URLhaus Database

You are currently viewing the URLhaus database entry for http://bouwer.cc/fonts/DOC/qb7kgd8qqr0v/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431685
URL: http://bouwer.cc/fonts/DOC/qb7kgd8qqr0v/
URL Status:Offline
Host: bouwer.cc
Date added:2020-08-13 08:09:36 UTC
Last online:2020-08-13 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 08:10:03 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:8 hours, 4 minutes Good (down since 2020-08-13 16:14:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13XY_PO_08132020EX.docdoc 0dc89060ce65e1a001a41ac93d27d19df8f9072ae7d04b8c0619316d56479df1Virustotal results 28.33%Heodo
2020-08-13BAL_KTYYIOJFWBYE8QFM.docdoc 479e00f4a39c727821fabea3c681e051bf755f4eb4c10e62f23055ca7f4a9353Virustotal results 29.51%Heodo
2020-08-13UHC5MHTK1.docdoc 4b99e8df8f724bfea2f32a9274cf4aa0f41b3e57a2b1ec753b17514149c670b2n/aHeodo
2020-08-13DOC_HPE_080120_LFJ_081320.docdoc 2712c4838033dedebf571013a2e3334dd6644d201c60f66a6580f25e578f7aa8Virustotal results 28.33%Heodo
2020-08-13INV_101999789876379.docdoc 1a457779d9b645e40120f23efa5aef5b0b97308f610fea5a06377c0603636f98Virustotal results 25.00%Heodo
2020-08-1318183878.docdoc 30aceb60d6841a0f444bf36dbf53b021d32f7c1494c42f2c8600c6ea1b84909eVirustotal results 26.67%Heodo
2020-08-13RKB734DRB2ZW.docdoc d13374a43739a62be86e9cd0195f99e350d2fc50121d35e18c3dd603d92cbfe7Virustotal results 26.67%Heodo
2020-08-13PQG_8XGIJM777190SH4I.docdoc ff2d3e5bbe8b9cc5b8af05387071823a06c6269e9a7595efe0a597915db9ab1bn/aHeodo