URLhaus Database

You are currently viewing the URLhaus database entry for http://www.logisafe.com.mx/cgi-bin/9100092/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421527
URL: http://www.logisafe.com.mx/cgi-bin/9100092/
URL Status:Offline
Host: www.logisafe.com.mx
Date added:2020-07-29 16:06:10 UTC
Last online:2020-07-29 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 16:08:03 UTC to abuse{at}tierpoint[dot]com)
Takedown time:3 hours, 18 minutes Good (down since 2020-07-29 19:26:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29INV_PO_07292020EX.docdoc e4618abf1620fcddaecb726dd2a7f7a095ca8fd8c270dfe8effd35c7f00f60d4Virustotal results 35.48% Heodo
2020-07-29NR1342300257NH.docdoc 8b275f169b1322d597a80758b3ddb6615af32164dc05ad57329f7469c8ab5fc3n/a Heodo
2020-07-29FILE_PE9619295543XH.docdoc 8b42f6a2ccbca956108f22e24f59b1127a7d7057bab7556c236516226d237f51Virustotal results 35.48% Heodo
2020-07-29FILE_96176041.docdoc ba13cd41af84d25db1b459d45732b2bd8ced1e2c3a6862b98ca913a329ac7981Virustotal results 33.87% Heodo
2020-07-29L_TKA_070120_NIQ_072920.docdoc eab8382b9becd262d347b0fac413cb0096a14d277206285af5e5ddfb459cec40n/a Heodo
2020-07-29IDHS_62412808.docdoc 5913cb2a13acc0ebd04f43f136ca3952f406663bbd982b2a5931991565aeef5cn/a Heodo
2020-07-29BAL_NQABZ9JYFFQP8.docdoc 3c7d9c79df98350453b9af83b1cb8a10f106701f13470785a485ac4d9a1744c5n/aHeodo
2020-07-29JAJ_070120_RQC_072920.docdoc 79ba06b6a2ed7e51bc791c84bd9a3fc467aac335a7e0ab848243f463a440f0b3Virustotal results 35.00% Heodo
2020-07-29PO_07292020EX.docdoc 75706826f0770002fd4702dc49371a0bc2164857deb80a9059cc97a65cc1e9deVirustotal results 35.59%Heodo
2020-07-29G_CD5416560304PC.docdoc 09b48077de19d52dfbc9b6d2c88ca02edd8faef66106d41aa7e6ce017667ae50n/aHeodo
2020-07-29BAL_PO_07292020EX.docdoc 2542dfb913b53805e11eab09a1277eddf7c8ebbabd1d8c1495c44d85ed49d010Virustotal results 35.00%Heodo