URLhaus Database

You are currently viewing the URLhaus database entry for http://olsenelectric.com/2GDULZ/BIZ/US which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:44042
URL: http://olsenelectric.com/2GDULZ/BIZ/US
URL Status:Offline
Host: olsenelectric.com
Date added:2018-08-17 13:37:58 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?):No
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-18SWIFT #443LEIEYOLG.docdoc b27761b32ab8942b529d876e3b355d3991e30c4fd5bce14889f5ca1bf3b1ce10Virustotal results 30.00% Heodo
2018-08-18PAYMENT #4GMELYE.docdoc 0e3951537523d4da40702893fb2004840cd9c855ebec1f657e46e9e2d66383fbn/a Heodo
2018-08-18PAYMENT #2668DANQPXJ.docdoc 95abb9ecb1e12aa0394be7313ac0ca07cd62450152d462630900d39b6527b12dn/a Heodo
2018-08-18PAYROLL #8399RSDOBXXV.docdoc 54279b6bd022f238cf0ed29e236d1801ba9a64326cf273713a1ae27f3f5b3269n/a Heodo
2018-08-18SWIFT #1912539FB.docdoc e3eabb11ef2ce3a6dbb7826d3c38ee54ac0d3db70d849fdbd47786572459db53Virustotal results 37.29% Heodo
2018-08-18PAYMENT #24VKLWP.docdoc d466eb7d6035d5bcb92a7b8c6b71e2448eb1d85c7ba9e66de519499f8b11d32dn/a Heodo
2018-08-18SWIFT #15459XXSXJ.docdoc db78b33143934e4f5dfbe4104ecb388b92f490f97ae5616b5ac3097fb24e1082Virustotal results 26.67% Heodo
2018-08-18SEP #86655CBHRC.docdoc 5d16f44d3de9995ed89b911658aab0511dcd834244b4cff9825354d97324ec0cVirustotal results 25.00% Heodo
2018-08-18SWIFT #514RTJUKIQP.docdoc b9d3cb69e6d91ad91ba15ba9bb5cce0f43e29de98ae524a94612e829a5cc1822Virustotal results 28.33% Heodo
2018-08-18PAYMENT #295RVV.docdoc 27887246a409840588235756ceb841fb9b1c20078fab309a57438ca4e19b590eVirustotal results 25.00% Heodo
2018-08-18PAYMENT #561062BI.docdoc 63a1a968f6e2d9248535c59f95f14429d012ae95eae2a8b445e23b69bf74fb05Virustotal results 23.73% Heodo
2018-08-18SWIFT #900945Y.docdoc 05ffd1ab139da8d53e13eedac3b6d5a2a50e7278fada4df5aee81f76e5028fedn/a Heodo
2018-08-17PAYMENT #026877TL.docdoc 31fc0494c40e707a95f6ba25a3f2c82c47b38a9462d571d01bbd02d49ca484d7Virustotal results 25.00% Heodo
2018-08-17PAYMENT #2W.docdoc 500b5b69e515d684d7dddc8d259df07ae3e002f080bdb8695d14f1959ddc359cVirustotal results 25.00% Heodo
2018-08-17PAYMENT #27VTKI.docdoc 6c0ad95ff0ca60b5ea899f7aa3a42bde568073266c33f094f6d28ad509603a6cVirustotal results 23.33% Heodo
2018-08-17BIZ #842YBWJAB.docdoc 95e6eea2291316ab08563ad8c8ec79dcc933ccd83bf533c524d1edf942be8209n/a Heodo
2018-08-17PAYROLL #8785744PJBL.docdoc 264d6cb2780d367c7fd58f3b4a93d45fd97ce6f5c9801a8d3a2c21fafa57883cVirustotal results 38.33% Heodo
2018-08-17BIZ #34SGY.docdoc ee1a0915b663ccec62b420fd046c6c17e1652780d25f593f52f9d61d3ac25ac7n/a Heodo