URLhaus Database

You are currently viewing the URLhaus database entry for http://locuspura.com/cgi-bin/open_array/external_cloud/b2q0x7qgq0_88u8x79/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438738
URL: http://locuspura.com/cgi-bin/open_array/external_cloud/b2q0x7qgq0_88u8x79/
URL Status:Offline
Host: locuspura.com
Date added:2020-08-21 22:06:16 UTC
Last online:2020-08-22 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 22:08:02 UTC to abuse{at}strato[dot]de)
Takedown time:15 hours, 47 minutes Good (down since 2020-08-22 13:55:40 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-22MES 20200822 PLD159.docdoc 19993ada17d417eac8d69e9ef6fff9bccbee9504f913f7b18414165b7cfdd964Virustotal results 50.85%Heodo
2020-08-22ARC 20200822 QUR483007.docdoc cc632bb864117c96ce9795a4077e0412d58358016ee1b15275bcca7c0bd368b7Virustotal results 36.21%Heodo
2020-08-22Mes-R155616.docdoc 2fea8b7f5754e42358ec1079c8f5995e1e733153af5101e3c786980aad17824dVirustotal results 53.45%Heodo
2020-08-22DAT 2020_08_22 54746.docdoc cd59c3570d89a3b5b8263e3beb294d4a87f3a1524d40f58e27d22b415db7b40fVirustotal results 36.21%Heodo
2020-08-22Inf VQ8600.docdoc f303289ccfa96ee597e4ed497e6aac8ca9ce382b04c40f5d17f21b63228ba66aVirustotal results 35.59%Heodo
2020-08-22arc 20200822 SZZ085523.docdoc 2f1fb6d0a8160b4201dd703dc1821a3476091a66a5fe04641aa80c9595342694Virustotal results 33.33%Heodo
2020-08-22inf 2020_08_22 GBN571097.docdoc 0a7181e539b268536df28fc63a82b43dfa50e94f794f246c2adf975042ad1384Virustotal results 40.68%Heodo
2020-08-22LIST DOX480380.docdoc 93517c3302157331caeed0ad1170abb2e5b16b1336fbb649fff15fd94a604b07Virustotal results 35.09%Heodo
2020-08-22mes.docdoc cbb9025406193f53d6b04ac2fe24f9273277d25df6b3e058d293ba8332908e89Virustotal results 35.09%Heodo
2020-08-22list-2020_08_22-QVF647943.docdoc 888576b006def3935c63b3044add14aff8f8a2f56a1a52592f895f1182d25ce6Virustotal results 38.98%Heodo
2020-08-22DAT_626.docdoc 41e117890931d05a1eaa233b22b71bd5de72311491f54ccd76c7141d37a2c2a8Virustotal results 34.48%Heodo
2020-08-22File MV9992.docdoc eb03beecb5dbcd12f2191ec6980a4b9abb56b43907f1bff900378a80daa3699aVirustotal results 35.09%Heodo
2020-08-22mes 2020_08_22 G8759.docdoc 7e23b5d1c6802917ef79115b4b1a242be7cd7465aa52247ae9d01092bcb49da1Virustotal results 34.48%Heodo
2020-08-22Dat 20200822 4779.docdoc 46821d694a7c94efbd9aa8cf863377946de88c036c813decd85ed3cd8bfb6cdeVirustotal results 34.48%Heodo
2020-08-22list-2020_08_22-54018.docdoc 4cd4ea7314c2268401c1395af0e562dcb530b081eb42c55152e03990a62bc4eaVirustotal results 34.48%Heodo
2020-08-22Inf-20200822-8419.docdoc 037b8124330acc05c14aeec4da5dd741dfc43260dbd62df806d84fb370ed3416Virustotal results 38.98%Heodo
2020-08-22arc 20200822.docdoc 90e7e0a921f7805d5392b6725349de6ed30c7a234187790c6579d8cc240ebce2Virustotal results 34.48%Heodo
2020-08-22ARC 2020_08_22 VR635551.docdoc 9171991027c772e7f4a0461492ca9a074c828f0647d3fb993b0b370dd233fd2fVirustotal results 40.00%Heodo
2020-08-22FILE-2020_08_22-6250322.docdoc bf613424225d5260ce91473ce6ebfe8adceb0588ea8fd5bb613437a9ce55f5cbVirustotal results 34.48%Heodo
2020-08-22File-2020_08_22-I560730.docdoc 9c6e241a9a90edac415dda654252a69fb56e32a5f9894dc1e0e44f8d02e56d2aVirustotal results 37.93%Heodo
2020-08-22REP 107636.docdoc e57d599086e79ba7f1f77e0a2feed6facfad3c7b3d142c75c2608906fdc6656cVirustotal results 33.90%Heodo
2020-08-22ARC_Y85943.docdoc 48a7604dcb51f7fc9e0bc37a40f2c7dcde23bbbacf719ae5494c9ed2c795a27aVirustotal results 39.66%Heodo
2020-08-22Arc_20200822_JOV860187.docdoc 17d1a183b329a542e212c99216bfbc17c5abd835093634f262e79e38dbb61be8Virustotal results 35.00%Heodo
2020-08-21ARC.docdoc f3910c447952615a78e47e19bb4d3f313f015a74e603c83b15fbe812d5437d4cVirustotal results 34.48%Heodo
2020-08-21Inf_2020_08_22_T63750.docdoc 44be463c465e4e229df4dcea734d505a424cb65601ccdcd1348117882ad9038cn/aHeodo
2020-08-21Doc.docdoc e2e7f4b11f11f2af066278c55e5cca8fb8e9e9c9f3bcebea7b72b4c6e938cf4dn/aHeodo
2020-08-21File 91212.docdoc bf674967afe4c840338de636d94e0808463b9786fdcb2161515d63e333f4bf56n/aHeodo
2020-08-21MES-20200822-NA40891.docdoc e41c9acb24c7dbffbe881b62867bf6c7e1ee5c151509f7fa14b4004d0db184aan/aHeodo
2020-08-21list_20200822_4440.docdoc 410274b2ca31ea3142f4fb91817422ccc1ca62617732458298145fae6d740559Virustotal results 35.09%Heodo
2020-08-21inf 2020_08_22 5476.docdoc a8c50cfa1146130af0f5fb5225f6ee606553cd2e869a7b0d4f3523bf464fd3acVirustotal results 34.48%Heodo
2020-08-21LIST 30613.docdoc 605a94a5d882c71dfe00f46a2f2206f95436ec9be3be78d13a2828dcd55a3935n/aHeodo