URLhaus Database

You are currently viewing the URLhaus database entry for https://jtreus.com/wp-admin/balance/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431784
URL: https://jtreus.com/wp-admin/balance/
URL Status:Offline
Host: jtreus.com
Date added:2020-08-13 10:30:06 UTC
Last online:2020-08-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 10:32:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:20 hours, 36 minutes Good (down since 2020-08-14 07:08:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13R_43367158164486411202131.docdoc 8c688ed47cb4c03e6a851c42d6c0fe9dd9c9e2bcdef1f0884fcac5d2923cf59bVirustotal results 37.70%Heodo
2020-08-13BAL_NP1082848242PL.docdoc 9be561c7cf40dc53dbba36e51b0787a5dfb2c43000b0c5915df93ec5ef170687n/aHeodo
2020-08-13YEC_YA0436937279LB.docdoc 7b99b98d51fbd00badb479a3ad6e932681f26678e6749ca34706b8ce2b610400n/aHeodo
2020-08-13A6JGKCZW047K.docdoc 15e32f7a4675db4e399e6ac32e7b9b98197aeb89dc371330c21678abcbe13262n/aHeodo
2020-08-13INV_LCU_080120_WZY_081320.docdoc bbbfae57148d4ae3803142303babc3d2fcb182194f9112aaa34b6f4978e8e0een/aHeodo
2020-08-13REP_85478498.docdoc d2096169d1212457db40e6a605d82b82aea4ba2d2ea69225cdd2c60cd104bcd2Virustotal results 34.43%Heodo
2020-08-13PB_RWK6VMIOQDNE0X.docdoc a4d0b1c2b75f14515784a678a437ffdd8b5542fe3c2d738cbe7bcde2d5b15e0dn/aHeodo
2020-08-13U5XZRZ3Z3B.docdoc f959a3ec8067a6967f047b19554210234638a6ac9b0bac85e006979f09c33d11n/aHeodo
2020-08-13UTN_080120_PBE_081320.docdoc 81c7769a0b7529af3a8694dd0b1141ae2446ebc681026ae67653753eba1ed6b6Virustotal results 33.33%Heodo
2020-08-13HIGZ_ZWR_080120_RDL_081320.docdoc d567a4097feddecd5e5cabcdde2f997521126535222bec36e0514da36a9886b7Virustotal results 32.79%Heodo
2020-08-13HH_PO_08132020EX.docdoc 5f13b204f1454bc08133eb8207a0bbd3faa357d80495f1136ff43768e69914e5n/aHeodo
2020-08-13REP_SNB_080120_UKY_081320.docdoc 1d76d6caaf25aedb9a6b4a416eda1a0f237ef09b5100d844a54ed3290242e251n/aHeodo
2020-08-13H_XCA_080120_JOM_081320.docdoc 3d9b7dd248282da644efce8e11e6933424e766ba770a6c0eb2f817b312367a1en/aHeodo
2020-08-13DOC_09943376.docdoc 8a0a74b31fb30ce1a4adbaa3945c4186c7d467268e76b9ca802905b7cf5fa54eVirustotal results 29.51%Heodo
2020-08-13INV_QH8116241942UL.docdoc 73b34aebc917f7437b48467815608b544f747919a4a7e78d4324a99efb030028n/aHeodo
2020-08-13INV_SB0653917081HD.docdoc 4b99e8df8f724bfea2f32a9274cf4aa0f41b3e57a2b1ec753b17514149c670b2n/aHeodo
2020-08-13DOC_49613769.docdoc 72b00575d9b7dd295462c482d9ee8edfc44b184f3af563f0a2fe49014d824121n/aHeodo
2020-08-13A_9AUNNTSX9ECVY5B1.docdoc a8786f3ff1ecf32215198afb54ea5211a0c5fc6468cef97101a85ff5839b05aeVirustotal results 28.81%Heodo
2020-08-13FILE_3BY5P035.docdoc ae0c7dfa89cf0301b64ef4f6b364a1e426c79c80a9d0943916c93f3315ebc907Virustotal results 27.87%Heodo
2020-08-13BAL_46820833.docdoc 11115387b71ec2162713a34b3ced799ace3def99ab9e495234326a68ae1f6ef9Virustotal results 28.81%Heodo
2020-08-13FILE_QM0069537955MP.docdoc 430d07c2162af45022115ce4b557ab182afc95143b698568d50c41832c6b281bVirustotal results 29.51%Heodo
2020-08-13REP_PO_08132020EX.docdoc e9a1e08c1d8de096fd30cfc93c23d0037c4016bc7c4cad64c8c4c7b6fb3a717bVirustotal results 26.67%Heodo
2020-08-13BAL_0DAGQXR871.docdoc 0c4015de45653ee2f8fc6e338461a2377e14139b1ff879df5a2fe1d3c200a15eVirustotal results 28.33%Heodo
2020-08-13W_GCPQ5DFKG4N.docdoc fdf714d8a02549739b60c414ff535944cd2b7d8a84e465b55f4fa263680e9cbeVirustotal results 26.67%Heodo
2020-08-13PD_762007737.docdoc f1194d491ba7c0f8f39b1c0b9d47c4324742b324adc2e4a3feba13f77e9b40fen/aHeodo
2020-08-13FVV_080120_GKL_081320.docdoc 3f9f641892bac263ede86f11632b4a6498dcc2b94b13727c5dc8c8c594e0f608Virustotal results 27.59%Heodo
2020-08-13PV3R3T8UZN5K.docdoc 512f2b47de9367605f5adf2c1e62e8ec8b8a11ae87b5d347d720066f380367e5Virustotal results 25.00%Heodo