URLhaus Database

You are currently viewing the URLhaus database entry for https://bajasocietytours.com/f6r9mezet/tYuWG8_1sCthR2n32EK_sector/individual_portal/49669779821_KQX81J/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431904
URL: https://bajasocietytours.com/f6r9mezet/tYuWG8_1sCthR2n32EK_sector/individual_portal/49669779821_KQX81J/
URL Status:Offline
Host: bajasocietytours.com
Date added:2020-08-13 12:47:16 UTC
Last online:2020-08-21 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 12:48:02 UTC to abuse{at}fastly[dot]com)
Takedown time:8 days, 3 hours, 44 minutes Bad (down since 2020-08-21 16:32:25 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13Rep 20200813 NNK836262.docdoc 147c789ee92535626bf97593edc4cba8eb038bbe791b789dcd5b3bd764422ab3Virustotal results 35.59%Heodo
2020-08-13List-MN994.docdoc 5f96809ce7318e6b0c924f6c7c8c0f347e5385e22069add17fe7d652ce942617n/aHeodo
2020-08-13LIST 2020_08_13 PDL482728.docdoc bf4e2b0052aad9331b180f8c0fbb0ee99b541507fb83d3854e867bd581c021d5Virustotal results 31.67%Heodo
2020-08-13rep ZPI889231.docdoc 57270c211c92893639f45356ac942602a73f44cd8d9f13538b2afd2e300ea475Virustotal results 28.33%Heodo
2020-08-13DAT 20200813.docdoc dc9ee8dbae745f314dcf91cf70bb49c1a8606b283b556b96f7a50319a6fcfd60Virustotal results 29.31%Heodo
2020-08-13list-F247.docdoc 1c7abfcf77b96e834aef70f12517b09ee1a40cadba5ec37d5839496d6d2cde7eVirustotal results 28.81%Heodo
2020-08-13inf_20200813_MT3930.docdoc 4c4fee5f3cb0f6ccf69fa127100c3ee319939f1dcc6c75670c7ea6d92fb49c79Virustotal results 31.67%Heodo
2020-08-13INF 2020_08_13 935978.docdoc 59cf60d70be84cb50173a843815e0f1e700e02794af516037a781dec3a6d6be8Virustotal results 28.33%Heodo