URLhaus Database

You are currently viewing the URLhaus database entry for http://viraloptions.com/0/FILE/339528/iiga2fl-000731231/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:440657
URL: http://viraloptions.com/0/FILE/339528/iiga2fl-000731231/
URL Status:Offline
Host: viraloptions.com
Date added:2020-08-25 02:52:09 UTC
Last online:2020-08-25 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-25 02:54:02 UTC to abuse{at}host1plus[dot]com)
Takedown time:3 hours, 14 minutes Good (down since 2020-08-25 06:08:40 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-25August Invoice.docdoc 435b10a98117c736e7fdd9b952f601b191966c18f3b3b3fd8c6ba07d0fede4ecn/aHeodo
2020-08-25invoice.docdoc 2f592ecaa8c275325a929f046ce7a1ee3103f415010da820da8f1fa255ede01cn/aHeodo
2020-08-25August invoice.docdoc c90dca9fe4de4f5ca7600ef9f3839ef037ffc834481313642a2893d26d97b49fVirustotal results 42.37%Heodo
2020-08-25form.docdoc 3ec9b1ad13e150dbaa252c498499665a993728f63d9f243fc71f6d564b18e684Virustotal results 42.37%Heodo
2020-08-25YH-080120 HJWB-082520.docdoc 661afae9cedb766f0717b71057f1e5ed0e6196f949dfc7c2d44224f77b6e42e4n/aHeodo
2020-08-251283433.docdoc 0ec54a3de74b2ce33a52e61dd413cd982256f6ebd129aec2eb96f88422c75c28Virustotal results 42.11%Heodo
2020-08-25Form - Aug 25, 2020.docdoc 41a664685a5b717edfd22f809d6d17fb7dfe646b4a5c27087f94b05ad5da7df5Virustotal results 40.68%Heodo
2020-08-25Electronic form.docdoc 61814b42da2c11035f8c0707be022bc67ef8598918c9c9d1bf890e4e7b07cf7cVirustotal results 44.07%Heodo
2020-08-25Payment status.docdoc b28d94f0a4f1561b6fb8a5797ab538946130854ca70f61cd41ee6ac742898af7Virustotal results 41.38%Heodo
2020-08-25invoice.docdoc 3d5befca940c74791b04702d160818375925273dcb1a343e05bbe3687dc17a51Virustotal results 38.98%Heodo
2020-08-25RQ05 invoicing.docdoc 06ada13b3b4ed1fafd3c2f9121a778788cb8a03e98081fedd83ecbd2580435f5Virustotal results 39.66%Heodo
2020-08-25IA083 invoicing.docdoc 8922ae3c34b7cadb942c67f78b3ca4d847f3819baccc6c755fa30030d2876a0fVirustotal results 38.98%Heodo