URLhaus Database

You are currently viewing the URLhaus database entry for https://weare.academicpositions.com/settingo/Scan/07ezlhjoipe/cqxrgn418603135127806co9wvvwizp5uxh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428065
URL: https://weare.academicpositions.com/settingo/Scan/07ezlhjoipe/cqxrgn418603135127806co9wvvwizp5uxh/
URL Status:Offline
Host: weare.academicpositions.com
Date added:2020-08-10 06:07:03 UTC
Last online:2020-08-10 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-10 06:08:04 UTC to abuse{at}amazonaws[dot]com)
Takedown time:9 hours, 26 minutes Good (down since 2020-08-10 15:34:51 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-10INV_LU9640766905XX.docdoc c82cbe522924e150ea3b677117518f7b51d4a6c084200611e1c73c35790bbfa8Virustotal results 41.67% Heodo
2020-08-10BAL_PO_08102020EX.docdoc edcc83eab42c8192a4daa83887285b3884aacec4e95a3f6a17e6b2e3ff40213eVirustotal results 34.43%Heodo
2020-08-10R_F79QFVLR11SYB1ML.docdoc bffce2e81a5c862490f9840a6eb2bcbdb5408bb297c5b8ccd57e04ea748f52efVirustotal results 27.42% Heodo
2020-08-10DOC_865510766369493330.docdoc dc5077277cfc327ea738f49f77b8ccc791a515634d299c2c0467c065eeca0d6bVirustotal results 26.23% Heodo
2020-08-10FILE_61711829.docdoc ccad7d8f297ecf97b8a2c961ea884e9fd3acde7d74213ba337f42bc8213f2965Virustotal results 27.87% Heodo
2020-08-10BAL_PO_08102020EX.docdoc 6be0d7b3de87cd34b500d16c52771c2f1058f7a9bc2185e7f757cc577419bc00n/a Heodo
2020-08-10Q_IXN0XW4.docdoc 846b67e88f29532f189e40a06de450fc6ae72516036c4cd9eed994ccaf51cfe4Virustotal results 22.95% Heodo
2020-08-10BAL_177751810228.docdoc ded05047906c77def61e260daae814f798bbc9e65399e99e6f985cf40802c06eVirustotal results 22.95% Heodo
2020-08-10BAL_2256525389429989.docdoc c7d8eee1bdb3e6476c9c65b86e49846b3cda22d4a078d223865a4da6b91f4186Virustotal results 22.03% Heodo
2020-08-10DOC_IEVJB84RGYLMNN.docdoc 0a8097112177cfa820edfa3b635f0e1099a3f7d916421e4d1f3410a25ce69c1cVirustotal results 22.95% Heodo
2020-08-10BAL_PX9485262882UJ.docdoc 3612453260283d4dfd0cbb88043fadeb880c7ebc9f4b5ef998a54aae31c89588Virustotal results 25.00% Heodo
2020-08-10FILE_291697678738.docdoc e1bf56fc0155d8a4fbbc227cf25bea3f74319628291a5c6f4ea86f482d80a275Virustotal results 24.59% Heodo
2020-08-10INV_S35MMDOSXZTHL01N.docdoc 49c2fa38189bce1866896feb04b6115472120d26fb4ede00cac18b93aa45bc40Virustotal results 24.59% Heodo
2020-08-10BAL_60108457.docdoc 2c9a9c2e22ceb4a274c3377576aaa704c7475d969169c29740745b9b0966dc9bVirustotal results 25.00% Heodo