URLhaus Database

You are currently viewing the URLhaus database entry for http://www.netcorp.ec/js/cv5f543314293u6jcehgyxd60a2b2ey/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422743
URL: http://www.netcorp.ec/js/cv5f543314293u6jcehgyxd60a2b2ey/
URL Status:Offline
Host: www.netcorp.ec
Date added:2020-07-31 09:42:04 UTC
Last online:2020-07-31 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-31 09:44:03 UTC to abuse{at}liquidweb[dot]com)
Takedown time:11 hours, 59 minutes Good (down since 2020-07-31 21:43:16 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31J_16826393182100.docdoc a3667171b7c4b632d7241b65287398007d28c018697677f2bac729d91af17b06n/a Heodo
2020-07-31BAL_BD9158188957DE.docdoc 2426ffe40cd9c239d96c674f7f69a51bd8a3e082fc6d97e71da1c7e7ecd285cbn/a Heodo
2020-07-31BAL_PO_07312020EX.docdoc 7fc8e6e9f781dbcd928e2801941f611c8bbbdc8559983a1f4fddfaa91892074eVirustotal results 47.54% Heodo
2020-07-31FTOT_88982913.docdoc 0bd2032e1ffe665517a03c7cbbea75705c7cf7af00789df956c635d752939ad6Virustotal results 47.54% Heodo
2020-07-31JVMU_15438155.docdoc 3947bd34b6f2fec52a9609289b39a5cc036db860016d3553cf90ca47e3e2c89dn/a Heodo
2020-07-31BU9230475988SF.docdoc 7f9ca2eed49a599b0f3f58c4641986960b01e2ca4fbd9212625d076abd9a665cn/aHeodo
2020-07-31ZXS_070120_UYZ_073120.docdoc 058d1f89179dfcc881c3b5536cb2043d92c25b8dc70c74af1fe9fe6d6f49e75en/a Heodo
2020-07-31ROOU_PO_07312020EX.docdoc 70924fc6c621c4d89c01cf966e0759c7efafb358fdfb087b76ac091cc5cef356n/a Heodo
2020-07-31REP_XQD_070120_EOW_073120.docdoc 4f8d2a942c244360b6b8c311d59352dad83f77899cc7d4094efd99c2e324af8fVirustotal results 49.15% Heodo
2020-07-31FILE_51090213698292218473.docdoc 5858ff6b1b7a2a32a3ea0025bcffc6cb3463458255f2f492a7d4a84f8f5389e0n/aHeodo
2020-07-31REP_PO_07312020EX.docdoc 53b0406efd3043bb9a82034aad1061ca92952b9d1a9111ba31afbc95d47076c6n/a Heodo
2020-07-31LOAH_VWG_070120_PIB_073120.docdoc a4793238143f28a12c3574808fca946d088dacc4570bbb1fd33df193b2185bb3Virustotal results 47.54%Heodo
2020-07-31Y_016575735214623045222506.docdoc 139e9c5ad9d6a1623f98793bb06bda1b4e5da37d9c26de4f314fc2eb5673acbdVirustotal results 46.77% Heodo
2020-07-31INV_658149513362917404169.docdoc 54ba24d383abb977b3b8e9fd0ad9a73735f0953a3c0f89fc0c192e86cb67d45aVirustotal results 47.46% Heodo
2020-07-31FILE_WSDCEAUF0GS.docdoc 55da5c5eb03990c56ace11826deedcc82fe9d5f1a0fa6055575be6d9830f85e2Virustotal results 46.67% Heodo
2020-07-31INV_FWC_070120_GEU_073120.docdoc 1a4bdb64a47146d10bf8594404bcf28b53acfdb7242c989eb3d1c6673a270f86n/a Heodo
2020-07-3184042743.docdoc 070d85940c505f80e563146c1264493f523229d81ef2aff4374669e0cc1769c0n/a Heodo
2020-07-31DOC_VN7498402175FP.docdoc 02652576eb32a3f75e1e91b05db47d2f50fc2069a6bfebb2f2f75fb57b64e919n/a Heodo
2020-07-31BAL_37172662.docdoc 080138d1e0b1b30c9251e6aa2467689804143563243d0fedf4f60f5065e7e1a3Virustotal results 45.76%Heodo
2020-07-31D7IOTUWZXLHZ.docdoc 97a0ba05768ba99119322c6cb79f62bfc92dbfbd64b56b393aa203e7679f5328n/a Heodo
2020-07-31BAL_TUDVZRE.docdoc 628a4059b2b1433fae9cd2e40f5e6c8dc2528d5269c48dfcd20ee92378809e66Virustotal results 43.33% Heodo
2020-07-31J_72407368673380043055475.docdoc 74c79e2ddbba251595996dc010becfe64bde18250a2996d4930d60b6dc688f79Virustotal results 43.33%Heodo
2020-07-31BAL_90425952.docdoc 79c176bbb127e50221aff1d14c8b4f8536dfe567f477e4608a526858824fcd26Virustotal results 43.33% Heodo
2020-07-31BZ_YHG_070120_RLP_073120.docdoc 67eefdc61c4894365a14b80f30a06e1581213946458527b37964761cfae38cd0n/aHeodo
2020-07-31BCR_PO_07312020EX.docdoc 8d3d57f3ae15f3a97337fcd5d624d4e1dabe04c558203f41ea9e93c23928790fn/a Heodo
2020-07-31INV_PO_07312020EX.docdoc fc8260756d35c29ece5bf1f7e3841128d9a81a67341151568d6885a070cd82b6n/aHeodo
2020-07-31DOC_R8RXUWMNRSL21.docdoc db530c8a178fffd02b8fc5c12c0111e002d221f1e0d471639c204ef9357c8b3fn/a Heodo
2020-07-31INV_Y4D09MX6L01RRM.docdoc 9c184a50a28234ea058519a136d7e474a3e8fa0d75828d3b5167ff02cbf87b8fVirustotal results 40.68% Heodo
2020-07-31INV_PO_07312020EX.docdoc 007714caceb91961d8fa30c6f7c1567b7cc1bfbdaa4f9d4d56651ae87f850ed7Virustotal results 42.37% Heodo