URLhaus Database

You are currently viewing the URLhaus database entry for https://barelmineral.ussl.co/wp-content/fi-c79-92/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431908
URL: https://barelmineral.ussl.co/wp-content/fi-c79-92/
URL Status:Offline
Host: barelmineral.ussl.co
Date added:2020-08-13 12:55:05 UTC
Last online:2020-08-14 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 12:56:03 UTC to abuse{at}isoc[dot]org[dot]il)
Takedown time:13 hours, 31 minutes Good (down since 2020-08-14 02:27:30 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14INVOICE_6_936972.docdoc b912946f86e61acf37130b179be53f6dfa2fdd31fa0e158dd2fd19f557aaf059Virustotal results 36.67%Heodo
2020-08-14invoice WV044 479698985.docdoc 60f8488fdb7df1654b540cffa5a6b15006c90ab03e4cfbc618d7594c813c252dVirustotal results 36.67%Heodo
2020-08-14Invoice-IQUJ6-444468.docdoc 2879a9d705300779c0269f3a6847fb725a3564c7ae27f44226fe17f422474ca3Virustotal results 36.67%Heodo
2020-08-14invoiceHEDA0864344999666.docdoc 532d6be9513e3dea9cfb7040d4e2b0878429f90b84e8c3229ba775ff99dcfbbcVirustotal results 37.29%Heodo
2020-08-13INVOICEZB726139047.docdoc 3c2103ec1e6af0ce039524d58d70a4ced5e2845549def894d03f836978afa09dVirustotal results 38.98%Heodo
2020-08-13invoice74127545.docdoc 1903fc2590537417ead798a7e0026a3f89c338018d0ff2942e8f984a197b930cVirustotal results 35.00%Heodo
2020-08-13invoice-JG39-4049977.docdoc 2700c5a0f48e93d064b77b0179fc337d59ed7d100dcdfa5f29c2f1d035e03204Virustotal results 36.07%Heodo
2020-08-13INVOICE-TWC8-52786573.docdoc e1ac6201887f008a8beef8eca74076739b93dacf2d0d366f3329ca55dbc3c827Virustotal results 36.07%Heodo
2020-08-13Inv RRW943 580040685.docdoc 9790de78c7614b7690b8f35d421b7704eb89e5eb5cabfe24dcf83485d90e2949Virustotal results 36.21%Heodo
2020-08-13Inv 66 69784626.docdoc cf0b0c4bf2dec3979bd7cc8606c1c911299845f9f97067fd4ae7af1985e6f6b9Virustotal results 36.07%Heodo
2020-08-13INVOICE GCUW4574 040668.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13Inv CN0125 8766941.docdoc 3423e50e3ca9d294abb9a295ac2ca4d7c44b5ff0e9642bf553ac9b6a5f44968aVirustotal results 35.59%Heodo
2020-08-13Inv-X49-1622684.docdoc 894dfe7d84439530c0f7bdca76e92f6d9ff10fe2121e0ff8decfea3153f5e91fVirustotal results 35.00%Heodo
2020-08-13Inv-0629-559913.docdoc 7f84ffec8d67c90cf874b1c63419a909e57b6e610d050a800bccfef7de037607Virustotal results 35.59%Heodo
2020-08-13Inv-UWKS9677-35345014.docdoc 17c0ad7fe3012db3c5ada59ba1d21436aa344ab57a37ce699684f8bbead66de0Virustotal results 33.33%Heodo
2020-08-13INVOICEGT9512893344.docdoc 9c555a84e2b325b4c2d60e9dba477c087791380312f4c5c664d3ab4f1c47ab86Virustotal results 31.67%Heodo
2020-08-13InvQ5475192591.docdoc 7e058242f7a064bad48c7b7a1e45ebabdb59903cabf069d79e145c9edd2408fcVirustotal results 33.33%Heodo
2020-08-13InvoiceY0624236.docdoc 53012447056c43d98e67bc063b1016fc1330216796dcc7c1eaed32a4aa02b45cVirustotal results 31.67%Heodo
2020-08-13Invoice2682232579.docdoc 286f7949f545a67074545aa0830816a560a993143774c4468d041d5e656d2897Virustotal results 28.33%Heodo
2020-08-13INVOICE-HF9-57635808.docdoc e2b52ca08d4008fa9685112c5dfd20fcc5fb9d70c23426f9a30404ece51ca0d1n/aHeodo
2020-08-13Inv-Z8777-44972335.docdoc 43911a79aeb74fd3a33a725d3ccbb05e5e86c849166f578f3404711fa0bf5b42n/aHeodo
2020-08-13InvE882891057.docdoc 15d4072c53fa3b05a16568fa5acde654ed398a0d7b016f4447cc7d051d91f05en/aHeodo
2020-08-13invoice-DLD8336-943758461.docdoc ec1d8db770842d2aa815d796d9ca7b59b1a84ffb342060081768bdecf7025cbfn/aHeodo
2020-08-13Invoice-2-668840.docdoc bf2332d7bb2fe3a48644b9436beaccf7cc4015b5954d8d012f2b095e21023629Virustotal results 26.67%Heodo
2020-08-13Invoice 6 770992083.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo