URLhaus Database

You are currently viewing the URLhaus database entry for http://grupoleferas.com/twitterAPI/gfdi3fxgt/rnydxd49256662613j1rxnwk1c662ie/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420530
URL: http://grupoleferas.com/twitterAPI/gfdi3fxgt/rnydxd49256662613j1rxnwk1c662ie/
URL Status:Offline
Host: grupoleferas.com
Date added:2020-07-28 08:14:04 UTC
Last online:2020-08-09 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 08:16:02 UTC to abuse{at}arsys[dot]es)
Takedown time:12 days, 13 hours, 35 minutes Bad (down since 2020-08-09 21:51:57 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-3080528107666526573830533.docdoc 44e198d158e76b7f97f737aa5b74de20f159ad7f13b41608d7ef9b793201cb62Virustotal results 40.00%Heodo
2020-07-30INV_40078428.docdoc fd2c870bab01edcb6af885cc070a9ededf595bb1b3613b83fb9313a3caf5e014Virustotal results 40.98% Heodo
2020-07-30DOC_BRUYGWOP1M04O4G.docdoc fd052d7b77fd112247dd93e3ff96b40e88c95d0cdc0adb5b81a49e91d5fd754dVirustotal results 46.67% Heodo
2020-07-30FILE_8TCX5EIJKE1.docdoc 9b9201d1a6812f56bfae2ab23b43743860110bf3e299305d69c02d83577be9dbVirustotal results 46.67% Heodo
2020-07-30FILE_OWJGKRSUMJN6E7E.docdoc 4e037190e0798dbb95a301951d9cefeb18b9f7c0d901052a67f3180236b72bb5Virustotal results 46.67% Heodo
2020-07-30INV_217529756689335.docdoc d834f17cd0c738eb95638a398e34040960ee1780aa6daa9c730d7d0188421681Virustotal results 45.90% Heodo
2020-07-30PO_07302020EX.docdoc 4cdedce9eaa2192b68d57d5362319c339f9efb5bb60d063a11500053b0a6dc2eVirustotal results 45.90% Heodo
2020-07-30INV_SDK_070120_WSE_073020.docdoc a3e3e8da6025ad93ee1a84c515fe80351cc08ea4a60620f29b4cd6cc65b5387fVirustotal results 45.16% Heodo
2020-07-30REP_EZ3753961694VD.docdoc 0f2ecdddfab774804433ce0b9a13b08e5d8ac3af412c34b2aa0c071ac230cab6Virustotal results 46.67% Heodo
2020-07-30DOC_28981673.docdoc e6658dff38b4a88f8d04cdb4f0e14bd6247e293b3249d10e195679438b9c4070n/a Heodo
2020-07-30IYDJ_XY6369449912UU.docdoc 47e3d76a19b9abda5ec59103b5cca5343e385cc0275a9fd5ac33d72783df7414n/a Heodo
2020-07-30BAL_ZH2504280963YG.docdoc 82e33e4bb7107828272e35aa57eed3fd535e57c9a39fbf2a762121b02c80ca61Virustotal results 46.67% Heodo
2020-07-30ZWMP57UKD317Q5Z.docdoc d2bbe6fdd87ccec1a995356886f7e88487d9628bb980b539c4b6302a50b78fb2Virustotal results 45.90% Heodo
2020-07-3054923098.docdoc 1b92a9e2189e1b1570803509487d4403924054cea97919e4055becadf52a9b5an/a Heodo
2020-07-30INV_XKQ_070120_JKV_073020.docdoc 8ef7719b6b5ea2d908bae174825539df09cc69ba74d699bac5a761711183a608n/a Heodo
2020-07-30G_C8DFQ9WOTF.docdoc 57e88b682e4b8606abc312a92312f3527a6490cea9f51480d1c1c3aa449c92f6Virustotal results 46.67% Heodo
2020-07-30PO_07302020EX.docdoc 80606958923e682272638b134b0ceb3f15417c8bc90f086b44646d8c8a025858n/a Heodo
2020-07-30AGX_PO_07302020EX.docdoc 84390b0c62fe199c631eafe739946719ae42dbac314d5e64d66023449ef31d56Virustotal results 45.90% Heodo
2020-07-30INV_3U91XYPUA.docdoc 681cb1e7ae8b40c7324d2bbba75e03f1163ac50a9f758c51dfe08baeb73aa815Virustotal results 46.67% Heodo
2020-07-30PBBDVNI6I.docdoc 9e9555715dda88c203569f25907a61d8bcea375ee2236a6906bd606f33762d12Virustotal results 46.67% Heodo
2020-07-30KU7278478902JM.docdoc 1a1a9791fd0415f23c426b978142a6fb9f414b08fca4a722256b4987ff96bc48n/a Heodo
2020-07-3021200368.docdoc ffcf999bd4956069ace23c70a4cdf979f7dc75fc959dd578b96db3207fdd1ff6Virustotal results 44.26% Heodo
2020-07-30N_UI78QY31.docdoc 0479ae83eb218bd31e04e86eceee6d8e844e3a5875204a95943197b2fe0cadbaVirustotal results 44.26% Heodo
2020-07-30V_32603496537988265376635.docdoc 6bf9fabdb3b728d7e67ec7de8ff0b69b6ab28e2d31d350d560963c706f83ccd7Virustotal results 44.26% Heodo
2020-07-30F_ASI_070120_DQH_073020.docdoc 470ba1b6d2583b2e72b253d2ea565669b79b44cbb0461c99d65f5df9f8028336Virustotal results 44.26% Heodo
2020-07-30REP_TP8184542028YU.docdoc 704af909402caeff30d6ed6d6f47b5f0acb7e12008448c8a043f5a7d2aa08932n/a Heodo
2020-07-30PO_07302020EX.docdoc bc06aea71e46ed5e64ca7cf24f3b794f46b9371d1df13696a3dfe4096a3bb6acn/a Heodo
2020-07-30INV_640453194991518060.docdoc 13e73da4adc126fa03c4f6e776fd1e257e0f3a50809ad6b9402d9498da8a5ad1Virustotal results 45.00% Heodo
2020-07-30P_DL2QUD9ON4.docdoc d3925d4dce34de594b7873b36880de7be2b8cf95a583665c91ab3c660f18d292n/a Heodo
2020-07-30BAL_4O1A4C2OD2QSPWCF.docdoc df0fd9aeb27800d1d055526f68c68130262c8c15596eaa5077cf3a067e810d76n/a Heodo
2020-07-29BAL_ZBH_070120_OOH_073020.docdoc ef354afa479fb3c2a19622cee6c8b67e9b54ff16871ace2f97bf8cf992883da6Virustotal results 43.55% Heodo
2020-07-29BAL_RDN_070120_XFZ_073020.docdoc 89b8e39fe7d385d95028dd98f22acbeab0045bf3be2c62108962316db2ec19c6n/a Heodo
2020-07-29G_DK1999043103HW.docdoc 247650d657b93cdc868b938cf09c549175ede9f04050b49bf731bf4187040030n/a Heodo
2020-07-29MU_PQ4634715338AQ.docdoc a4c0992c92db3e0c5c314930e66582a8544194b5ba6bd3870de21b986ee1ccc3Virustotal results 39.34% Heodo
2020-07-29EAE_GBU_070120_DVH_073020.docdoc 845c967a72f3cc7fe9cdc602e855b0702578f3b8a74cf1b26c3d7443fa3a1a57Virustotal results 35.48%Heodo
2020-07-29QG2929436648NB.docdoc 85586aed0ec99352b1a7641827523f66047222df673d56eaef2318e8cfe5d325Virustotal results 36.07%Heodo
2020-07-29FILE_PO_07292020EX.docdoc a1337b78d948a4c579b396e2c35ae69111e6af596065944b6730552491a80d21Virustotal results 35.48% Heodo
2020-07-29INV_345619077601018.docdoc b3f5fa3ba5a803742303c634ab82d6e1900adec1244c8444f0b632239c2331b9Virustotal results 35.48%Heodo
2020-07-29FILE_31007764.docdoc 509e5ceff7eb6060dcdfecb46ff0cc25302b21a0086e73f472d6a87e5a30b26dVirustotal results 34.43%Heodo
2020-07-29O_6ZNQCVJ2V9.docdoc bf3fd8c2ed0676122a6ef0ba1e01f28237e3b6f574b59b11d03a75cc5c683248Virustotal results 36.07% Heodo
2020-07-2941993561.docdoc cc1c85fbcda8db7e5b287f91d83f2f4acf6235e999339f956e9d592f9e7c59a8n/aHeodo
2020-07-29FILE_72560106.docdoc 61be402d01ef60907ecb10271e98676d6e061ed6ddc0e7d6909589ffd22eef0fVirustotal results 35.00% Heodo
2020-07-29DOC_697989776255402.docdoc 8b275f169b1322d597a80758b3ddb6615af32164dc05ad57329f7469c8ab5fc3n/a Heodo
2020-07-29REP_91491418.docdoc 7cc0e0d42675739a03ee7a45f6f70ba77f5586f1757dca8f793b25daf607f7e5Virustotal results 36.07% Heodo
2020-07-2947472666.docdoc 70772d8a081a64b2b2b197a5420031c3da09118a6906def96284253a85deb963n/a Heodo
2020-07-29KLTX_50811798662933405.docdoc b3ba7eba2631c4a7d69a068f7273be62e8435ef7b8564aeb7270fed27f11981aVirustotal results 34.43% Heodo
2020-07-29CG26UPCOMRCU07VH.docdoc c53e4356e0a876f07a7b63c9c93e8e198f72a37a5dd754cf3f8060369b2ea9f9n/a Heodo
2020-07-29INV_YXED5JST1WHF.docdoc 727f2b57969b68dc6e79c694c096bf3420cc788db33ec0f47193d70ce11fb20fVirustotal results 34.43% Heodo
2020-07-29780237883501364096919.docdoc 79ba06b6a2ed7e51bc791c84bd9a3fc467aac335a7e0ab848243f463a440f0b3Virustotal results 35.00% Heodo
2020-07-29BHO_070120_QQM_072920.docdoc e4d033e0e6be77392f3329a0d3960eec4f96997814442ba8cd17e94866a4d36eVirustotal results 35.00% Heodo
2020-07-29FILE_DZT_070120_LBV_072920.docdoc 6fbae9bccf7687065cab8a4f08d6b3698f4d8224cf72ca4eb10032c0178766adn/a Heodo
2020-07-292LVYJFBQR9TX72.docdoc 2b446f962d60ae78cb353c325d1371e6526cb8315092524b2709b9c2eeae6753n/a Heodo
2020-07-29DOC_IKU_070120_QSJ_072920.docdoc 4a406747cc4af71f72229df7ddbd5c6858984101d67e93ab864273cdff151823n/a Heodo
2020-07-29C_A4EU6C2WZ4U5O3AS.docdoc c2ac2bba78f3f27d36a97f527237ad4454b85b03bd0d8a1bd3c47c161c99aa5fn/a Heodo
2020-07-29041276885.docdoc 551a8dde631d3e53e4ccbec22c88ff151b1ae950686fe687b93d2886a94d841en/a Heodo
2020-07-29NQ2233997463PI.docdoc 9c24d6fd85470958aea67d26f6293c5d8cb091ccac7299fcc6c243ff90382cben/a Heodo
2020-07-29MY_24201173711831.docdoc d32b9efd8f82427e98069b5a06bcde907a9f906406d27e85ff7741cc7d338febn/a Heodo
2020-07-29S_65718432777533378989.docdoc 3681daa87fcd7273080d8c9943be0e8f549075f23e2ceef7e89875649ad5a0efVirustotal results 27.87%Heodo
2020-07-2963209177.docdoc ea0c4bf37a77d48ec55e6fd331d26c6efd0c643194ff2c6919b8f975f0562e7dn/a Heodo
2020-07-29S_99226979.docdoc 35882c33b875d15f1c62d995a525bdbf80355da1abfef138e5b369c5543b2ac9n/a Heodo
2020-07-29INV_PO_07292020EX.docdoc 5a959afcb67ab697d8f53e2e91f7424fb274bee1600360681f6b61c26e377fd7Virustotal results 28.33% Heodo
2020-07-29REP_C9CSVVS8B3X.docdoc 255028b13e1798a9210c65582ec63fe7da4f42e7a9cb9f68ebd049b60ebc6219n/a Heodo
2020-07-29PO_07292020EX.docdoc 9be11fb35c708221d0f4907f606c0ac7320ceeba311812a57038841301e80a63Virustotal results 28.33% Heodo
2020-07-29X_EW8340292398GX.docdoc 88f400fbb72c120c9fa8173bc5f047a5e904164c21372b4164f9149f554d4891n/a Heodo
2020-07-29NG_08969015.docdoc 1257945161cce1eb5a26d2ae6cd6d914e96eb7e505d3f37a281f2d091e2a7a32n/a Heodo
2020-07-29BAL_LHFR25O.docdoc db9b63cdcaff706197aea2e1a576f55006b3513170c106f6e2ee66586482b6f6n/aHeodo
2020-07-29BAL_YJ8024124775ER.docdoc 74135d57c55d6142f0678a1f28259364b24907bd824f953dc77b3ba7f10648e4Virustotal results 28.33% Heodo
2020-07-29IZZ_070120_WFM_072920.docdoc c973cb08af272436c10c7665181ab3cb5ca566f5ddb70644ca92882b87d2b29bn/a Heodo
2020-07-29PO_07292020EX.docdoc d303d07324f08db643e402e98153df70e6eac7c42905dd67d233231438bbe25fVirustotal results 26.67% Heodo
2020-07-29ATI_070120_WMX_072920.docdoc 9ab92090f841355a66c7a8807dd706180f5326f0ac8711a80b36953821641740Virustotal results 26.23% Heodo
2020-07-29FILE_57950408.docdoc 95ddeb5b478660d0b266b024dd44aebd724fed9224811a72568ad27a0d3de832Virustotal results 27.12% Heodo
2020-07-29FILE_64473705.docdoc b3a825ec435cb3188c7e312d426ebb88fc14bf826a552888d2b27110ec074175n/a Heodo
2020-07-29DKT_SDR_070120_WZZ_072920.docdoc a1774a6485655119ea70b0979992d361b648420fb0b003439e52adff57c241baVirustotal results 48.33% Heodo
2020-07-29PO_07292020EX.docdoc 63b027fb3e70f8211fd1d27de7a473d4a8e4d4f7e19774275ac6a60f8b6e5fcbVirustotal results 50.00% Heodo
2020-07-29BAL_MRY_070120_MPC_072920.docdoc 9e3690a0a71dc239833dddc5b2aa94983eec61d88a636aa96f12bcfac9898592Virustotal results 41.94% Heodo
2020-07-29BAL_OMF8QWQ5RDML0VE.docdoc b3ffca228d4d444172e54cbafb591ce0d37193492c7775c7dbf7e8c8e6bc00dcVirustotal results 42.62% Heodo
2020-07-29REP_34777598.docdoc 5ed1399f2abe4abc20390f317598ea019e62a7f410ae2ca299df6b438bee4995Virustotal results 40.32% Heodo
2020-07-2911986646.docdoc 85433bf01e39441b1cc6245f6096bbb9410c45c3a53efaa948c9b2b48a2292b7Virustotal results 41.67% Heodo
2020-07-29DOC_PO_07292020EX.docdoc 2e0013ae11fd80f2fcbd8488a53d6931d5cda77bb542e026cdca5c602ae4c3e1Virustotal results 42.62% Heodo
2020-07-29F_QU6296994158UV.docdoc 6370801cfa9c5207d9891ac6bce41478e5f4d52c83922ec87b94af39195aaf65n/a Heodo
2020-07-29DOC_PQU_070120_ZKM_072920.docdoc 1f19f1cc91f28959e4f1a099b4f6d11a2dfd3b5d5ecf73f596b764dfdc356b57Virustotal results 42.37% Heodo
2020-07-28DOC_98163986156499293258825.docdoc 9e2785a9cb319ef1e1ae50d46ca804ae72583b7910a6c8fcd6bdafc8fd8ce956Virustotal results 40.32% Heodo
2020-07-28Z_PO_07292020EX.docdoc 26c4e8ead2701556bd3d09795db4bb4cd554b40cf9f30b9e76b7434c0e6e96fbn/a Heodo
2020-07-28BAL_US8882547779GG.docdoc 99b2b5aaa43315869607123def2b0263ccfea7ff610adf6c2ea919663ea4303fVirustotal results 40.98% Heodo
2020-07-28BAL_ZQP_070120_FZB_072920.docdoc 32631dfcd1e0a725b4b51420531bfa589d3dcb19269f060e7a7083332d537fa1Virustotal results 40.32% Heodo
2020-07-28F47731U3FE.docdoc c90b4d39e32acc86e0a7e4a43e30283550d82b6d61d3565135fb62a930bc3654n/a Heodo
2020-07-28JK_DXL_070120_XZH_072920.docdoc 942f521ccdd9490b25a14dfdb03ff9e8ff7bce4d9d0ad9c5a5fe684216b81579Virustotal results 43.33% Heodo
2020-07-28K_PO_07292020EX.docdoc c46ea06e842e6d711490963a8e862a721511bb33e041fea939dbcb3ab001203eVirustotal results 40.98% Heodo
2020-07-28Q_6J3P3MY4AUX.docdoc 040eb6591f2ab93e8868b61948d73fe36651ee8af6e4f2ee985708a9ec43126an/a Heodo
2020-07-28BAL_93249749.docdoc 3b37651a73e7c5c4c966ac34a4b38a9e69d7eed9f17e276b8f84f43749cfc70fVirustotal results 40.32% Heodo
2020-07-28REP_224090789069063916168539.docdoc 9ba684d3bb94c46b9c7476bf8ea2ecba98cc9e6975bb465242081e17e69ff0b1Virustotal results 40.32% Heodo
2020-07-28ENN_VIA_070120_RHP_072820.docdoc 5f9b42727ea965d687ec9d1f1e1793d4c35993a10e15ed1e12c30019a64b1003Virustotal results 40.32% Heodo
2020-07-28HSD_070120_WHG_072820.docdoc 0f3d19d2092e84e52aa8eec6d932f177849ae15bd1febf920b40e980de9aeb97Virustotal results 40.32% Heodo
2020-07-28H_865196925776830051622151.docdoc c3c5633aa6844b78f5fd68ab867c7f0ee8c3cb63387b2b497ea29bcc8566a2f6Virustotal results 39.34% Heodo
2020-07-28C_UP6719650604MD.docdoc 5a5a1de568829f744aa5dafeff7301a0cd703b4815e4be3a77f7dfca352438bfn/a Heodo
2020-07-28BAL_PO_07282020EX.docdoc c2dd657c048f69cc272050ec717b2c8d31cb310b02e2fc5bd920783a0cab340aVirustotal results 38.71% Heodo
2020-07-28PO_07282020EX.docdoc af26c866db5ba35031339b3165820e6b21f8dd848ec1bc66c960a8d8de2fc31bn/a Heodo
2020-07-28QZEWQ8NBGFHK.docdoc c0abfc654f0e7e781bed0aaae89924773004af65aa46af36b80189f7368edb64n/a Heodo
2020-07-28REP_11417225.docdoc a6858e9165456c23bb7896862f4d3ec153bee00b02c3b2598e0f8f1cd3cb1b39n/a Heodo
2020-07-28INV_W4ICFNOCHC4W7.docdoc dbe72f10329f82fbca2b2eb70b1e4291bb1ab55d80bd83bd56a7b3a47d12fba2n/a Heodo
2020-07-28FILE_ARP_070120_KXW_072820.docdoc 0a2818ce9bfd7f5eaf2b201eeea0b4e9f4d110587584ed13017b1574324b099fVirustotal results 42.62% Heodo
2020-07-28DOC_LMXLMASVQDX6V4.docdoc e0c8706f01f812beb106bfb124ddad3456dd4e33159910d1c9588ac63e00c2abVirustotal results 42.62% Heodo
2020-07-28BAL_CW9289663003IU.docdoc 9f0ff88a05a5b3cd763f233b4764cb591599142f82dfc63c3f4acf1d9d7997f5Virustotal results 42.62% Heodo
2020-07-28FILE_023064490915939833.docdoc 3ed97b5c98bb43b9d6a5042b5617ddebe018c780836be36dfc96b78865a851deVirustotal results 41.94% Heodo
2020-07-28REP_53855099.docdoc e85502045fec3d9af13567ce4608221f4b92f8b0262e4bae4dd305385079e63bn/a Heodo
2020-07-28FILE_ICI_070120_PGB_072820.docdoc da3bcdea8cc3b33756792fdfa11bdef92dd36e4620ada8b660fc12cc211b4281n/a Heodo
2020-07-28DOC_141469930718750.docdoc d3fde9018a0bc9e76edf0b992ee8af63d938a122dfe68f7ecdb578b27bcec3e7n/a Heodo
2020-07-28INV_HIV_070120_GPV_072820.docdoc 9c8f04c408fe3170c3f9d50092fa7bc79b072ac1bfe7c985dd2887d8581242f0n/a Heodo
2020-07-28DSUWNIGEBDD9X5ZR.docdoc ed68893c9c4a4e3abfcfa85ca077b8d013605d2994fdd6c42b2858cdc2bd30d8n/a Heodo
2020-07-2894K1DZPNU.docdoc 33892c4fb618745a9020642ae7ab40da499637463bad8dfde420034b8f9c92a0n/a Heodo
2020-07-28DOC_MDE_070120_WFI_072820.docdoc 3462186176f663901dcf8db6383a21ecf0995c392966bd5e17f518fb7c0f6961n/a Heodo
2020-07-28BAL_2410164122474317844112473.docdoc 8568762e1933e7b9acb305ef10ceef97fae4501ae0f805ad873393f9459fa229n/a Heodo
2020-07-28INV_89729964.docdoc 6277f4f92177c8a9d172a70df991b4b7d04cff62b0f2e04e78d277d2aa648411Virustotal results 39.34% Heodo
2020-07-28WW9ZODHYH.docdoc dcab281c030ca8ebd833b95d2379df634eec571e1ae19b6aad70ae1a0eb2e07en/aHeodo
2020-07-28WW9ZODHYH.docdoc dcab281c030ca8ebd833b95d2379df634eec571e1ae19b6aad70ae1a0eb2e07en/aHeodo
2020-07-28W_RZR_070120_RUF_072820.docdoc 7880dbee79353af6a070ba20eda972b3ef7abad67d3c309d064ced44676ed6e4n/a Heodo
2020-07-28N_78207321.docdoc 23c51d3c717104427e3ee990c8db28900701083c086707b24493ad7f9968be97n/a Heodo
2020-07-28BAL_MZ2ZWBOXUFW55E.docdoc 69314a5a40529facfde61bb78562869e4ca9a67ba69a3028d376a265e174ea6cn/aHeodo
2020-07-28DOC_75105020.docdoc 2840dbe68611c23040d1bcd78b9473dcd48de959c93280ee78f105b5af51fe75Virustotal results 37.70%Heodo
2020-07-28INV_938461632.docdoc 8b8b2829eec27c2687e1e4dfb190e65d66875564f241e73d6229909a552a510cVirustotal results 40.68% Heodo
2020-07-28INV_WVY_070120_NJN_072820.docdoc 26906041efdeafb6c1754eac8dff97abf079148816f1121ef92bfaed0a6e9991n/aHeodo
2020-07-28I_314690406855741696.docdoc b5ff10eaad0448b933f253da6bfde702a18b8fe967e071e92fc3587fe3e0c4b2Virustotal results 37.10% Heodo
2020-07-28AOV_070120_ZRE_072820.docdoc 4d918759cfed2186f862d40496751ce0b69c70f8fd2d6ea9d0076defd4672dben/a Heodo