URLhaus Database

You are currently viewing the URLhaus database entry for http://hvatator.ru/2222LR/identity/US/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:44070
URL: http://hvatator.ru/2222LR/identity/US/
URL Status:Offline
Host: hvatator.ru
Date added:2018-08-17 18:41:04 UTC
Last online:2018-09-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JayTHL
Abuse complaint sent (?): Yes (2018-09-07 11:36:29 UTC to ip-box{at}ripn[dot]net)
Takedown time:14 days, 20 hours, 27 minutes Bad (down since 2018-09-22 08:03:41 UTC)
Tags:heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-18SWIFT #12RD.docdoc 0855da5a6db49a1d2043493d292f3282845b92d4b1d4f6c55eea9026cfcda488n/a Heodo
2018-08-18SWIFT #7312877UTI.docdoc 970f1af3ec3615ca7e7e61d06c4aa5d6974198e2c07aa0010cbcb65af8d16853n/a Heodo
2018-08-18PAY #10704UHZQFT.docdoc 0e3951537523d4da40702893fb2004840cd9c855ebec1f657e46e9e2d66383fbn/a Heodo
2018-08-18SEP #1R.docdoc 8405dc7cd79bb8de81295bb3b75a17b0797f0cda2b46f6b0f08738adb1c9d594n/a Heodo
2018-08-18SWIFT #4KKB.docdoc 54279b6bd022f238cf0ed29e236d1801ba9a64326cf273713a1ae27f3f5b3269n/a Heodo
2018-08-18PAY #88URTUGPPA.docdoc e3eabb11ef2ce3a6dbb7826d3c38ee54ac0d3db70d849fdbd47786572459db53Virustotal results 37.29% Heodo
2018-08-18SWIFT #83127DFBZVZRF.docdoc d466eb7d6035d5bcb92a7b8c6b71e2448eb1d85c7ba9e66de519499f8b11d32dn/a Heodo
2018-08-18PAYROLL #9158471BTBAYWL.docdoc db78b33143934e4f5dfbe4104ecb388b92f490f97ae5616b5ac3097fb24e1082Virustotal results 26.67% Heodo
2018-08-18PAYMENT #12532YFV.docdoc 5d16f44d3de9995ed89b911658aab0511dcd834244b4cff9825354d97324ec0cVirustotal results 25.00% Heodo
2018-08-18SWIFT #07047KBGJTTWR.docdoc 31fc0494c40e707a95f6ba25a3f2c82c47b38a9462d571d01bbd02d49ca484d7Virustotal results 30.00% Heodo
2018-08-18PAY #8731846XOJAC.docdoc 27887246a409840588235756ceb841fb9b1c20078fab309a57438ca4e19b590eVirustotal results 25.00% Heodo
2018-08-18BIZ #10HXQOF.docdoc 675bcc0d81696e4661fc4aae7310b85f0f82b4636116851f7402daee90cf001aVirustotal results 25.00% Heodo
2018-08-18PAYMENT #2458281I.docdoc 62e7df7fc67b12f92826314df862cb9752dfe4922c7d7aa78b19a22940ec9778Virustotal results 27.12% Heodo
2018-08-18BIZ #469JCWCLUJ.docdoc 4bf6eef7bfbdbe861459ddd5171dba22602893ceb008858a832d484c0482fdd8Virustotal results 26.67% Heodo
2018-08-17PAY #28489IZPABVG.docdoc 6f5f0dd15c6de0b64cccfae94c453553aba1baab6845b2d6af9a0d76842c40d8Virustotal results 25.42% Heodo
2018-08-17PAYROLL #07ILTNHCDA.docdoc dc0f2a0c3bdf278cc25e0208130623ce987476b5566c4dc4a6ee66522a100e65Virustotal results 23.33% Heodo
2018-08-17PAY #15137HTZ.docdoc f6d4fe4cdd98c36471e7904e2dea5ad3e3d78d7232fedbb60c90d53d011fb894Virustotal results 22.03% Heodo
2018-08-17PAY #33649RGXOC.docdoc c9bfe8b62a99f0fc27d1d1cabcc278285f056d201ff37dcf789fd4e0c7af4c31Virustotal results 38.33% Heodo