URLhaus Database

You are currently viewing the URLhaus database entry for http://naturalz.co.uk/wp-content/OCT/gd6srdp1peq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435743
URL: http://naturalz.co.uk/wp-content/OCT/gd6srdp1peq/
URL Status:Offline
Host: naturalz.co.uk
Date added:2020-08-18 14:54:33 UTC
Last online:2020-08-25 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002873901 created on 2020-08-18 14:56:05 UTC)
Takedown time:7 days, 6 hours, 49 minutes Bad (down since 2020-08-25 21:45:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20INV_5683252394355267628848.docdoc 02beded3bf97160a812d8bd478ac0f798e12c3b82c464bb8429c8a5d78ae0c3cVirustotal results 23.73%Heodo
2020-08-20REP_81449879.docdoc 6e331c9aade826ba3e5c77a819bbcd3cea15de0fd225a9bb48937c18be6855eeVirustotal results 24.59%Heodo
2020-08-20DOC_59999274.docdoc b60e04c121ade20dec6f8ce0c0a4a61a493f860a63c36b02796272a6897c95d6Virustotal results 23.73%Heodo
2020-08-20T985V2UMCJELT.docdoc 2d76fe1bacf66d80f4a8dfd102f00c77dcf12834e0adad890869fe7a75d45c2aVirustotal results 23.73%Heodo
2020-08-20PO_08202020EX.docdoc aa93e863d27c68551129cd31ecabdb36f458351a201c4b1a75ebe0290ea8a96fVirustotal results 23.33%Heodo
2020-08-2081374543729888073.docdoc 3f2c830f96d457a0028af46251cc2fc50abb54219ec28d08c67c0836e7316c7aVirustotal results 24.59%Heodo
2020-08-2083115557.docdoc af814b93d391c55cf505da148f1c2115049dda290499697b1b91cf51e099828eVirustotal results 23.73%Heodo
2020-08-20REP_88616195360255735530480.docdoc 66adaecff904f859044c0d2aacc5bf77afc7928a3827c0e75dda7e79c0c29601Virustotal results 22.03%Heodo
2020-08-20LNY_080120_BNG_082020.docdoc 73bfcb9214b001594d3b0d3cc9c11c8ae9b0c2f57e4b75b8772cdad41a7e3c28Virustotal results 22.03%Heodo
2020-08-20FILE_22278677.docdoc 004df4af1179c95b943b776e868fe3f553dc136e2586a75fcbb13bf6c000f569Virustotal results 20.00%Heodo
2020-08-20BAL_PO_08202020EX.docdoc 1ec4fbe7672e49a2c4d311f2abb491d07517aa98db9ade8f346fefdc6cad7469Virustotal results 20.00%Heodo
2020-08-20FF_PO_08202020EX.docdoc c802eba2db804a04ab987a147c222f47fd3b4d1857357dee1b8654b785f0cb79Virustotal results 18.64%Heodo
2020-08-20REP_10761564568499303786683.docdoc bfdf3c9957775bcbc77fd32ca103eb77c0d7ce345a27bde62c3347647ad94a06Virustotal results 19.67%Heodo
2020-08-20BAL_26152277.docdoc cc9254149ac0a5f25e859e00fd4ae509b05a23e42d49708d4c0a15e4628b1c66Virustotal results 20.69%Heodo
2020-08-206257007145303634275.docdoc 890e403968406cb230b63710dd6d5778f4d263ba49a2d760dd467d43bf7abf6cVirustotal results 18.64%Heodo
2020-08-20JRW_080120_UVM_082020.docdoc 6e647b837da2262825372b4fb5ccf78f780e467cdcc593c348153bd1619dbf86Virustotal results 44.26%Heodo
2020-08-20FILE_866625567.docdoc 66a403efd8393bccf77c5569e565832eff2be778707554b35b78be859b2af41eVirustotal results 42.37%Heodo
2020-08-20INV_19822614.docdoc b1a3a3654d76f8eeaf84cff925c62e4f349407617da64a11c91b03851f5cf209Virustotal results 40.68%Heodo
2020-08-20884170966792809962703418.docdoc 77dc94d7a2eb1a8f1f2875ee18a8115333a3c2ab0f0455d8cd46b952f93809b8Virustotal results 40.68%Heodo
2020-08-2070559044.docdoc a184a094e50174dc9dc8c5c22ac016c02f3605fd19c733c49ad1ebf02c493f65Virustotal results 40.00%Heodo
2020-08-20INV_XJXYSXNKW.docdoc 6caf84cf6a6cadcdf4aa5f45a9f87b63c16cdf6486f53279c0ce48676edfc142Virustotal results 41.67%Heodo
2020-08-20FILE_YA8102106419NF.docdoc c5efc23a6bc4da1660b4c6c3b4755581990f7c00591cfdce1350df652c03a3f6Virustotal results 40.68%Heodo
2020-08-20RO_PO_08202020EX.docdoc 28a20d1749e1a04f9f1a3b039848a6bbea1a51f656aed41cc4dc53d7f5b0244dVirustotal results 40.68%Heodo
2020-08-207760776686348782839720.docdoc efc9df64f0aea494ccbf81d79ceb9ad0f6f61a44f33641edc6db589eb766ce52Virustotal results 37.93%Heodo
2020-08-20INV_NIW375SD39Q.docdoc 580ae2c3801f24f8be8cc24b136f1d795787ace030c75c837410f5d827ca02e5n/aHeodo
2020-08-20INV_YX1681122099YD.docdoc c1f3cbd6d7d02d5e8ba90bfd5879666ea767404317f85fefa8ab95d16e938b0eVirustotal results 38.33%Heodo
2020-08-20INV_JQ6417608786LK.docdoc 275e276c98e61d33c2852f27d543c9cda4212aa16383e36b2e3651a28070a8fcn/aHeodo
2020-08-20FILE_RH9053172810EG.docdoc 60bb16533f938460519528657d8b785485622e3471330a87fa5894fed506eed8Virustotal results 38.98%Heodo
2020-08-20INV_PO_08202020EX.docdoc 5debb0401a79585a656197d49e148048a7c7db909c234ae80dd84798e89663cfn/aHeodo
2020-08-20QJ7221492185JG.docdoc b32f302c129728edd895136f299f0e68031f9554b42be4fd2dd35f80a9b2a750Virustotal results 38.98%Heodo
2020-08-20REP_SFI_080120_WUX_082020.docdoc 258ce6696ac78fb8d21424c2e471d638e03aaa8c2aab1dc7a78e2125e77dc9b9Virustotal results 38.33%Heodo
2020-08-20RW1768005675CV.docdoc 96f7d13cfc1edad4f9381ae98cab2336d39557b2230d88583c92284d6616b4e5Virustotal results 38.33%Heodo
2020-08-20DOC_HX1352917806WS.docdoc c2924a9f73b92c51fa8e36a2e4d1f98f76871c4dc0c8343033f8b18002cad912Virustotal results 35.00%Heodo
2020-08-19REP_AVZWHAII5GU.docdoc a75897a4101123281bbe047444001acc874171e15cc5a6047baa32d5100d4237Virustotal results 35.00%Heodo
2020-08-1939146692192.docdoc 06212a633940e412d08fe257dc44e835d74a44b32a8792643dbc963f5002005aVirustotal results 30.00%Heodo
2020-08-19E_981968721682184232397.docdoc 202e9946335a6bbcfe31ed6dd361c069685259ffe504dddfcb312ff5ca4b5107Virustotal results 26.32%Heodo
2020-08-19REP_02232705.docdoc 038f9798da3df2c253620a2fd844e48c6d1a331e314d44196df45b0f9bedffdeVirustotal results 27.12%Heodo
2020-08-19R_PO_08202020EX.docdoc 293921527da71236ef9e13d2b761e81efe85607ab084b379dd797bc3b6a31218Virustotal results 16.67%Heodo
2020-08-19TZM_080120_RUJ_082020.docdoc 063b886950d14cfd765fafcd552629e1c87c3c1d0b03cc4a794e8c02dd34db42Virustotal results 16.95%Heodo
2020-08-19JSN_05675934.docdoc 249d09495f8a48b2afa8c8ee4d0d0dd82905f53396e8026eb04a6db756d73593Virustotal results 16.39%Heodo
2020-08-19NJQ_080120_EMX_081920.docdoc 080538677c76d09277a58f1dc9be3e5df254a92d12fddc11326c1f896cd93a98Virustotal results 17.24%Heodo
2020-08-19R_EQ6593319499KN.docdoc 7feab4f1f35adcc7433afdbf4448e5b79996fbe150dfe6e0f708a6c13ce86f7bVirustotal results 23.33%Heodo
2020-08-19S_77684495.docdoc 8d3b2fdc25288364fd65d1dd62308aadc287a87a4dd553b72a6937c088715771n/aHeodo
2020-08-19BAL_PO_08192020EX.docdoc 86480c7538f4288ee85b3d2de9e26e9d24cf22c6a2902bf81013a5826ff2afeeVirustotal results 23.33%Heodo
2020-08-19DOC_KTS_080120_EOG_081920.docdoc 39f8850f02b807a843447f461d3436d67191f0f08709c03d32958988964b5e9fVirustotal results 23.33%Heodo
2020-08-19F_98795152.docdoc 783974bc2743d417a2df0a73eaf9e83ebf04435f67741f711a498effe3997894Virustotal results 22.03%Heodo
2020-08-19BAL_484007373287933773.docdoc b4319c87f6557ca9768ff78abfa16c323c6ed7de149f3f741c390bfd70cfb22bn/aHeodo
2020-08-19167138921323955963435.docdoc 0d9522e1c5d18866b466aa9d28546adc56ea56f6d821fdda5ab77b1285b9e0d8Virustotal results 23.33%Heodo
2020-08-19PW_WT7FD8PZFHV.docdoc ed6f742fc6e103f092e9fd9301bf4ec786e88abca3ec1593661c4083f398616dn/aHeodo
2020-08-1989291896.docdoc 543c33664c0023f112db5e33d85ecef70d375848205f72b2305c648abd21137aVirustotal results 20.34%Heodo
2020-08-19REP_47513969.docdoc 6e24d40dd2ab39e102c07369124f050fc0b0f2c103fc5acd2fcf280d8048b1bbn/aHeodo
2020-08-19INV_EPF_080120_ETY_081920.docdoc 77834d629af8b45f85ec232e03fab3cf97e78e448b23fe48bc93ad6a391f3c90n/aHeodo
2020-08-19INV_V6ZS4C1YSY0.docdoc 42b9726416b4076116e799c57988e1d97cfc0331d87ddbb84cd3ddacae97effeVirustotal results 18.33%Heodo
2020-08-19BAL_DM5684464165RA.docdoc 8cec3b93eff7809fb7cd1ac496b3c62702625511c0f52ac2aa79894af7801ad0n/aHeodo
2020-08-19L_BBI_080120_DKG_081920.docdoc 3ae29b3f7f29f20ad0073a44572a88b7aafe19da62e0a8d8d8a04213945f0e80Virustotal results 16.39%Heodo
2020-08-19VTW_080120_VFP_081920.docdoc 0497b08002a87140203cebba96112f295125ba3e002ada7880e6937d484d72a2Virustotal results 16.67%Heodo
2020-08-19REP_489480843032914401774.docdoc e11c5acfd7962cbfc0d24bd96833b535c52e148b42d4181feae6ea497f2fc228Virustotal results 16.67%Heodo
2020-08-1998205846.docdoc 1a17af806d615019154f0985010aad3789bd90bdb40970f78cd0cda2bd722896Virustotal results 16.39%Heodo
2020-08-19REP_IXJ_080120_KUS_081920.docdoc 1b110485a730140a1499cfb4e0313b280748117cd1f41699438e6e103af73ea7n/aHeodo
2020-08-19DOC_IJS_080120_LNB_081920.docdoc 031a67c034a76b31c3fa139f4bbe570bc3a74c61c3b901164fb60733db2db9a1n/aHeodo
2020-08-19DOC_66058115.docdoc c6c4ba6bead64d98f91dca8dbc28c67ee9be3a3c5b9de2e50dd98c7c11349cb0n/aHeodo
2020-08-19DOC_920269689841640247.docdoc 2ca8d5c4526c1a04e6406016d315ea1905199c970b43545fb72bacb3e0cab192n/aHeodo
2020-08-19BAL_PO_08192020EX.docdoc a7f7da45bf54c26cc2fce4e3c3a639209f7701cad6339b69b3980224423d2d7bVirustotal results 16.67%Heodo
2020-08-19PTGZKZNJYV.docdoc ddc5000139723887bfc62c11f989af0e0fdf375b0ba4557f5abc5805e1228203Virustotal results 16.95%Heodo
2020-08-19TG0031702318GH.docdoc 74c71e841348fffe1f1a1bddbd7db99dcefdb48c019b49fd480dd8975a482cf3n/aHeodo
2020-08-19ZN9888688199QQ.docdoc c84cc34fabe449b4d98254989e104711653a48f902a35184e496f2f61508fc55Virustotal results 18.64%Heodo
2020-08-19DOC_85214306.docdoc 6c565f07002b82c287ed1f4c316b8ed204766e4fbd223250f1c2cc1f110b7bdbn/aHeodo
2020-08-19DOC_N1EW8NVTTXXT.docdoc e6897b31f6e77a3182753226f0781709a200bf67633cd45568c33c4e78b9456bVirustotal results 20.00%Heodo
2020-08-19130680793204174366.docdoc 0099a00ee33efc8e25e68b3bd2862656ac4819416a7ce5252da75b326480ece2n/aHeodo
2020-08-19H_053286399338885533.docdoc 05897a743fd2fe3d791b9560b3a3a0d5fa3f4ca8c2dc6f1a490aaf4a7f4f5636Virustotal results 18.33%Heodo
2020-08-19FILE_PO_08192020EX.docdoc bb8f4400df61e199e8f1c8bf7bc8f4409d7ad9eae9af6cc6ce8ae32bcb99be8bVirustotal results 18.64%Heodo
2020-08-19GRK_080120_QMJ_081920.docdoc a3cdf0d9417faf332e124ab24792ff79fdd1dcd6f24bfb381b70d9b735e6cf18n/aHeodo
2020-08-19SZZX_VXT9SCXK5.docdoc e7b5571f8fcba096c1240aec4d940d600588432e00c3f22504711fc6b240f8bfn/aHeodo
2020-08-19MGQ_080120_PZU_081920.docdoc d5b8f7aec352f5d8ac2d69df3092351a5eb917efa88b9e676fb8fad5ab66d38bVirustotal results 18.64%Heodo
2020-08-19AYVL_MK3203821283MQ.docdoc 8a1e1fab3fba900930b3f32533b358523802c467157f7234c695ba163bc0fba0n/aHeodo
2020-08-19FILE_KBVZ09LLC7.docdoc a1b39bb8e04288328a8785f48219abb0b12a2a6330e2192973405a2bf6682644Virustotal results 46.67%Heodo
2020-08-19BAL_36607492.docdoc a3773aee947b0fdf4bb4d2a48777f6e8e4a83beb62f033efffbb0b487bef2e8fVirustotal results 48.28%Heodo
2020-08-19REP_ADO_080120_NMK_081920.docdoc 4e187ac73b149abc0e10adc49388c872b2bf2dc68d4a7285586ce13e3b6bf427Virustotal results 47.54%Heodo
2020-08-19TLLU_BX9259464463JM.docdoc 882600fee7e0ea4b30699f07b2c5237c9cb80b2ed0bdd471d055f7b450565272Virustotal results 46.67%Heodo
2020-08-19INV_5J4QEO7ZZ1N.docdoc 1e5fdb496c17dd55dfc3e32231d286de4334d59bcc313b939202c4f8ae2abecaVirustotal results 46.67%Heodo
2020-08-19FILE_TVX_080120_RIC_081920.docdoc db532f530a3c0922c028cff817afb07a9e082ec260a37750a8af82739e8e8ba8Virustotal results 46.67%Heodo
2020-08-19REP_42722980788897.docdoc 4fafaff4c35c7050da039eba46004fb4df1789b0f4cb103ecaf05d4fcf0834beVirustotal results 47.46%Heodo
2020-08-19REP_PO_08192020EX.docdoc ade0c61c5a90ff1c6aa1b54b0f5d9e29382b98feb206f3b170724aa6e34cb389Virustotal results 46.67%Heodo
2020-08-19REP_63130260.docdoc 0e79daf2a9f00edeae140c5e513dfe381e03f54ae3fec2dae7b2bd9f005b4f6fVirustotal results 46.67%Heodo
2020-08-195846482430853451766923332.docdoc fbf8375b991d64aa1173b7a2d5792b19bdc39b63df4d483e9ac99f47157f3446Virustotal results 48.21%Heodo
2020-08-19FXY_080120_ZQN_081920.docdoc 13ecb0280410d83e2d67d9f049fe85af186a0c9959c316c90f3ec327a9ab244dVirustotal results 46.67%Heodo
2020-08-19DOC_KQJUGB4CUK.docdoc 9cbc258b5f93fe39609cced6c936d4529b4b3ba671125e8ad51eba9085dbd3a5Virustotal results 45.76%Heodo
2020-08-19C_0701720781508575224.docdoc 189ef09b3af0c487e840219d1b144a8022ff6940de058c276ecd313ad2771c0aVirustotal results 46.67%Heodo
2020-08-19DOC_ROSHQPD832DT.docdoc 94fe6d0cc1723a60d8965c606027ad0283a60c1f4677cf33c8cb85fd202bbc60Virustotal results 46.67%Heodo
2020-08-19PO_08192020EX.docdoc bb7514867d581af837a3d30b735e4c0e010220c3b2bee800c0217cb4e7275e3cVirustotal results 46.67%Heodo
2020-08-18FILE_273049661853573438.docdoc 6e7bc5b464486368fc64b81be80628536390d77832adc42ae658a9ec6642f2b4Virustotal results 45.90%Heodo
2020-08-18Q_RB1TYHG2Z3Q.docdoc 6c9d3d58e28a1e8bbf0d1c77a0bbb7f6c71a55ac204041c9f1f8e372b19df91eVirustotal results 45.76%Heodo
2020-08-18BAL_TRL_080120_VMJ_081920.docdoc 805f00873a643dff1edc0ebb808bcc771a6641780897a3d7732b01444b2ec3d8Virustotal results 40.00%Heodo
2020-08-18DOC_VFV2WDKZY9.docdoc 471800c07ff4f9683a7c7608227076df2dc2f4c484156617e374e766466333a8Virustotal results 37.93%Heodo
2020-08-18VKNS_DU5261891463KJ.docdoc 2db327ec6e030d7937f39cdedb6cbdbade5a89c43fbf6ff39f7c4b7299261a0dn/aHeodo
2020-08-18HNQO_GER_080120_XXI_081820.docdoc 462b55199b1901a5d737132fa6f604c4b6e8d201ca57b5971ce95294fb74a056Virustotal results 40.00%Heodo
2020-08-18PO_08182020EX.docdoc 1ab945db51701046ee561291c84c12844c96cad17d38c044915bc3657803b75en/aHeodo
2020-08-18LW7471247471DL.docdoc cab6349ac0df4084c7ff95a5e68f961048537236c2602cd3aff11482fb0d0af0Virustotal results 40.00%Heodo
2020-08-18L_PQL_080120_ZSP_081820.docdoc 58f54242a517952baf0ab77f9eba354e7f6299fc66a0a2ef3eddfbc9def3870aVirustotal results 40.00%Heodo
2020-08-18BUN_PO_08182020EX.docdoc ab6514637521441d7f8ac5ed656209f5c3ede987d353fbbd3736273fc2e1d770n/aHeodo
2020-08-18DOC_YD7340136468MA.docdoc 0abe25a1015f697d6e8f5657c0b05437419935530321c56d7d76893e138ab8f6Virustotal results 40.00%Heodo
2020-08-18PO_08182020EX.docdoc f13b6d284eb7046fcbacbc7d199359ef96282da973fb4baee25c10fe1f96d9b9n/aHeodo
2020-08-18DOC_APD3EIGVZ8H59.docdoc 2afd7cea805a330a133af9bf275a0d23de175b15c5cb194c042da07bc59f2cfdVirustotal results 40.00%Heodo
2020-08-18INV_GYL_080120_YWT_081820.docdoc 40bf45a0f3955cc2cb68375dd18ebe4bfbf79a8c1ced852bfaab79bcb58eb4bbVirustotal results 38.33%Heodo
2020-08-18PO_08182020EX.docdoc a7e09fdce8bb372722c2e23e9a17db2d7ebbd56845a8a4d640485b9597b271f5Virustotal results 37.70%Heodo
2020-08-18INV_VTQ_080120_BEP_081820.docdoc bdb11339f1bd60995f4f996322b18b502f9fd561ba97b25fbb7e290f03c44e28Virustotal results 35.00%Heodo
2020-08-18K7KC8KRHOMJPH.docdoc 59a09a4e193789a268b7d79fc4e5a2f5be16c87cbb04c5fc10e2ec27aaa641d5Virustotal results 30.00%Heodo
2020-08-18REP_PO_08182020EX.docdoc 0cef6300d4ff34161fe15685c7de03dd6663177b6ca1d87df136eb05e9daf650n/aHeodo