URLhaus Database

You are currently viewing the URLhaus database entry for https://balcon.in.ua/cgi-bin/fffvwgbw-4074/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436533
URL: https://balcon.in.ua/cgi-bin/fffvwgbw-4074/
URL Status:Offline
Host: balcon.in.ua
Date added:2020-08-19 12:28:36 UTC
Last online:2020-08-21 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 12:30:03 UTC to abuse{at}contabo[dot]de)
Takedown time:2 days, 0 hours, 22 minutes Poor (down since 2020-08-21 12:52:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21invoice #061231.docdoc 2ea68a6593ecd154f5831ded058bb90fb04c3504f377a4817ac2c154e1735748Virustotal results 22.41%Heodo
2020-08-21Payment status.docdoc 2d95348a5ec4fe86adef58e7bac3cc8c8bf1520554fe9d9bda6adb84865fad75Virustotal results 21.67%Heodo
2020-08-21Electronic form.docdoc 403c11dfcd14c01cf91b6fc45cb7ef0a55919e8e5e0292399e1cbe734bb9d2a3Virustotal results 20.69%Heodo
2020-08-21form.docdoc 6f69eecc69ca89716c536b2effc57f04fe5739e38fcb08dcce20d16efa1d382eVirustotal results 20.69%Heodo
2020-08-217291693623JI.docdoc ebf536cc3ab147667e77823b5feaa2f72da1042d653ad11a26298800a7a86d77Virustotal results 19.64%Heodo
2020-08-21Invoice.docdoc 4da5e980866878da930be670800361fd6b9b6ec73983dd60cdba9eb29bd09ab6Virustotal results 22.03%Heodo
2020-08-21050696.docdoc 1c8f1124a4ccfc01bfc51367aeeda6685df4fc2ffc245deca3430582af9e816aVirustotal results 20.69%Heodo
2020-08-21Inv. 0905578338.docdoc cb1cb520f7c2fe2b89113a68a240335c659dae5af1b11b7c68531927c1e227c8Virustotal results 20.69%Heodo
2020-08-21August invoice.docdoc 762a08ff51aabd7ee2cdcb6f27fe687ead902ab8f3b84925b013904d356cb622Virustotal results 18.33%Heodo
2020-08-21JZ1701384797WG.docdoc 8ffb84f76b863917f3ef52c3c75dfa70bc77599b7deb86067b43c413c8ff681cVirustotal results 20.00%Heodo
2020-08-21Payment status.docdoc 08b9f7ca75b18aa5ac89ec3d9232718b6027867f80a02ce5c5d9e90f8eef711aVirustotal results 20.34%Heodo
2020-08-21NX1325362464VH.docdoc 0d9f1f173fd3806d10312760c50f85b6fa23b65193732358ef675b670c84f5eeVirustotal results 21.67%Heodo
2020-08-21Form.docdoc 27e58aecfab42bc8d94aee0b51ae82f1f6364e61e448956650480710e64596f0Virustotal results 21.67%Heodo
2020-08-21Inv. 09715789817.docdoc 847717b8f4573eabf8736def4405be87f319a2f5aa3eae17a33ae61f13c9b3a0Virustotal results 18.64%Heodo
2020-08-212421501458EF.docdoc 487dafa07afa8fcd6af8fc5cb6a9455e080bb3bedddc1b64bfee71d65440c10aVirustotal results 18.64%Heodo
2020-08-21Form - Aug 21, 2020.docdoc fe21d7c3b7bf725c58793f7d3fa3c8cc7dfbfd48c10a2d9f90b6e4f0e7a708c4Virustotal results 18.64%Heodo
2020-08-21invoice.docdoc 310dc3ae17963a0ac8df3cda0697749f205c3c01787d4e24026bc30ccb7f90b5Virustotal results 20.34%Heodo
2020-08-21INV #08656 FOR PO #0492319206.docdoc be0c986b37c30a192c9f2e62d6c85b635a3e25bc10cb8a8b4ddac390bbc93163Virustotal results 21.05%Heodo
2020-08-21KP-080120 CDCC-082120.docdoc ad61f377cd0d259cfabac17a4a874cd5dbd88b076e00680d5fb1d31706816ca7n/aHeodo
2020-08-21Copy invoice #630023.docdoc eb65f89380e33a9b00ab3e9cbdd92770694c8174e055f420ae67d26718260e27Virustotal results 18.64%Heodo
2020-08-20Form - Aug 21, 2020.docdoc ed8f3cd480b6fef9996f65e02cc1cb3d295447728fd009032ac3838d32e01f37Virustotal results 33.33%Heodo
2020-08-20invoice #08149.docdoc 9c2952185499dfb564607790c299bf8a01a0bd16d64484be1812bfc88c5f5a06n/aHeodo
2020-08-20O-080120 NILX-082120.docdoc ab67561e67852b32d7111a32687165f91c21cf6acb96eb57ae1586163bfe85bfVirustotal results 32.20%Heodo
2020-08-20invoices 487 & 47034.docdoc cfc44b8a1d4f143fe85d73f5f4fb235a387a34ee7bc8d52a79e97624e075fa55Virustotal results 32.20%Heodo
2020-08-20Form - Aug 21, 2020.docdoc 8396ea542554b554875f9a90fc2135537f7d8c95b5a3cde99df06bc3686ac5cen/aHeodo
2020-08-20August Invoice.docdoc d602c575bf86a934dfc17916699ff512aba1b2b6829f1e4fd1ac6c4d1a9e9d55Virustotal results 31.58%Heodo
2020-08-20Electronic form.docdoc e39276fc7b5a1cf340d080a626b6d285ee5d53a47b231b7a3da7fc341671c8ccVirustotal results 30.51%Heodo
2020-08-20form.docdoc 205b245311901312ed7d08e486ee280d59cf15060b656390f4ea347a7eb6d485n/aHeodo
2020-08-20Payment.docdoc acf06f69fc335f401184ad3a218aec5075641fe29bce91e0f71b698c062b3e0bn/aHeodo
2020-08-20Form - Aug 20, 2020.docdoc 76d365a5b93ff03e1887ad487f1ad59d74d6b0530b2f66a47413ddb27f99d942Virustotal results 28.33%Heodo
2020-08-20Payment status.docdoc 91c51b6adfe6595da08931a5894071e6388a4cf770a95f00ee37480f8213916an/aHeodo
2020-08-20invoice #140963.docdoc ae09a760faec9e5c8f9d147329271cb1fa3971b119943d8cc9e16ce71c8e5fd3Virustotal results 25.00%Heodo
2020-08-20Form - Aug 20, 2020.docdoc e3b9adfab9f86293c439dc64a2392bdf6645cd200616eb185bc3c8fa23cb0839n/aHeodo
2020-08-20Invoice #68079.docdoc 722219128e30ae7a17fbcf0d24147c7713f628e28f3af2117130c95e0d75005dVirustotal results 22.03%Heodo
2020-08-20INV_3830.docdoc 3a9ab8d5a3d76cba944447091197434086ecae7e4ba97affdb86c17fd77c31b3Virustotal results 22.03%Heodo
2020-08-20Form - Aug 20, 2020.docdoc fb7cec2bb2ac4c31c65e299f198a586f5c5918f975075467063f59d48d28844bVirustotal results 22.03%Heodo
2020-08-20invoice #09619.docdoc b98c8587312b2674ec04ec4c3cccd572e53475f8c51922bf5418d51f07b006b5n/aHeodo
2020-08-20Inv. 297697.docdoc 7e06ee4704f2c5f8a4ed2f68565f3f7518dd9ae22b9ae4fde59b898d8d9647d0Virustotal results 21.67%Heodo
2020-08-20invoices 6777 & 1147.docdoc 1a379d36dbefbacb5038e5d9d5652788e66d50131190771a2716690a2f063976Virustotal results 21.67%Heodo
2020-08-20Invoice 0041552.docdoc ccbcad2a9942d0f7bf92e15755b8a683672cd6ec815358a55c4d2b2a74f6b93cVirustotal results 22.03%Heodo
2020-08-20V5183309243RV.docdoc ce4cd4d124a577ac6f489568a077a53e6745170cb71a64c5b4bcba502af51347Virustotal results 21.67%Heodo
2020-08-20August invoice.docdoc 700b22e0508a889751892ce66df22fe34fcf52222db541d24e6d338aa351cfedn/aHeodo
2020-08-20Copy invoice #213629.docdoc 88b2e8e9fce8d57e43a9babac92605fdc43c417e3d6fe2f67e7463fc7dc41424n/aHeodo
2020-08-20Invoice #2155.docdoc 35cdbc32f50870b20e2cd551f4805152d7ff4c9a9977739de4036d9fe76a6e0cVirustotal results 40.00%Heodo
2020-08-20INV_8483.docdoc b462b6985f21115db5a18167bd1701f4a2599116fe237a0156cc2cce93e96edbVirustotal results 40.68%Heodo
2020-08-20Inv_1567.docdoc 1ded2d7cc228ed55fcd64164252d2a2da11cf10ad774d7315bcccd449336ae72n/aHeodo
2020-08-20Copy invoice #455353.docdoc 96724ca5aa5c891ca6a5e5ba740b3ec303445857cfd63cecc5828087c6171673n/aHeodo
2020-08-20August invoice.docdoc 6d2b21d6252c4659acfd6b04ba63540c373507ab3df7cf2d209a7eb70c693654Virustotal results 40.00%Heodo
2020-08-20Electronic form.docdoc f1a7f5de80b5f75e5e52318197ab69af5a862ec92c7d2c27680503abc81e989cVirustotal results 40.00%Heodo
2020-08-20invoices 881 & 5381.docdoc 252905fc07b8d4de77b22dd1c68bba23716cb7bfbf56bae15a624f59b7e69c70Virustotal results 38.33%Heodo
2020-08-20August invoice.docdoc a0601dc3c3afeb7471b9fe739ce24e0b476d100c3f2ee756df211888184f67f0Virustotal results 36.67%Heodo
2020-08-20Payment.docdoc e10d9e51f37cac947f9dac20f25fe6c9cdbc9a27072d1f54575087d0d63179fbVirustotal results 38.33%Heodo
2020-08-20Copy invoice #3460.docdoc 7525c4f7d0c94e9857d4b84b20357ed327900e78defe3291bbed47d0d29e1de4Virustotal results 38.33%Heodo
2020-08-20invoice.docdoc 416a4f17b5bc066941020cd43640276363268db7cb067a8cc7f1d27c3cb3cdb2n/aHeodo
2020-08-20Payment status.docdoc fa10393ccc08487ee9b80a41d01c9e5e87c3c7690a74327b1b19e47f3638b66cn/aHeodo
2020-08-20Electronic form.docdoc 2cceef317fac265bf56fc5819196f6a58b95574e8085a889f61ed9cd5c6c387bVirustotal results 38.33%Heodo
2020-08-20Inv. 110275361.docdoc 741eedc40d043df1d8abba1e18fdeab3d276fd970087ad3b980243aba3c4878fn/aHeodo
2020-08-20054463.docdoc 04a14a477cf1d1d2e5a426b932542d931d6264a101a10da26141be2752db8a72Virustotal results 38.33%Heodo
2020-08-20Payment status.docdoc e138a2d8f76c4e6fea232fce64cf92aaa0e8ad25dc803478feb65bf7e4c0f1abVirustotal results 35.59%Heodo
2020-08-19Invoice #2384150.docdoc 8fef0fa03aec63f50c5f6c1b055fc5c7c90f092a2b4549ef022e6696d49c9bb7Virustotal results 35.00% Heodo
2020-08-19Form.docdoc d225f5ee78fabc34f19b2f3cce92c9ba74649bd52222615bc3c7d4301e1d174dVirustotal results 32.20%Heodo
2020-08-19Invoice 002462070.docdoc 3f50adbc111dad1db785e1c67241fd31740db030e0307cc9a2f1e4ff21aa2f56Virustotal results 28.33%Heodo
2020-08-19Invoice.docdoc ebf3882fc3552ee25191b706c94ec2567d1e45467048c7182c3cd8fde34cd4cdVirustotal results 25.00%Heodo
2020-08-19Payment status.docdoc 9318cf92c7e976a17c5fbb59cf477b976df4769fb71e7f523bc4f42edfa6393bVirustotal results 25.00%Heodo
2020-08-19Payment status.docdoc e2b049254060cf2643d248928331a6a30efdda3762f6a91a881524e30263ae09n/aHeodo
2020-08-19060469.docdoc 1cb2ba7d956a3d1741b3a3599aa84b917cb9af9e2e9e4a7814f0bef5f2abe48eVirustotal results 27.12%Heodo
2020-08-19Form - Aug 19, 2020.docdoc 7dcef62f0fc5ee7984311d8c0520820bed4f9d2daba7926f4371d2dee98d6f9en/aHeodo
2020-08-19August invoice.docdoc e518a717decc9cfeb174f53987f99d4a4c1802301dc8a18f5d83c137cfd95d31Virustotal results 26.67%Heodo
2020-08-19Form.docdoc a1502f115a7017cb9c7c69031663b6c1ffcdb53af33a3dfe8b2ed61cdd0bcc63Virustotal results 26.67%Heodo
2020-08-19invoice #671506.docdoc aaa14437f6dd748c3f483550973aa8a386d763a94036204ac1f2961d104a64eeVirustotal results 24.14%Heodo
2020-08-19invoices 258 & 8019.docdoc 3f6ede3e0181e7fd9efb5449bf7d89d05cfc819f83c78068116a366a5dd105e2Virustotal results 27.12% Heodo
2020-08-19invoices 871 & 2627.docdoc d6930b7f588a3196bb268650eb94c774a25c046e316b1c2b532fa72b71ad495bVirustotal results 27.12%Heodo
2020-08-19form.docdoc d69e7c1cc00bca634b35c3ad6f47a9682c9bb54a804e431c357f4d4b2a41619bVirustotal results 26.67%Heodo
2020-08-19Invoice #364290.docdoc f730ca57a8d3c6e26d440760271ac159ba93a110fe815fc3babe354a2a5ed4a8Virustotal results 25.42%Heodo
2020-08-19INV_856456.docdoc a812657d14a3e18ca7e96d7986dcabd377bf56ddc9c1359e1b6112b583b8a89aVirustotal results 26.67%Heodo
2020-08-19invoice #3281.docdoc 715da163a93216d8a21d68d8ba513e1f3229af00409cebf9ec1554118c703388Virustotal results 27.59%Heodo
2020-08-19Electronic form.docdoc 6f02da28377b727dfbd6e5e9e99efcfbf60faa5aaf59c7d15ffa90d17a2a3451n/aHeodo
2020-08-19invoices 8845 & 4707.docdoc bfecfe6abbd2c89807edd60e91a6826c02cde73ca91a7913bad15788f962b349Virustotal results 22.81%Heodo
2020-08-19INV #009129 FOR PO #038006405.docdoc 676fc0bbe23b4bde0f682cebd5b0e3317e1253b7b7e187fb4db080a0e76384a8n/aHeodo
2020-08-19Invoice.docdoc a6c0f9b77a2740ff615cb245fce18051af9e8f3be6f8e11512279f1abc121cd4n/aHeodo
2020-08-19Inv_101541.docdoc 2080e7550c951ac8fb488247f9ea953e73c9095393885e0d3a9e1a82077dac92n/aHeodo
2020-08-19INV_3699.docdoc 30eb0188f1beaeba0cff8341219e04f0203fe046f0600de969d67f2228e6e96dn/aHeodo
2020-08-19Invoice.docdoc 73e94740e88d19f7015e1a7025eb77e524e4b23b72f576a8e5d3abdcb6c73849Virustotal results 20.00%Heodo
2020-08-19Invoice 006632742.docdoc 0035029f24eb07d3c1eed94e8f4a24fa26fecca542c5be93577e62c55fba8fb5n/aHeodo
2020-08-19I0071 invoicing.docdoc 12b185bb785a13610c8be7a4eca5958016587dcd691c3d7881ca8927733034e5n/aHeodo
2020-08-19form.docdoc 4f4c929b5caf34632ac67337a4b27356b26490f6fbe06e9228c5d8cb60f0e102n/aHeodo
2020-08-19Form.docdoc edfa9346fe1d4b1ee98087094b8a609fcec37b0eee818d08f1852c7c695c342bVirustotal results 18.33%Heodo
2020-08-19August invoice.docdoc ab1cd40376eba2a0465c99926c13d8e538fd6acdf6db61bdff48ddda2e33a6f6Virustotal results 15.25%Heodo
2020-08-190078484.docdoc 3b376e0e8c0c2f60043466a31fa8bd5d8940395cd2e06a8b230bceac21b8bb4dVirustotal results 18.64%Heodo
2020-08-19Form.docdoc 4f36399c611399d5deaf735d98fe58ec5389be3ed80fdc5e5b7e61f2371010a8Virustotal results 18.33%Heodo
2020-08-19August Invoice.docdoc a81a36b0a593300644e70fd29ef9903447762f6e5717b6ef0520fabf5f86b393Virustotal results 18.33%Heodo
2020-08-19Inv. 001837847.docdoc 913066db387d09ebaf3bcd95c376a17dd23f0bb900d257fb47afc5183f208f2cn/aHeodo