URLhaus Database

You are currently viewing the URLhaus database entry for http://basinfarm.com/cgi-bin/8pj59opx-indk-156274/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432610
URL: http://basinfarm.com/cgi-bin/8pj59opx-indk-156274/
URL Status:Offline
Host: basinfarm.com
Date added:2020-08-13 22:32:12 UTC
Last online:2020-09-08 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 22:34:04 UTC to abuse{at}macstadium[dot]com)
Takedown time:25 days, 18 hours, 30 minutes Bad (down since 2020-09-08 17:04:44 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15Invoice_A4992_7693003.docdoc b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421aVirustotal results 45.45%Heodo
2020-08-15INVOICEE6787183159.docdoc 8f88dd80520ccf01a78eb649cc1a7918ff8a0c36019a7b5ecf59ae9c79afae7dVirustotal results 40.68%Heodo
2020-08-15InvD6333192232.docdoc 6c9a9fe8a14e4fd6412da7cb62d2b7b0b648d8297d5fcdc035620a95ff1b2650Virustotal results 37.93%Heodo
2020-08-14Invoice-IZD3595-995861.docdoc 426e28c9564a4fa65f54f69e35bc2c5ff53a951f924883a9dcb491a5278446f9Virustotal results 37.29%Heodo
2020-08-14INVOICEWDN8124786330.docdoc 9b4854075266029833675d652902a1baea75b0755d7ebcd141125072d0967b65Virustotal results 38.98%Heodo
2020-08-14INVOICE-N24-636331.docdoc 33a8aa9764e02d87f0cec4eefb1f0a698ad48b39a10a8a9f2d62856a30cce1bfVirustotal results 30.51%Heodo
2020-08-14Invoice-UGB870-35481881.docdoc 022cf3a8bcb181e5218ff3a6b7e759e94462df01ff93902560371dfa2ffc0950Virustotal results 28.81%Heodo
2020-08-14INVOICE FGRP9 2643936.docdoc fcb8e14f4f7c929c7459969ddc1c4e7cc6d538686e9e51e9a1b4c3a30dc444b6Virustotal results 25.00%Heodo
2020-08-14Invoice-IGC60-28276558.docdoc b580ef15f157d6c19b61810ddb5f085007685d55693d05cb54782cb52bac7e2bVirustotal results 24.14%Heodo
2020-08-14InvCYLS800338433.docdoc 73d4b0a7ca15e61e87a8fe48a88037618e4b4aac3d8a94cf4583f52cbab9bcc1Virustotal results 25.00%Heodo
2020-08-14INVOICE-NUYM3-80457281.docdoc 99db7baf30cee72146c4791d36d158ca3ed62a58dd3bd57b7bfa60d0f13b08d9Virustotal results 24.59%Heodo
2020-08-14InvSK803927403598.docdoc 27db24afe51c643a809e559c190b96146022ef6d3394b8e990c6eee4bb9846acVirustotal results 40.68%Heodo
2020-08-14INVOICE-P0-907610998.docdoc fb17807621969c33d345882ad5ae95cd5294c32509e13a6fe8ce1d317a5c3f4dVirustotal results 38.60% Heodo
2020-08-14Invoice_W2_811007.docdoc e8516c23d1aec8faadd52ae68fd240339940d05f4a1db7c56afdbec1eb5de0f6n/aHeodo
2020-08-13InvoiceCCB6025446364.docdoc 3c2103ec1e6af0ce039524d58d70a4ced5e2845549def894d03f836978afa09dVirustotal results 38.98%Heodo
2020-08-13INVOICE IGXU8107 3953868.docdoc ade362fe6bf01954d42e0274b7ea92ba659ed089143955dd7e73bd36389ef2b6Virustotal results 35.59%Heodo