URLhaus Database

You are currently viewing the URLhaus database entry for http://www.puertosalsa.cl/js/vd7tdotu-782z1-95/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422317
URL: http://www.puertosalsa.cl/js/vd7tdotu-782z1-95/
URL Status:Offline
Host: www.puertosalsa.cl
Date added:2020-07-30 18:50:22 UTC
Last online:2020-07-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 18:52:15 UTC to abuse{at}godaddy[dot]com,abuse{at}heg-us[dot]com)
Takedown time:1 day, 3 hours, 3 minutes Poor (down since 2020-07-31 21:55:27 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31INVOICE_ISK8502_7923900.docdoc 604d8d4b25d82a9fa60525c21b4f7ff9f0edf0d00aea808ceef6bef8e9e4f4c5Virustotal results 49.18%Heodo
2020-07-31Inv_R29_04990878.docdoc bdca99af8fb2e41f029cbfd5733521eab5744382fc0e38dd79767a27378416e3n/a Heodo
2020-07-31INVOICE-GCYM8-148633235.docdoc 25c12d4806108d86841e67f79d958093ac0ee1b28322cbeaae2e7527322b66f5Virustotal results 46.77%Heodo
2020-07-31INVOICE_NHDX8_65531219.docdoc b2671d67c068a833209094947cc1f15c6169a854e02006f116cd342528850f15Virustotal results 47.54% Heodo
2020-07-31invoice-YNBT3-346253.docdoc 37524ad76f2f5b4eab6611654b6d4db507e547ccf9b0490f0a011d2900f7ceadVirustotal results 47.54% Heodo
2020-07-31Inv_JLTW8056_60222813.docdoc 7d45b681bf88eb9dbaa17bc604d6aa7df3cfc0c3bfaed371a08d5c1805df192cVirustotal results 49.18% Heodo
2020-07-31Inv-WFR43-34734383.docdoc 72b6a8f04525307c44ce8cfe6b0fa344fb42d2273826c3406e7bad305b933afbVirustotal results 47.54% Heodo
2020-07-31InvLCWW237651894.docdoc 7215486425975ce0aa1c7e3e980b1c70b6bde41a872a7b946a2445fd733a3701Virustotal results 46.67% Heodo
2020-07-31invoice-EFG033-5683138.docdoc 955df219d60bd853070b3b3202dffdc5458ac8fed8c076c8c8076baf06348236Virustotal results 46.67% Heodo
2020-07-31invoiceKE3608536.docdoc 2dbecdec1580b1e170e843749f2dee018efd43137a30d5024a6c2ff301b99e7bn/aHeodo
2020-07-31invoiceEPL0427469235181.docdoc 5e3e4c0db013c193ec0fc613f3e0876bd36a6ba53ce477f2b989f8732f645dd7Virustotal results 46.67% Heodo
2020-07-31INVOICE VMQO8 854515042.docdoc 1bbf1c280e0399776065e6c00e7ccc32e3dd3657069cf5d5f27ccda9a1e53d69Virustotal results 46.77% Heodo
2020-07-31invoice W3423 06768191.docdoc 4cb3ccb083a74daebfaa6b646b8294f70cebbba4515d8798b52a41cccde1c7a4Virustotal results 47.46% Heodo
2020-07-31InvFLQS3572706.docdoc 74ea191fd9dd8739f62ffc1cb8d3ba2aad0b198006c5e8aab604e362798cdd45Virustotal results 45.00% Heodo
2020-07-31INVOICEC3779481.docdoc c1750c95a8c4d6fa3ace82fdd29e4da91bc8ae1612124941dec4b06310e9a00dVirustotal results 45.76% Heodo
2020-07-31Inv77516384132.docdoc eb06e5d66d21212c7eb73e44c67b0748a034545ff7a5127eba4ca016692e4786Virustotal results 45.76% Heodo
2020-07-31Inv KHY4 8196894.docdoc a1fceee63605798a0fd7e9384d897c32cf77dde3d5a7de41e6355cdd80cdac28n/a Heodo
2020-07-31Invoice_3400_251313724.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 50.85%Heodo
2020-07-31Inv-CPQD33_76936999.docdoc c7ed06b6f4284ba3fd857f03875187654aad78683efa88d3ed984fe057d484abVirustotal results 50.85% Heodo
2020-07-31Invoice-DQ20 763397615.docdoc c66fa17e4f5d76079707aa28d126feaef92ac1245b1ecb420e7e632e8eeb76a2Virustotal results 50.00% Heodo
2020-07-31Inv-UJP827-75381021.docdoc e3c6519f7b0b581bc58ccec2a76f8bce09e09658d05624ef33b7c5cce0197b6bVirustotal results 50.00% Heodo
2020-07-31InvEL213-614647252.docdoc 9d87ada7dcb70d012d66826ec3f4f26a2f853edce07b15282c119048283a80edVirustotal results 50.00% Heodo
2020-07-31INVOICE-M750 32481970.docdoc cb27bed9b173d425693fe6c19d0d7502d62645a8fff074790841a362952e9936Virustotal results 50.82% Heodo
2020-07-31Invoice-S14-350204.docdoc 1e253d59d5ef3aaf08431b406cd5c024476603459b847f6b40dd0f86827492c1n/a Heodo
2020-07-31Invoice-LW8{:REGEX:.docdoc c8e498b47aef6cfa8fe5259b40faf397127d496992e126c2f4f6026f7945813bVirustotal results 50.00% Heodo
2020-07-31invoice FV09 06552099.docdoc cee085d16cb1dec28ff7ef5bd5399111ba8a5e26623b17902866e886144c228fVirustotal results 50.85% Heodo
2020-07-31invoice-VGE2-792104.docdoc ea4ec66d739ec6c93a0e5890743a01a5283b804889147308ba45d35ee1f2247dn/a Heodo
2020-07-31invoice-E76-321834483.docdoc 2ab3a5f443403e9ed1928d27e4e551ab95a6532d540b98d5103f0ed8a45a75cbVirustotal results 50.00% Heodo
2020-07-31invoice6 62352246.docdoc a766fc0e20a4f8cbf281aef6bb29f7a20a937044d7fd4e008c1097cf266c24beVirustotal results 50.85% Heodo
2020-07-30Inv-Z8478{:REGEX:.docdoc e42656550ed8d746cb8b453d28e1ca374da03e76bdf6b65633f3b1bedd1e051cVirustotal results 50.82% Heodo
2020-07-30INVOICE_P5_408245.docdoc f2e5dfabe9cc22bc5f4995c900e073bcf2219dd18413aa69a7d1148fb6257585n/a Heodo
2020-07-30INVOICE-MNF543-961100.docdoc 2495bd3856b6f88e40d08279462a5689e93d3e698a054cb411f65f84bf189ca8n/a Heodo
2020-07-30invoice 210-799880515.docdoc baef0f6a498331d648f442e8851509d8e91245685e215ae6beb917e8d4a9980cVirustotal results 52.54% Heodo
2020-07-30InvoiceAQK49{:REGEX:.docdoc 1c8026d6bd75a1ea091d6a6676d3a7e3bcba3b17717e21607488b9fdb762fba7Virustotal results 49.18%Heodo
2020-07-30invoice_2251 113206.docdoc eb0c42082f911cdcef8ef582fb3b24067cb2825910839bc6f4b1a4ddf20fbe5bn/a Heodo
2020-07-30invoice-T7{:REGEX:.docdoc c83969e81859c8ba427abffea78663dfe0ea99293074096f42edd85903e45876Virustotal results 48.33% Heodo
2020-07-30invoice-ORYQ7750_8450777.docdoc 73893811ca278a3dd0be7d512b791be9de0331c3fc6c82c42026a4f4cffe2481Virustotal results 47.54% Heodo
2020-07-30invoice_SI9 721654342.docdoc 4bae1b817b5f647d1da6fa839d95dc1a747069f8cb885d0a402df30d268b6b5cVirustotal results 48.33% Heodo
2020-07-30invoiceM511{:REGEX:.docdoc 07a7615f05229feb74b9df0b9ccabcd1b162b654b65824d8662e61fd6ae61c93Virustotal results 47.54% Heodo