URLhaus Database

You are currently viewing the URLhaus database entry for http://bestangeltravel.com/css/invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420131
URL: http://bestangeltravel.com/css/invoice/
URL Status:Offline
Host: bestangeltravel.com
Date added:2020-07-27 20:02:35 UTC
Last online:2020-07-28 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-27 20:04:04 UTC to abuse{at}hivelocity[dot]net)
Takedown time:22 hours, 16 minutes Good (down since 2020-07-28 18:20:45 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-28FILE_O3AE42V7UTMVLY.docdoc 271265337665d4b6dcfeba3d1e2acf6de92e94f23c3c82b272dfac52c38fa571Virustotal results 43.33% Heodo
2020-07-28BAL_7587588446521486791082866.docdoc d487cc38c856d2cb27368dde0ffc7fcd18f4c32ad9e19e44422e98d3e36d3e58n/a Heodo
2020-07-28FILE_PO_07282020EX.docdoc aee8c34f1c430fedfc697089732e0d51939863f4253fb7455be1773ffea8de0bVirustotal results 42.62% Heodo
2020-07-2820298864.docdoc 0a2818ce9bfd7f5eaf2b201eeea0b4e9f4d110587584ed13017b1574324b099fVirustotal results 42.62% Heodo
2020-07-28P_93725604.docdoc 6e6b40f219ab4a11fdc4001a81f2d72c968ccd1022f998524375b9b943bafb0dVirustotal results 44.26% Heodo
2020-07-28EB0312393854MO.docdoc 181a733145822f0c1256bd24fd8e19ff7f1217f6166e56dafb7075bf6fc54a06Virustotal results 42.62% Heodo
2020-07-28FILE_35591659.docdoc cfe67567737aa3c2dcdec28c0d6873e5e340c8ad049faa917c527f54e1c1875dn/a Heodo
2020-07-280735918158169509308899.docdoc e85502045fec3d9af13567ce4608221f4b92f8b0262e4bae4dd305385079e63bn/a Heodo
2020-07-28INV_PO_07282020EX.docdoc da3bcdea8cc3b33756792fdfa11bdef92dd36e4620ada8b660fc12cc211b4281Virustotal results 39.34% Heodo
2020-07-28Z_PO_07282020EX.docdoc 3ede822580b26357e4126b461a884666c12bb750fc30415502dfc452f5b04c30Virustotal results 39.34% Heodo
2020-07-28BAL_98414044.docdoc 8d27e36fe079fffb278a007a07dbcbfb37ae765b71bcefb8e0e41c4a70101512Virustotal results 40.00% Heodo
2020-07-28PO_07282020EX.docdoc ed68893c9c4a4e3abfcfa85ca077b8d013605d2994fdd6c42b2858cdc2bd30d8n/a Heodo
2020-07-28628968140800.docdoc d9e1b8b8313a688c0096c914d0cc62aed82170a3e85263d69ef058de2d978b15n/a Heodo
2020-07-2896354346.docdoc 78343bb65eecfad5b62d2de0e25b21a708b837293f90cfd6b1bdd8e8cb7d8014n/a Heodo
2020-07-28557139003572113.docdoc 878399ac6fca1894c7e9acc48eddb6a535513a4fc7b0b8aa410b19c0f85cf361Virustotal results 38.71% Heodo
2020-07-28AM_PO_07282020EX.docdoc 2099d5d04c39f86f1da8058861951deb8c6ef875e5a77272709f711e80a3d998n/a Heodo
2020-07-2843037553.docdoc aa5f1c9ba21577549daac728f105950663fa787b94f266a50602a7ba43772e99n/a Heodo
2020-07-2897554940706945617.docdoc c42f2ac06fe469689cc7d39407bbd26f418223213b99e1c4178bab4735bb7e9cVirustotal results 39.34%Heodo
2020-07-28INV_MP7618588268GZ.docdoc 4fdb97a98c47101b9d2c0308f3c3a9d4fd53c97fd7a0d7937ee3f292c51f8757n/a Heodo
2020-07-28BAL_J61GA0MO700.docdoc d831fb7e6ca7099b615f50a60fca9d58ca6307bb95d592dfdd1c793b267f7f86Virustotal results 39.34%Heodo
2020-07-28XA4167630527OO.docdoc 0908f65f4fc6bbc55135748a1dc9f8120e504195f01caefafb80e6d7639f32c8Virustotal results 39.34%Heodo
2020-07-28REP_II5395895671XX.docdoc 8a02a02bf39b80d809da634fe105c29a2b012acfa59c4eaedd94360fb5fbd2e3n/aHeodo
2020-07-28REP_GCD_070120_QYV_072820.docdoc 26906041efdeafb6c1754eac8dff97abf079148816f1121ef92bfaed0a6e9991Virustotal results 38.71%Heodo
2020-07-28BAL_VCG_070120_USS_072820.docdoc cd8165b730d0801f2eb1524b1a430abe1d69e7105b2a898fbcca440afafd8f01n/a Heodo
2020-07-28INV_PO_07282020EX.docdoc ba613571c6d4657eb92bf9852164f5e774f458def985b842e8594704632bb9e4Virustotal results 38.33% Heodo
2020-07-28UW_08545023.docdoc d0b863f7a0a3856c5bdb5e1d6d5b4f641d64f352e54d54080c23025a30a0b5c3Virustotal results 37.70% Heodo
2020-07-28FILE_9GO3UQ70LVF.docdoc fa0ce8c142463b37579d0d5a4fbb8da9dde5081ce2d5ffe0303872a533e7e190Virustotal results 37.70%Heodo
2020-07-2811931674.docdoc dc7c90dcb5ec12e5b8f816048d2843dcc7c972ca78b9e48578a917666e7a2845n/a Heodo
2020-07-28R_MY2436385235CH.docdoc 20d81ffc64ba89a114dc4ee30c643d555945ab0ec0f3a17c96b56d6087ef3b13Virustotal results 42.62%Heodo
2020-07-28BAL_PO_07282020EX.docdoc 3bd36ab32026af0a6cb457a12a0ba75df13d8e6a288da64ca838af0bef9c2e24Virustotal results 44.07% Heodo
2020-07-28FILE_WUHYTYYNPZ5338.docdoc feb69e5e064dc9aed0fb86311321af444f6296260687339fcceb53d31201a026n/a Heodo
2020-07-28PO_07282020EX.docdoc 1e687ad756dada51e71738e9b4af3eedc481d865f7df0bd32500ea50bd16233aVirustotal results 42.62% Heodo
2020-07-28PO_07282020EX.docdoc 388d49d105196dea02e96ac0172560dff1d9862e5b8910e7af963585439dbde3n/a Heodo
2020-07-28DOC_73740316845169344251.docdoc 2b2dc53af6714037713433698dae9be164fc7c66c23377ec620a17a4130bf425n/a Heodo
2020-07-28FILE_PO_07282020EX.docdoc 29c42aa5892fede943d2975f64abfccbcc8cfa164a85e278753f970a17d010den/a Heodo
2020-07-28PO_07282020EX.docdoc 6f725b4e11df45b38cea3502301ee5e92df17109fa860dc84523501a6940f5d6n/a Heodo
2020-07-28DOC_PO_07282020EX.docdoc 2b4263841c81074211dd59e820bf05562e5c59be8d38bf8791a0a21753cdf504n/a Heodo
2020-07-2761074241.docdoc dd1fe9f11a267149ce356a768d071605c1972fd10d1f7a57a29fe8a2c8fb41c1Virustotal results 41.94% Heodo
2020-07-27PO_07282020EX.docdoc 3e21349ba3bf686515975146afcebe14651b2304ec58b47bea6b87b5fbc79a69n/a Heodo
2020-07-2747401066419136.docdoc 3a4fd8ba092ea2243de196e6a43f4568bc13d88e3c04ed3aaba6e494b4ec47ffn/a Heodo
2020-07-27REP_PO_07282020EX.docdoc d88b494734b0a01b33a3095214b8f76b448f625fa97248e6d6385ed6a1edc35en/a Heodo
2020-07-2750129610.docdoc 2ae67471c658ada5648053a5da6b55d64bb0f6de4ee16ebfcbc335055b398f1bn/a Heodo
2020-07-27DOC_5LED7YN6TTMGC2.docdoc df3f07a28988e65741321c968afd02eaf8a49fa2dcf2e2f2685d04e13a236122Virustotal results 43.33% Heodo
2020-07-27S_JAD_070120_BTZ_072720.docdoc e014e7351a4ad87f016b72570a6ea61c63069ef368ef1501bf75c019760740d7Virustotal results 41.67% Heodo
2020-07-27INV_PO_07272020EX.docdoc 5d08f7fb64c5fc4af654eed617b862ed33cd458b34326c027882d886627f96d0Virustotal results 40.32% Heodo
2020-07-27PO_07272020EX.docdoc 8b45eedf831a892ec3c09d8c866f1d771b5910bf44de36ce99157d6dcaf56eden/a Heodo
2020-07-27PO_07272020EX.docdoc 2317a555c5aabac7a3b94757661b5ca7f25d7612b4c4a93df00b35fa56fd8e9en/a Heodo