URLhaus Database

You are currently viewing the URLhaus database entry for http://hercinovic.com/Scripts/LLC/ombz68l4z54j/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:430458
URL: http://hercinovic.com/Scripts/LLC/ombz68l4z54j/
URL Status:Offline
Host: hercinovic.com
Date added:2020-08-12 14:11:22 UTC
Last online:2020-08-14 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 14:12:05 UTC to abuse{at}inleed[dot]se)
Takedown time:1 day, 20 hours, 58 minutes Poor (down since 2020-08-14 11:10:54 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14DOC_PO_08142020EX.docdoc fa4a4908d530908c1e687ff784931d3e57af14fe24494b625e45f1f0387a8528Virustotal results 35.59%Heodo
2020-08-14DOC_PO_08142020EX.docdoc 8c1068585407f5f88829c4f57a246305ddd51450ef74893d81cc738604e9cb3eVirustotal results 36.07%Heodo
2020-08-14FILE_ZN9777975630XP.docdoc 0928f7c9c557d9e232052edc5377f9986651f02861f1f90ae67a9bcdf3caa375Virustotal results 36.67%Heodo
2020-08-14EXZD_YLG_080120_IHE_081420.docdoc ac72c66d611118545906b5f23ba3aa32a7dcf91eb2f2f41c1476afea66ad21faVirustotal results 36.84%Heodo
2020-08-14REP_53282913.docdoc e738788216e4f42219fe764c10b970a6d5d4ab6ce811744bbdc9aaf9bff2dd2cVirustotal results 36.21%Heodo
2020-08-14DOC_30685227883691025384553.docdoc 6ab2c399c8174e97809e728dc331f229df5e7d30dba04a5b1658ff245c45a657Virustotal results 35.59%Heodo
2020-08-14BAL_WMC2CBT.docdoc 1caf3b81363b58c02feb6ae2c0ccb617e3ed49bc8a03b4f3de7243dfe6451fdeVirustotal results 35.00%Heodo
2020-08-14F4ER8BWIJLV.docdoc 28bc4f423b833b0fadccb2de2327be63041318014cf1ae1e1dc1941010322f53Virustotal results 35.59%Heodo
2020-08-14INV_6482094305.docdoc d4fade764b1ae03f546843ff7b67176a1d7fca0c1cad66455d0770c364b5746eVirustotal results 36.67%Heodo
2020-08-13COI_080120_KJL_081420.docdoc ae61420aebc07da884917752dcdac62809ccd7a3eb2ed470a3b6c810e7635adfn/aHeodo
2020-08-1307283683.docdoc 668487ec145e75676c1a4fd6e0828331c412f7fe35709a3deb6d182debad6422Virustotal results 37.70%Heodo
2020-08-13DOC_611793192984861.docdoc 71e77ff8358d9754ad9a0f3c14c25781dc744be7a30920dde527364cf1ef18c3Virustotal results 36.67% Heodo
2020-08-13BAL_SR8073959828AZ.docdoc 34aed4bb09915606f5373f0d72261b384fe3d85fcde9b3c716ac00967158ec77n/a Heodo
2020-08-13INV_07248877.docdoc a54d64f137fed12ad381046f13c34ed6e31b194d4574870aecea8be459a49382Virustotal results 37.29%Heodo
2020-08-13BAL_PO_08132020EX.docdoc 40fa25d14444c5f0471cb5e33a8397ec008ad42615aefa558366173602afc62bVirustotal results 38.33%Heodo
2020-08-13BAL_RZJ_080120_OLD_081320.docdoc 0f56c76a4c47767ff9ff3f8a9fdc37edabf5d585992ab218eec6d39627dee63dn/aHeodo
2020-08-13BAL_BJVC4UY3FI.docdoc 9be561c7cf40dc53dbba36e51b0787a5dfb2c43000b0c5915df93ec5ef170687n/aHeodo
2020-08-13PO_08132020EX.docdoc 24a1e2e987d8b20088d57c9e0a758e8f43db7b3709aa02f6bff770e590e36624Virustotal results 37.29%Heodo
2020-08-13REP_KS0643759375NH.docdoc f153d1cd2401db480ab764a78b8a1928c558755e34f37ecc8ece84b1f14e6964Virustotal results 36.67%Heodo
2020-08-1315742166023514504520475.docdoc 92b38ca67d00bffc28647167730cef8ea6123542c4123464f1c565e59186b871n/aHeodo
2020-08-13Q_YU3572693684RK.docdoc 3f54dbc7d7efc9342ac4ae143a7e38bb8d4138d9106817ab2f5ae7ac6b95f277Virustotal results 36.07%Heodo
2020-08-13INV_8DJ9FBWQDQU.docdoc 75b72728b4e1d6de964271f76b8536a1a62dba26552d07436aef8f183e57b267Virustotal results 36.07%Heodo
2020-08-13DOC_GQEHII9K1O.docdoc f959a3ec8067a6967f047b19554210234638a6ac9b0bac85e006979f09c33d11n/aHeodo
2020-08-13C_97491072.docdoc 787b6d7c7eccdccf7041ef2028eebf0f8eb9691e1fc1561c6a6c13985156b1a7Virustotal results 32.79%Heodo
2020-08-13YD_73279963.docdoc bccd7607de30c4481db2b724437ae78b0d1248b1b7bd563add97f212194b4fd3n/aHeodo
2020-08-13BAL_D6C4N1A.docdoc e075507a16b93d21aa9bf0848bd5299ef87fe338654ca4e30075fb8677475c50Virustotal results 31.67%Heodo
2020-08-13XX_96667217.docdoc 5dfe99bdd766418f029d534146438a97818581f989d4b2ebf5f92179344000c0Virustotal results 30.00%Heodo
2020-08-13PO_08132020EX.docdoc 379e94fbd1ac9a1b6ee5207057f464db427f71873639ce917f88a309dc68cc29Virustotal results 28.33%Heodo
2020-08-13053054673.docdoc cc1a7efdcb7e41f40365042a5f31c2338804f4bacce2f64fec0ef2fcc3dd2f96Virustotal results 28.81%Heodo
2020-08-13DOC_51604628.docdoc 34cdb3854071dc86030fc69f90094d0ecc4064d54c2f6c5c2ccea449991908bbn/aHeodo
2020-08-13JY8870659869HR.docdoc 4a62d3729df93b38995a6be4a79fd8785c7591f0230b355532afcc18f823ab7aVirustotal results 27.87%Heodo
2020-08-13ESR_02028836.docdoc bd7871f1fceddc02727f3be310e4507aa75ac650a9319a03989d0a1c18bc74cdn/aHeodo
2020-08-13REP_JY1831039750QJ.docdoc 415f12593d783f3724a45d8024d5e50439644e8cb0e91457f529e45114cb9129Virustotal results 30.00%Heodo
2020-08-13BAL_UR3293961746UU.docdoc 04539e7fb7b3fbb0503d6a986c26dc4b34f5de6dc36ca7b96859bb2bda495f2cVirustotal results 29.51%Heodo
2020-08-13REP_23429012.docdoc 03ef971ad58eedda8a6ca86a77257b4214bf5f6d8725c319241d8d25cb255991Virustotal results 28.33%Heodo
2020-08-13J_BH9900662250AW.docdoc ee5d444d2829e2f9cfc90756f94149f85514b3766615fd081b722c6587c331d8Virustotal results 28.33%Heodo
2020-08-13PO_08132020EX.docdoc 52426d2c2644ab78cd7fbe3a9e0d19acbd34903d9f62d42fe2e999b964e3eea7Virustotal results 29.31%Heodo
2020-08-13REP_647259964539747987.docdoc 25098bc6669e16e80698b99b3d8cbf99d9ed025c13d1ba59f4e90e906ec106c0Virustotal results 28.33%Heodo
2020-08-13TH1339990761YR.docdoc fdf714d8a02549739b60c414ff535944cd2b7d8a84e465b55f4fa263680e9cbeVirustotal results 26.67%Heodo
2020-08-13REP_AR0255606068OH.docdoc b1f8d98523bd93f24f930e85c58bf2dbacd41064303731e4dec0fed008fc3080Virustotal results 26.67%Heodo
2020-08-13Q_VQ2296336651PM.docdoc 0652c184cccfd772644a2b72467b93f57ee93b1095894cc08ab3a9d9470fbac9Virustotal results 26.67%Heodo
2020-08-13Q_VQ2296336651PM.docdoc 0652c184cccfd772644a2b72467b93f57ee93b1095894cc08ab3a9d9470fbac9Virustotal results 26.67%Heodo
2020-08-13LGR_080120_MBU_081320.docdoc e303bd587f94e0cc2bee4cd31594d807f186aa22f04da0615deaa6c27863e72aVirustotal results 28.81%Heodo
2020-08-13BAL_17707813.docdoc 1ac4188f22c717e76b493881ab12ef60e719cb86d2e5289f743b42b338cb5b96Virustotal results 27.12%Heodo
2020-08-13KJQ_VS3018366908GG.docdoc bad77bb86f43d26aeeddd264c08f21e690be629f116fd2659556e12485195610Virustotal results 26.67%Heodo
2020-08-13BAL_04813284.docdoc fdd5654b78c6c5c23b4f6c6502eb69701c87c65ad4bd2d121046db883154d863Virustotal results 27.12%Heodo
2020-08-13G_QZ7259456884MN.docdoc ba510b5a0f97430a09efbd12acbb4c1be869e71e678adf5fa0b5498fb477068eVirustotal results 28.33%Heodo
2020-08-13EA_WDD_080120_CTG_081320.docdoc 286553ae57a160d6c96aead277a25d92227a3f0030fb98198e7be863f897e1deVirustotal results 52.46%Heodo
2020-08-13DOC_9YJA32BSDX5YSGH.docdoc d3cbf8eb26742271a0281233827b52ab52334bef5335d0f8a27c9db613de55c7Virustotal results 53.33%Heodo
2020-08-1314000962.docdoc 0938a3eb8d86fa634cbaa1f643bd2c6cafcdacba202e4683cf7245705bd11fb3Virustotal results 53.33%Heodo
2020-08-1340280870.docdoc c2bb5e128810c06abd15ad3ef0bc95622c20da154ca500892972305c94feabedVirustotal results 52.54%Heodo
2020-08-13X_IRZ_080120_ZPP_081320.docdoc 294dc4d0897b43e65d8e7c4ab761281fae2d7ff62a16dd47e9b7731019ed0c21Virustotal results 53.33%Heodo
2020-08-13DOC_TIRXEJ24GJWA45M.docdoc 2ec1025c3a44b35de74853b22998ea439d6eb5f0d92d9065256692f0deadcbd9Virustotal results 51.67%Heodo
2020-08-13BAL_YY2753046258IE.docdoc fd41e70db05893d7c379f80fc4f746ba5434063d86627d72354c1b604a2ce8d1Virustotal results 51.67%Heodo
2020-08-12DOC_PO_08132020EX.docdoc b09cdb8f91eb70d7f179d304a4585ab2b1867a160d9760ab236065aae029268dVirustotal results 50.82%Heodo
2020-08-12A_PO_08132020EX.docdoc d0ecee1cad0e97af4b127dc23861ffbee329ef4a465840447b48e554801e6081Virustotal results 49.18%Heodo
2020-08-12PO_08132020EX.docdoc c872e36dabcc02d5ca6d5a1c7ff09a8673509c3a45dc42978988f19f053fffadVirustotal results 48.33%Heodo
2020-08-12DOC_90175094.docdoc a60558a7dfbe4e862f3eadcdb17ae60763476f2941a79db0ba679e0756cf4e18Virustotal results 48.33%Heodo
2020-08-12BAL_75519316.docdoc cfec1c4aeca2bf10496b8ae3be0b77a9dfade44f1503c09398114731db0e92b5n/aHeodo
2020-08-12INV_SYH_080120_VFL_081220.docdoc 2ce9231232c3f7dab2351dd85611a118de814e5678f3916e3f1d049099f1267fVirustotal results 48.33%Heodo
2020-08-12DOC_D5542JZ14K08W.docdoc 448b77551e8ab272663dac5ccf4cad4be8b7dcfc1759a2859785754aa44d285an/aHeodo
2020-08-1253190007.docdoc 81b56737e0ebf1766ee14ae1a7c022da0208f91ddbae7d06bee3cefbbf3b01a1Virustotal results 48.33%Heodo
2020-08-12DOC_MFR_080120_JII_081220.docdoc 73d993b62b39229b0ab7fea80829a2adc7b229bb3cb9737b3f905c219aa9754fn/aHeodo
2020-08-1281588702.docdoc 42784e0de01af05a046c1361a8e58eeb1d7eb88b72badd646658090e49a54939n/aHeodo
2020-08-12REP_513015412093.docdoc f19b16a6b70c8cb1df5f029983b5176588645914bead2d0b21292174bf7d0839Virustotal results 45.00%Heodo
2020-08-1204150089.docdoc 97feccf3c91f6d0275ecafdf2bb2d3a869dbd30f1ed7e87db533ac6a63678fb5n/aHeodo
2020-08-12FILE_PGMZFZ6TC0G.docdoc dd4525e6914fa0fd2f91bde41f2df30ef8857b9f08c19e0a106ec78098ab63c1Virustotal results 40.68%Heodo
2020-08-12INV_PO_08122020EX.docdoc 1b43dacaa3825888c4583607901a5fad687f60840690fa8dfb7b5ab72e28c27an/aHeodo
2020-08-12HPC_FXHFU2HBBHFPBXXI.docdoc 25263694227734da43c741c2d09b0f0aceb8cb2d9488378a2ea765c6c19be594n/aHeodo
2020-08-12DOC_AGO_080120_DRC_081220.docdoc 4020a8982e70b51b150cd40a837ea5dfceb35f0a6c9f9858b3fae5e00404ae62n/aHeodo
2020-08-12REP_63166110.docdoc f7839e4820b80184243adc516719a06331ca2214d95f1f803b33f2884cc5cb22Virustotal results 28.33%Heodo