URLhaus Database

You are currently viewing the URLhaus database entry for http://performanceactive.com/xsell/OCT/6255965737760uwmoylv2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420619
URL: http://performanceactive.com/xsell/OCT/6255965737760uwmoylv2/
URL Status:Offline
Host: performanceactive.com
Date added:2020-07-28 11:06:09 UTC
Last online:2020-08-07 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 11:08:02 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:9 days, 15 hours, 56 minutes Bad (down since 2020-08-07 03:04:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30DOC_4HIA2SGGQBCE1.docdoc 18190f715f0c05ac6e28e0fa78c58fe7a1f6a0733be72ea6494e4340611c2194Virustotal results 40.98%Heodo
2020-07-30INV_YTE_070120_DLN_073020.docdoc 00812e8bf247cc4740941ed973f367678110761be944eef39e69217fc78412cbVirustotal results 41.67%Heodo
2020-07-30Q_IDD2KG1RVVKYD.docdoc fc6275a02a2f5f20f9c833dd916d5180987e67d941c5b7cbd14e09f66e4147d8Virustotal results 40.98% Heodo
2020-07-30R_XG5674622710CH.docdoc beb8b4ce59c55378b8be7421c85d203146858f1b7470942590d417ad208b02a7Virustotal results 40.98% Heodo
2020-07-30F_W8FHJRL3VI.docdoc ede4d3f3f62948285291afc16d31abd1c17c5f9db3ceb0e376151913977749cen/aHeodo
2020-07-3019583111.docdoc 2fa814dd0c5fd6baf41a1dff861eee948734721c6155c4812ca40945d7432a07Virustotal results 40.98%Heodo
2020-07-30BAL_588252549727743.docdoc fd2c870bab01edcb6af885cc070a9ededf595bb1b3613b83fb9313a3caf5e014Virustotal results 40.98% Heodo
2020-07-30RS6500193959DB.docdoc fd052d7b77fd112247dd93e3ff96b40e88c95d0cdc0adb5b81a49e91d5fd754dVirustotal results 46.67% Heodo
2020-07-30XINV_ESG_070120_PES_073020.docdoc 5c46767fc0c57e8f2edbec2b4ec57ea8c1e3b2f070b4a79e786b15f28ceeda11Virustotal results 44.26% Heodo
2020-07-30INV_PO_07302020EX.docdoc bc06aea71e46ed5e64ca7cf24f3b794f46b9371d1df13696a3dfe4096a3bb6acn/a Heodo
2020-07-30REP_APVIA1MA9VXQXOX7.docdoc 13e73da4adc126fa03c4f6e776fd1e257e0f3a50809ad6b9402d9498da8a5ad1Virustotal results 45.00% Heodo
2020-07-30REP_PO_07302020EX.docdoc d643b83d5c405b9ec31fc661b83e10d495518afe7ab286b15c07bccfc7490614Virustotal results 45.00% Heodo
2020-07-30REP_02434039.docdoc 876916b9592c5282a236605b7027f048d30f6b75e47dc12e7d5687f27a3e58e7n/a Heodo
2020-07-29FILE_82852384.docdoc ef354afa479fb3c2a19622cee6c8b67e9b54ff16871ace2f97bf8cf992883da6Virustotal results 43.55% Heodo
2020-07-29JV6276923909EN.docdoc 89b8e39fe7d385d95028dd98f22acbeab0045bf3be2c62108962316db2ec19c6n/a Heodo
2020-07-2961190703.docdoc 67c5a90d4ee5e1cc1015bde3eee2d7e55f0d79c96418c74824260adc38c28ae9Virustotal results 44.26% Heodo
2020-07-29BAL_343340403201751105.docdoc ea1d07ae55467195b610358c91f9d4cb4f280d055e9a86158339ca3bdba8ca15Virustotal results 38.71%Heodo
2020-07-29VAE_070120_YOR_072920.docdoc 85586aed0ec99352b1a7641827523f66047222df673d56eaef2318e8cfe5d325Virustotal results 36.07%Heodo
2020-07-2927280845598.docdoc 9699d65df4c2fe82af8b8dbfe2a0b1165432346f1be0417429b127a7d7346558Virustotal results 36.67% Heodo
2020-07-29BAL_PO_07292020EX.docdoc 38c7641f84de0551bd18ecfaebf19f21d99a1e740b6dad360238b096124e87deVirustotal results 35.48% Heodo
2020-07-2914264732.docdoc bf3fd8c2ed0676122a6ef0ba1e01f28237e3b6f574b59b11d03a75cc5c683248Virustotal results 36.07% Heodo
2020-07-29XFF_070120_MHT_072920.docdoc 018beffb57923eb38dac054bea5fce0c4e9aca87f1971e226c7a7bacad5606b7Virustotal results 36.67% Heodo
2020-07-29NY9431963299NY.docdoc ac9e2f9c90f1ed60a92877da43dca2649167e79de7a185a03fdf6870ae5e771aVirustotal results 33.87%Heodo
2020-07-29E_3020871375003400.docdoc 4a406747cc4af71f72229df7ddbd5c6858984101d67e93ab864273cdff151823n/a Heodo
2020-07-29REP_ZH1757638964WU.docdoc c2ac2bba78f3f27d36a97f527237ad4454b85b03bd0d8a1bd3c47c161c99aa5fn/a Heodo
2020-07-29DOC_13918976.docdoc 9f9215921096d47043aaa2f2bba439f4279458c4a60bc192ff0200ca4ecd1a07Virustotal results 28.33% Heodo
2020-07-29FILE_13030878.docdoc ea0c4bf37a77d48ec55e6fd331d26c6efd0c643194ff2c6919b8f975f0562e7dn/a Heodo
2020-07-29G_952930349.docunknown 35882c33b875d15f1c62d995a525bdbf80355da1abfef138e5b369c5543b2ac9n/a Heodo
2020-07-29W_AX3883679250EN.docdoc d760a46487725541e8c44463c4330d83efb97f55a550e307000db217380797e3Virustotal results 27.87%Heodo
2020-07-29INV_92002974.docdoc de26db90a47a147773f2f26730984929f9a89483907f77015ea5c5a20236183dVirustotal results 27.87% Heodo
2020-07-29INV_37053047.docdoc 3ff753b8bc5e2168abf096605061a3a0791cd60801a9b7b35a89744ea362c197Virustotal results 27.87% Heodo
2020-07-29INV_CFN9M897.docdoc 7492ce7e990e0dc53f8108d30122c4b86311af2b0ed423b25e42e0871fb2f0f2Virustotal results 27.87% Heodo
2020-07-29VBCP_PO_07292020EX.docdoc c973cb08af272436c10c7665181ab3cb5ca566f5ddb70644ca92882b87d2b29bn/a Heodo
2020-07-29Q_OQN_070120_XSF_072920.docdoc 9ab92090f841355a66c7a8807dd706180f5326f0ac8711a80b36953821641740Virustotal results 26.23% Heodo
2020-07-29INV_PO_07292020EX.docdoc 95ddeb5b478660d0b266b024dd44aebd724fed9224811a72568ad27a0d3de832Virustotal results 27.12% Heodo
2020-07-290VF99VRVRW8BPJO2.docdoc 4dbbad92c8a96176270226654745d40e4df036d5e94064fa8784f48fb3124b7cVirustotal results 27.87% Heodo
2020-07-29MT5369145050VD.docdoc a1774a6485655119ea70b0979992d361b648420fb0b003439e52adff57c241baVirustotal results 48.33% Heodo
2020-07-2921061201.docdoc 63b027fb3e70f8211fd1d27de7a473d4a8e4d4f7e19774275ac6a60f8b6e5fcbVirustotal results 50.00% Heodo
2020-07-29DOC_JKMDTQ3KIX.docdoc 9e3690a0a71dc239833dddc5b2aa94983eec61d88a636aa96f12bcfac9898592Virustotal results 41.94% Heodo
2020-07-2949347305.docdoc 8592e77c1c48d939b205ebf81fe0b5903ed8d37d9738f02db0360c37442133ddVirustotal results 40.98% Heodo
2020-07-29PO_07292020EX.docdoc feea2193fa8429572e0d346487c4e58bffd2c6cfc320d05054411a8df5c3e0d3n/a Heodo
2020-07-28Y_16482168.docdoc 3b22de2133662d6bc3110543625e64f9db12f61bd4b994f2042897181b970547Virustotal results 42.62% Heodo
2020-07-28DOC_01036098.docdoc 0f3d19d2092e84e52aa8eec6d932f177849ae15bd1febf920b40e980de9aeb97Virustotal results 40.32% Heodo
2020-07-28ANS_070120_NVX_072820.docdoc 5f8afeaecb819560a5cebd56fc5eeba473f564b4dcc9cbd45858c7f2c372920cVirustotal results 41.94% Heodo
2020-07-28BAL_WTX_070120_SRU_072820.docdoc 271265337665d4b6dcfeba3d1e2acf6de92e94f23c3c82b272dfac52c38fa571Virustotal results 43.33% Heodo
2020-07-28N_PO_07282020EX.docdoc d2cda43e36e25599ff5b2db7bed64985a55b6d99a7238942028a2fcc4acfa3d3Virustotal results 43.33% Heodo
2020-07-28BAL_LPG_070120_DGN_072820.docdoc 9c8f04c408fe3170c3f9d50092fa7bc79b072ac1bfe7c985dd2887d8581242f0n/a Heodo
2020-07-28REP_HTQEAXU6PUM.docdoc 1b9bb9d81eed1ad129c4638a163e37f9053f673136aebb0dca08af3c3460dcf6Virustotal results 40.00%Heodo
2020-07-28REP_36043371.docdoc 2099d5d04c39f86f1da8058861951deb8c6ef875e5a77272709f711e80a3d998n/a Heodo
2020-07-28BAL_DFQ_070120_MNE_072820.docdoc aa5f1c9ba21577549daac728f105950663fa787b94f266a50602a7ba43772e99n/a Heodo
2020-07-28BAL_TT6UY1E609HIS2YQ.docdoc 7880dbee79353af6a070ba20eda972b3ef7abad67d3c309d064ced44676ed6e4n/a Heodo
2020-07-28INV_QZT_070120_VYO_072820.docdoc 88bea3cf547c2635af27e2c05d6b034f48116570cbf09b34b316c4804b53374an/a Heodo