26% Heodo
2020-07-28ARC_2020_07_28_2655854.docdoc 6f752dcbe61a11bdfe7b1b0d52104ba5efec6539f9588696876a091ae7feba58Virustotal results 45.00% Heodo
2020-07-28Rep_20200728_AU0877.docdoc 21dce6efb379371051277359737d8c090f5bd3feb2322f04fadc8c1da068432dn/a Heodo
2020-07-28REP-ZJ877.docdoc 1285ab067041ccc47554c1b6a78dd2ab191d2426e7242817235a92f1f674307cVirustotal results 44.26% Heodo
2020-07-28Doc-20200728-D39910.docdoc 88f424caef167c363184d8497774224063f29ad00f73366ac8d1cfe921b19741Virustotal results 44.26% Heodo
2020-07-28doc 2020_07_28 64945.docdoc ff97460ec476ba0b1dc6bf5044dc590c950725e79412fb75bcb38f37bf94e227Virustotal results 43.55% Heodo
2020-07-28list-2020_07_28-R778639.docdoc c8f7207b776cd41fd7bbd4a9c1bba2c4c1161dc9a1e132d8754d87743107e43dVirustotal results 43.55% Heodo
2020-07-28arc 20200728 CWN4743.docdoc 0eac07138b228f378cdcf932ae99d43434a3a644db3255f402e18a63335e9ff4n/a Heodo
2020-07-28MES-B848890.docdoc ae7f037dd7436f637bbb6f62f4a44f2dcf5ddbe56fa25edd87e054d203e34d27Virustotal results 44.26% Heodo
2020-07-28INF 20200728.docdoc a07b7087aa9e62580d3df6662c97f7827de42955fe766f0969af529daaee016bn/a Heodo
2020-07-28file_2020_07_28_0012.docdoc ed42839bc1ce973dc9b130fc3bf6f29300210d2351b6caae9b715bbaa5a50e8eVirustotal results 44.26% Heodo
2020-07-28file_Q517601.docdoc 65750bf28b7d4acf01b9eb045e261c88920a881299f29c97aff7ff4d42be2104Virustotal results 43.55% Heodo
2020-07-27mes 2020_07_28 3073.docdoc 80c2733aec99f5aab73c4555949f84ae4ebf7369955d07fa9a0c4a8d06265fe3Virustotal results 44.26% Heodo
2020-07-27REP.docdoc 89c0676d70b229ef63b2b04b4a00aec67e5b583e4d8ca3eb06434f7fffae1dbbVirustotal results 44.26% Heodo
2020-07-27list 564.docdoc 9b9fc48b3a867f41ceafcad4eb30f015f67a30ad192aae45018b530c6f4bffaan/a 
2020-07-27ARC 20200728 MED728775.docdoc 6318006343841f00c3c81c36a2259fc2744780c8d0ea1de93d8920116f8dd2acVirustotal results 43.55% Heodo
2020-07-27DAT 20200728 466879.docdoc d5c02f77a90c627c04faa9dabbeb7271d11a7df0749d07af987994c830ea0657Virustotal results 45.00% Heodo
2020-07-27FILE_7312498.docdoc f9e21c32753d07b9af540aa838505f4aab10a1fc3e670affaae3c322976891ffVirustotal results 43.33%Heodo
2020-07-27MES_20200728_2730.docdoc fa3daccc5bb500ad9b60a7054441ea832c9f792285acbe3dfdb188763bac9019Virustotal results 43.55% Heodo
2020-07-27List 20200727 0810052.docdoc 5710b01ee4d0e978814cc2610a9cd3a20fd8761101b3a3de4f63b51679796c0aVirustotal results 41.94% Heodo
2020-07-27MES 20200727 4017.docdoc 8bcb81a90d9831d9b0ffd723b83b907cbf0011de32de2cb18c01cbd66b11d47eVirustotal results 41.94% Heodo
2020-07-27REP JTZ8803.docdoc 1a704c94e4b9c2397d69c18e3bcee059f55c598d5ab8bede5013a0b9714f68d8Virustotal results 41.94% Heodo
2020-07-27Dat_QLM415.docdoc 5588396b9cf93b36678e28fd8d7d99d5cc61d2f6b5ed687ebb6f68332bef4f76Virustotal results 40.00% Heodo
2020-07-27Rep-2020_07_27-PI408467.docdoc c2c34b25ee57862cfaad4f1eee4460977129f70b097055b16335b6b811b9e2c8n/a Heodo
2020-07-27Mes 2020_07_27.docdoc 3e46e35eafcbaed6de99b5c2b731a907d06a02d41fcb9e091f4d99d7d2c73bden/a Heodo
2020-07-27mes_2020_07_27.docdoc a88def160248a9f1c1004c02d418deca1f2ebd8f47ef454e401c7a414de4685bn/a Heodo
2020-07-27Dat-0524186.docdoc bfb47d299444268850ba81fe8405b0e67bb464edeafdd2256da8b407c7c631c1n/a Heodo
2020-07-27List L561860.docdoc 78eed1b4f1cfa761cdb70a2f13074b370f5cb7ae6b90d864928b6c378795f4faVirustotal results 35.48% Heodo
2020-07-27INF-20200727-U2764.docdoc a5140b5c967d0a8986302a5b9b69e7d0d57e7e5a555ecd1f3098cad461c9ce59Virustotal results 35.48% Heodo