URLhaus Database

You are currently viewing the URLhaus database entry for http://vailventures.com/cgi-bin/Document/iwq3rgt2iaj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421927
URL: http://vailventures.com/cgi-bin/Document/iwq3rgt2iaj/
URL Status:Offline
Host: vailventures.com
Date added:2020-07-30 11:54:08 UTC
Last online:2020-07-30 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 11:56:04 UTC to will{at}mediaserve[dot]com)
Takedown time:7 hours, 14 minutes Good (down since 2020-07-30 19:10:25 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30FILE_TKR_070120_YHC_073020.docdoc 3d10e87c65df148b00ee77cac7e5ecc608f2855e1b8f6e1149ca2d8a8dd956e3n/a Heodo
2020-07-30DOC_PO_07302020EX.docdoc ae3abc573956f6ecf54602dabcc2c4c20488c1bd826e4a064e379ffb44b76424Virustotal results 48.33%Heodo
2020-07-30BAL_69994115.docdoc 044a931e427040bddbe572ff16a3bc688cd83e8796727a0df74491157ba7d1f5Virustotal results 47.54% Heodo
2020-07-30REP_PO_07302020EX.docdoc 3ec0cda0966fdfac5059b61d8b718eb7dc9e4454c370aa8260f34a3c759d43c2Virustotal results 48.33%Heodo
2020-07-30PO_07302020EX.docdoc b7c80485c06d98376a33061daffa3a5da0b493251d67b50832d2dff57354ff87n/aHeodo
2020-07-30JFE_070120_MUU_073020.docdoc 07e776c54df1af3395854812f0a6b7915acfa69f07c466e088eab9655d99d886Virustotal results 49.15% Heodo
2020-07-30BAL_Q7ZX0MYFHY5I.docdoc e44fc7d94a825e4d43a775fa247ddca6f4f8593e3605289e79eb4a8210025864Virustotal results 43.33%Heodo
2020-07-30DOC_T1M7CXW96E.docdoc 1460e8d0ac636b3af0e01a282bd5be1286d0b25f0d7f003bb770aad9980dae20n/a Heodo
2020-07-30BAL_35968911.docdoc fc71240699d99fe12f5253034d018233aca29f28291d562f41f75444f6ece914Virustotal results 45.00% Heodo
2020-07-30BAL_4947977021517450347.docdoc fc7484c50c216c229bc56f1a30be53166091175d16fd5c67ee9100e89500aae6Virustotal results 46.67% Heodo
2020-07-30BAL_60142586.docdoc a2d7b4b2a090055111b128e125677d30c87b56ed6a737221b7099b2a611e14ean/a Heodo
2020-07-30GSY_54831853.docdoc 644ecceefd25470a4909b40c0d4c590ef6f5df9613ed3ed3703d2795a21930f3n/a Heodo
2020-07-30A_034392402021.docdoc bc5d38b7165644157ba958af3bdec370f11c8d2d63a5f3c5471b9ee414f11db0n/a Heodo
2020-07-30H_63503199027.docdoc 7d5df463b526686ba6280739c51ad18700d360b4f5d3d43aa53ef82a7b758747n/a Heodo