URLhaus Database

You are currently viewing the URLhaus database entry for http://www.bap-host.com/COPYRIGHT/public/4095796635433/f6su1p9xo8-0048513/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438083
URL: http://www.bap-host.com/COPYRIGHT/public/4095796635433/f6su1p9xo8-0048513/
URL Status:Offline
Host: www.bap-host.com
Date added:2020-08-21 09:39:22 UTC
Last online:2020-08-26 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-21 09:40:04 UTC to abuse{at}hetzner[dot]de)
Takedown time:5 days, 0 hours, 50 minutes Bad (down since 2020-08-26 10:30:44 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-22Invoice #347217.docdoc d264878eae29d3da022f38e67a38560346ba42cbb6dbebbf0e6c852c666fb1acVirustotal results 55.17%Heodo
2020-08-22Invoice #614994.docdoc 817fd6335b92d0b8ab452cc5d00decd2e0919a8fb5b6dbe0730a19432ef5b731Virustotal results 36.21%Heodo
2020-08-22Inv_127702.docdoc 5d343c4cc60ceae7c55758376842b90845f6d3dd1d7ab8fd2bed44ee745bf527Virustotal results 37.93%Heodo
2020-08-22invoices 09957 & 94618.docdoc 88fafca4b3195bc1843721aa1d78221a5d05be8d88f43ceb0e85aab917c67a43n/aHeodo
2020-08-22form.docdoc 27e2a7ad7764b75f11753d945f9b7b087f89fa4b8b9bc1198bf7992c7c85d1e8Virustotal results 37.29%Heodo
2020-08-21Inv_248050.docdoc e5c9f8c0ccfa47835d30be512636ad1b0e40d75587d5a309f586b67796aae5cdVirustotal results 33.33%Heodo
2020-08-21Form - Aug 22, 2020.docdoc df8d09457a129b57c4740b237ac226b0e0245d035dc20930563bab681e98e8c9n/aHeodo
2020-08-21invoices 6683 & 2382.docdoc 43057d3c74a6fbe3be2660879e861ae3d0b2118866abb1e3fe8bc169c526d957n/aHeodo
2020-08-21Inv_75487.docdoc 214116ae52ad96af88fa41e0ea271fecb493e2afbc403bc3ca2c184ffd03d996Virustotal results 32.76%Heodo
2020-08-21K3 invoicing.docdoc d594bcea91f0259160c0122a56ad8ec4a7896173295fb3b2c197781cb1bbfddcn/aHeodo
2020-08-21invoice #68015.docdoc 83e013279f45dc89d5efc3717634b746a611baee472756272e91e1673d8fc3efVirustotal results 32.14%Heodo
2020-08-210549855.docdoc b43df5c0df066a651a976b156ca480e58acf3b61caeb45c08fadfcdb82e46addVirustotal results 31.58%Heodo
2020-08-21009640811.docdoc b79c89f1882c609b4abca4db5b83aace234943227d1cc9c3624f1f063d348e41Virustotal results 26.32%Heodo
2020-08-21invoice #552213.docdoc a99b807165ca13d9f9b50acacbb5c81c8e155e9347c5ff01cee84f4f19806a22Virustotal results 22.41%Heodo
2020-08-21Payment.docdoc 7f2c8c4b7894e6d7e260f4f48034312a7fb96c9728c9c9fe0e4afd9866daabf3n/aHeodo
2020-08-21H3140846341UU.docdoc 3e4b8326cfd9bfaeb2956b955bf3644032eb675cfd32a6284f371b2d6f68a47bVirustotal results 22.81%Heodo
2020-08-21Payment.docdoc 69eab92915bca8074c0e4c4a14a6d4532a6d4162923b7c51799ae872c647ee21Virustotal results 21.05%Heodo
2020-08-21Electronic form.docdoc 403c11dfcd14c01cf91b6fc45cb7ef0a55919e8e5e0292399e1cbe734bb9d2a3n/aHeodo
2020-08-21August invoice.docdoc f31012ac78ab2a6de1fdb75aed9cee6eb69e6222f724303a66da51fe0c29cd0en/aHeodo
2020-08-21DC-080120 QIYQ-082120.docdoc ebf536cc3ab147667e77823b5feaa2f72da1042d653ad11a26298800a7a86d77n/aHeodo
2020-08-21invoice.docdoc 4da5e980866878da930be670800361fd6b9b6ec73983dd60cdba9eb29bd09ab6Virustotal results 22.03%Heodo