URLhaus Database

You are currently viewing the URLhaus database entry for http://exfil.us/ww12/closed-sector/individual-space/y4zmfrd5ggi7vies-u1s8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428479
URL: http://exfil.us/ww12/closed-sector/individual-space/y4zmfrd5ggi7vies-u1s8/
URL Status:Offline
Host: exfil.us
Date added:2020-08-10 16:36:15 UTC
Last online:2020-08-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-10 16:38:04 UTC to abuse{at}privatesystems[dot]net)
Takedown time:14 hours, 58 minutes Good (down since 2020-08-11 07:36:12 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-11file 2020_08_11 XMT533567.docdoc c63d69fb1a335468a6aeebc2b8af051bf71cb55b4808a17409b332fc70728b8cVirustotal results 44.26%Heodo
2020-08-11File 20200811 0032784.docdoc 9cc9ffc477277e4e3f239e9614780f61763818b20a39f9bbdd64fc1b3239b42aVirustotal results 43.55%Heodo
2020-08-11INF_2020_08_11.docdoc 493101a81b243bc896303e65c73263b1664d1887fd631666fbf895c875db3dccVirustotal results 43.55% Heodo
2020-08-11INF_69106.docdoc e4790d41e27c6978baf5ccf9461b74b1e9606fdc7edcb4d2022edafc3d8a6fd6Virustotal results 41.38% Heodo
2020-08-11File_69730.docdoc 13c77da9bbdaea66303dfe4cfcb8b5a9f8eae8d46f1e710ab6574c73b2c1d91eVirustotal results 44.07%Heodo
2020-08-11ARC-20200811-OMG44659.docdoc ce70fba1cd6c71bfbc91162f8e5d6f99e03ffba2db898e1088139f06cef9c304Virustotal results 44.26% Heodo
2020-08-11Arc CP568104.docdoc bda55acb649535e7d61133cf076b1604f3da829aa4d7b45a7bf3ba27466d9c3aVirustotal results 45.76% Heodo
2020-08-10INF 7178637.docdoc 1ff50f088800028624af3ad83890529e6cd409d4c797d27b35f77e33fe36793eVirustotal results 40.00% Heodo
2020-08-10Inf.docdoc a685d179f34dc5fcb9fdb968d93826a1931f9e729bd7fa6491dc6cacf4ca0c68Virustotal results 40.00% Heodo
2020-08-10Rep 2020_08_11 WZ845916.docdoc 230cc48c70942780ddd2cc9327ac6c9b96bd8c1272c1ad0ccde75cced629204aVirustotal results 40.98% Heodo
2020-08-10INF-2020_08_11-U882296.docdoc ab0306c2455e32e50062bce1ae1e34c69f5b6b90faf1e02827ea1333ef8d6df2Virustotal results 40.98% Heodo
2020-08-10inf EZV737.docdoc d1995ed56b0d8d1b1696cf696e047d70dd9f86f9ba8dfeb1903fa84aa82f3e94Virustotal results 41.67% Heodo
2020-08-10file_2020_08_11_QKI44293.docdoc 3b59369e3166425caaacc1f0c00428539ecec010f83337e7af44a660bc6c7735Virustotal results 40.00% Heodo
2020-08-10DAT-57362.docdoc 8bac60fe9c581db6206a5ca49fc3fc76df934a47006c8effcd145a6ab3c70cc8Virustotal results 40.98% Heodo
2020-08-10Doc-2020_08_11-Y7328.docdoc 69a6b1c09608f190a59315faa99814cad90c3eda1f938f379415adb9ce80d7fdVirustotal results 40.68% Heodo
2020-08-10FILE 44505.docdoc 3708962d8333f33b8ca2229ccdf932d5f06c2e380b5634afb33c2b29e209e269Virustotal results 41.67% Heodo
2020-08-10File 2020_08_11 0084.docdoc 8f9e5cbc1eaf541061e1c1fd545d23d12c9af3e75781e353cb46b9de8dfd728eVirustotal results 41.67% Heodo
2020-08-10mes_2020_08_11.docdoc 6fdba2a3c021e527cc4d508e143f075fee286280cbb58cc759f2c7968248b1c6Virustotal results 41.67% Heodo
2020-08-10INF-20200811.docdoc 47c81bf4ef434b2d8dcc344dd6d8bb166138e0df39808d51dc12f319eb134129n/a Heodo
2020-08-10arc_2020_08_10_84472.docdoc b07e6b18d82a1b8730658e479cec7e7a91bd8f23f429e34de9f652065da22b4dn/a Heodo
2020-08-10list-20200810-C2166.docdoc b5184411717b5186e80a521f6b70c47091f21c4e9c586d2f565438dfaba70d7dn/a Heodo
2020-08-10file-20200810.docdoc 21d305c97502379abad7f15c44454ff18239806f9839d1e72f83028893df2fa4Virustotal results 41.67% Heodo
2020-08-10Arc_2020_08_10_0818673.docdoc 6d218e558b2cf4b5f4564d9bbfe8feb68602b363228a53f9c7e7aba48ae19d1dVirustotal results 41.67% Heodo
2020-08-10DAT-08871.docdoc 098876500a634aa472d3871b18a4ad318ee13f16787cd4abc0f17172bd7a9b6bVirustotal results 41.94% Heodo
2020-08-10Doc 2020_08_10 OJ0178.docdoc a183ad4b8a0e9fb7dca68946fd71e2382b7d6818ea27d5aeeee1eccb0c15ede7Virustotal results 44.83% Heodo
2020-08-10LIST 2020_08_10 274224.docdoc 5f408255186026aae91da7dac783ae1d17a15678a5a433632286887f07555709n/a Heodo
2020-08-10mes 2020_08_10 VP80499.docdoc 3ba827fdccdc439eb5e92985a6ce5abda57ef7ba59f302f21602034b51e817f9n/a Heodo
2020-08-10inf.docdoc 03c3b83396d5866a19b8173b63e93341e1fb76a16e082ec63d43b8db44d2b9beVirustotal results 40.32% Heodo