URLhaus Database

You are currently viewing the URLhaus database entry for http://valleyinsurancepro.com/css/zgqvti-o8ihp-797640/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421652
URL: http://valleyinsurancepro.com/css/zgqvti-o8ihp-797640/
URL Status:Offline
Host: valleyinsurancepro.com
Date added:2020-07-29 20:47:04 UTC
Last online:2020-08-10 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 20:48:02 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:11 days, 19 hours, 51 minutes Bad (down since 2020-08-10 16:39:34 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30INVOICE_NF3793{:REGEX:.docdoc 28ad746a87c186873fd8d644a8ca704b9768959c1d8cc780bbd1e4fcec07256cn/aHeodo
2020-07-30INVOICE VH07-94480818.docdoc e039f53c75e931e700cbcafe41ac39dfd4673929f7f2cf333a2f722272fd240fn/a Heodo
2020-07-30INVOICE-DOT6249-8774003.docdoc b881c04d3421fa27957a0aba96dbc228420bb1dc80ed828300fb45848a66447dn/a Heodo
2020-07-30Inv_E47-58226643.docdoc 809ac32f203aef0349016041a30ca0ecbe4529aeea08b872bf48d62a8efa1b3fVirustotal results 45.00% Heodo
2020-07-30invoice-QPK4-24836956.docdoc 72244c8748d1f0b37e10ef8b0f5be0624ea7ac975aa1214281b4f326e6b2f4b2n/a Heodo
2020-07-29Inv-B47-814705.docdoc 9682cb3fed20b168899452201908168de9b2c2d82530d7227a4474b8b2587eb8Virustotal results 43.55%Heodo
2020-07-29Invoice_RH703-319876.docdoc 95a7f27115ec0027c6e80a07bfbe83181bf8cb2236bec3e8b13e7c7e59dcd3f4Virustotal results 45.00% Heodo
2020-07-29INVOICE FMO742 365728178.docdoc bab5c1d78dc95301e33f2feeb7364a84411aed85ded73a18e6c108ee554ffda8n/a Heodo
2020-07-29Inv UZLI071_7856671.docdoc 53bef3fb74db1a15f20b8b64a324c31ae732c3b70c733bf6c838f3eaa10c03adVirustotal results 43.55% Heodo
2020-07-29InvoiceVXI7038-0594059.docdoc 1bf7b884965fe118224269d25022bb33f7a4cd50fee399994fe4c1e7058ade39Virustotal results 35.48% Heodo
2020-07-29invoice465 2027232.docdoc 4e5402409bed2c6052e6cfb0cd998f3b88be85d561edff6ee16212a4df9d844aVirustotal results 34.92% Heodo
2020-07-29invoice_PS5 609923947.docdoc 75c73c21e1d38ea2b779b97ba6e4e5470f12950c2d71f301f96b36e221783d6dVirustotal results 35.48% Heodo
2020-07-29INVOICE-FZH1166-690827217.docdoc 657963516302bff1d416e213c4e427f5db195e90000865aa0b37181d45986f13Virustotal results 36.07% Heodo
2020-07-29invoiceZH3009{:REGEX:.docdoc 99a504a30bece5a880e6faf4431f7bd547a33701313aa16a4a822fc0e33ce09bVirustotal results 36.07% Heodo