URLhaus Database

You are currently viewing the URLhaus database entry for https://blueberrypharma.com/asserts/PTFO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429520
URL: https://blueberrypharma.com/asserts/PTFO/
URL Status:Offline
Host: blueberrypharma.com
Date added:2020-08-11 15:42:08 UTC
Last online:2020-08-12 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-11 15:44:02 UTC to abuse-team{at}dhinatechnologies[dot]co[dot]in)
Takedown time:12 hours, 48 minutes Good (down since 2020-08-12 04:32:11 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12InvoiceB4321863.docdoc 5130c2b92fca78b92aa03684b7110c4e341f9d8ca4e3a20bead042e888e45873Virustotal results 51.67%Heodo
2020-08-12INVOICE-MZM1330-24113930.docdoc c0f86f5a5d4c4ca1e8921cda26e02a082b931bfc17d32900cf54c105cff9a226Virustotal results 51.67%Heodo
2020-08-12INVOICE_X2_1808347.docdoc 0af3f5b45bb78712c8ed836cb9c83c6799e36000f09c7c4ec285f36ad72b336bVirustotal results 52.54%Heodo
2020-08-12Invoice-FT5407-0564012.docdoc 44b8c2c694e595c5c101cd70e1c07cb585b19db23cfd60049e3fe445f6df525dVirustotal results 52.54%Heodo
2020-08-12Inv N3711 1579995.docdoc 6e9b1ad824b0bc35792a2ec92fabb0456af70c654e99e5f6d0067903f3c771ceVirustotal results 52.54%Heodo
2020-08-12INVOICE-HE4-7587701.docdoc 9d49d327fa9d96671e507479a7958bd3d51fd6b28b575f43117cd3796950934cn/a Heodo
2020-08-11invoice-LQ317-553911.docdoc d1ada929c1d864f25ddf89d90029767d6c3b46a1bcd2f20cc967703c3d84bf5bVirustotal results 50.00%Heodo
2020-08-11Inv-ET1137-20888944.docdoc 98891f34f0962ebc73b8be9c5a37aa21ad42fea2d08629bcbf84ff00595fe02cVirustotal results 50.00%Heodo
2020-08-11INVOICE_JUF4_2279562.docdoc 855f271178a061c154a5feed625773d8a02e960340dff7e0e0aedfefd40c2873Virustotal results 50.00%Heodo
2020-08-11Inv IRNN2678 92371544.docdoc 4e7dada550866484045928cef6fdd4d7ccb5d19d79febe490ed7da33d3491b01Virustotal results 50.85%Heodo
2020-08-11Inv-HANK6-830732034.docdoc d15a312fed2ecc7aebdd2c640e30f9f32c1ab015bb92a2605164c281d2bff179n/aHeodo
2020-08-11Inv 09 6053686.docdoc 58fd95e7b27451366d5ea9b0aefeeaa2230636fe086c16bdf49d07824bc70a0eVirustotal results 49.15%Heodo
2020-08-11INVOICE BG90 688201.docdoc b8b0ac3e831b2c1da81ca4dcc7f32ba26a362ccac9c83fb89eda121ef805c395Virustotal results 48.33%Heodo
2020-08-11INVOICE QFT979 7754250.docdoc c427cbb868038c912ba21fe4de92c5dc4dfbdb5395c7ac27c1bd07a2f683fa93n/aHeodo
2020-08-11Invoice-MJK2-93901231.docdoc 50ec0f5012c83993533de48a638157f8879561483c54242f0c74cc2c57ce3917Virustotal results 46.67%Heodo
2020-08-11Invoice_46_068561201.docdoc afae9a58f094ad2820f5d92fbf12b243f4f7db992916f2e6893329b9db28ccc2Virustotal results 45.76%Heodo
2020-08-11invoice-AF9-90973323.docdoc 1cc98c392c0aa7e8ad7669a7b0c7be701ac2fbd93fd030a57f0aed0dc0a1f4fdVirustotal results 38.33%Heodo
2020-08-11invoice 8 8325793.docdoc 800e57c4ad645349b6c44afc8fe14062e1f9ab0b9073ae5b69b17bb231eaf189Virustotal results 37.70%Heodo
2020-08-11Invoice-W3-4618479.docdoc 037ac6663cc663afedeb54cc2424400903cff00417fd70e5ad9b648a50eeae83n/aHeodo
2020-08-11Inv-B027-7787486.docdoc d88d96cc358261f1924dc023ccaef2acc858bd460564cf04b70d80a5569b7c78Virustotal results 39.66%Heodo
2020-08-11Inv_OEO4_905127764.docdoc 81a81cd7bd810ce513cc65228f2046fdaa21f79402d31a76221873894c844982n/aHeodo
2020-08-11invoice_6484_88508868.docdoc 5d6ee55a76b2af864622bf0ad7469af81f6ba3694891a5492fec13a0bd84b2feVirustotal results 36.67%Heodo
2020-08-11INVOICE 53 455135305.docdoc 361883f66d3ba57b06154969450d80a60534d4c926201f523875ecf69bb474f4n/aHeodo
2020-08-11invoice_D73_365959.docdoc 4ea7e2e5423422007c99c5639c31b5e265454505df3f15fa1277c31923799a4fVirustotal results 31.03%Heodo
2020-08-11Invoice_7651_1956333.docdoc 4ed6407bac7a7d0e0122dd585bd1479764cebff3701d3e6bce6f59fd8698378cVirustotal results 31.15%Heodo