URLhaus Database

You are currently viewing the URLhaus database entry for http://omegahelp.net/tom/browse/545j6j7/znmrb91363874350bwrxvtnejoeaewgeesjiz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:441014
URL: http://omegahelp.net/tom/browse/545j6j7/znmrb91363874350bwrxvtnejoeaewgeesjiz/
URL Status:Offline
Host: omegahelp.net
Date added:2020-08-25 14:40:07 UTC
Last online:2020-08-28 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002891560 created on 2020-08-25 14:42:06 UTC)
Takedown time:3 days, 0 hours, 33 minutes Bad (down since 2020-08-28 15:15:45 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27BAL_PO_08272020EX.docdoc 72a047a55409445c1767467b0e67391b0fbdb99be5b2e6a5457df52c7e2ef398Virustotal results 38.60%Heodo
2020-08-27G_EK4208729886KO.docdoc 442c6c1b3552629189583ebf544309cedac07108c44417b823a74dcda644cd8aVirustotal results 37.29%Heodo
2020-08-27I_00208979.docdoc c0a1d4e96315001e0292c2ffe0e419d82b8f88cb9e8a5cf1b9483c8fa8d2a511n/aHeodo
2020-08-27000C3G8PVF.docdoc 1de15c9ed545a45fd0d8427d1ecb434fa6f59d9efbb91236202a73b806f0d1ebVirustotal results 36.21%Heodo
2020-08-27SD3373689836ZR.docdoc bdf2b4b3cdc18737c4bac36e0f0d212c7d58bce68675bc8bc1ff74984e534913Virustotal results 30.51%Heodo
2020-08-27BAL_PO_08272020EX.docdoc 53c00dce9f2c52d3c86f5dd33d1554478edd1f1fa7f4c1e0d538c2b0e11cb049Virustotal results 31.03%Heodo
2020-08-27BCFM_NHM6K953NQ4L.docdoc bf913198774af473c451fa304746ed1434412a8f1c7706b2e5f12c6cf1827249Virustotal results 28.81%Heodo
2020-08-275220746666305530.docdoc 854e81fb831b2bfca0c213488fed462224e10dcdc68e0f48c0d5061f53064454Virustotal results 29.31%Heodo
2020-08-27BAL_74108813.docdoc 991d1c5d354ae5640d55186accbd371791d03c05853b380edcd80ba40e515861n/aHeodo
2020-08-27RYPW_MTZ_080120_QCM_082720.docdoc 38923432e3f3c288a95ad269e276d83fc311457e325def95858c499997a5e00en/aHeodo
2020-08-27FICO_PO_08272020EX.docdoc 6fd8df41a454fd5cd94079282364950f554b86e679c9ef87ff59d082afd47f8cVirustotal results 29.31%Heodo
2020-08-27INV_CK3149864059RZ.docdoc 8b1e85e899250ae238664c29df61c908610d31299f75ab0da17ab24d8e89725eVirustotal results 29.31%Heodo
2020-08-27MZD_080120_TSS_082720.docdoc 92edabdfafbef478611378e867cb3f462fa7f5ac106a8f0d5045627d04c4c00fVirustotal results 29.31%Heodo
2020-08-27INV_70853180.docdoc 151815029e695cd4af22c16d6eb0aa00c3ad74ba422c20d22e9bedf220485490Virustotal results 28.33%Heodo
2020-08-27PO_08272020EX.docdoc 3599cbdbe9bf9bc3a8a824fe0b4df98018df67b9c07cbaafa6331c4fdb68208bVirustotal results 28.81%Heodo
2020-08-27KYC_080120_BCS_082720.docdoc 6f5d563d229dc97a5c6f0cfdcb4da16991f16b2209818b717c7495a42859d7d8Virustotal results 28.81%Heodo
2020-08-27LBT_080120_TZK_082720.docdoc c9bf4b4a386bfcde7c1072c3c00f1d708885dc202c1472658b0ef712f39d7867Virustotal results 27.59%Heodo
2020-08-27BPXO_PO_08272020EX.docdoc 20c3a7be51f8040c61c0e273bbb24b48baa3591f42ceeed30a1feb5915b085ccVirustotal results 28.07%Heodo
2020-08-27INV_45975425448552881390.docdoc 27dd928df3b326d25154ccfe5219d7343d48e5d73d6b04f5697d0b2b889da4bcVirustotal results 30.51%Heodo
2020-08-27HW_DZW_080120_JXG_082720.docdoc 93119253f1efad2c20d3a96b3298fd4188c306d45adb0d544c895225e276908bVirustotal results 29.31%Heodo
2020-08-2730486248.docdoc e145b5be039742a0b89435111a34036fd1d0316c27f2ad4781450cc43073dd5eVirustotal results 29.82%Heodo
2020-08-279957454671.docdoc 4b21ed50ed79a420217fa1a72731b1a30d251a06141cd56f00a0fdd17ee11493Virustotal results 29.82%Heodo
2020-08-27J_PO_08272020EX.docdoc 00dbd35594b633c02429ab2154dab2e2b19e93caa9322d5ef46b2c730d6af123Virustotal results 29.31%Heodo
2020-08-27GDKV_PO_08272020EX.docdoc 41213a4adcc07029d82e0c00a9932eb28ea7e5c9a41934e40ee35de060f8ecfcVirustotal results 30.36%Heodo
2020-08-27HOX_080120_VJD_082720.docdoc b13b6fb044972063fee5a633ab2c88e75a1e7201427b25f21be5ba73dbac82afVirustotal results 55.00%Heodo
2020-08-27BRL_080120_GCB_082720.docdoc 418cc4b29a2f7c05861556be1785c3b31dc530a4042c65c36253adb162a34d7bVirustotal results 54.24%Heodo
2020-08-2772997928.docdoc ccd219a6f531ed3f9ff84a1ce8e664e71c3dcc4af09fe196889fe1e1b69ed956Virustotal results 31.03%Heodo
2020-08-27INV_NKV_080120_KPG_082720.docdoc 39af19338e24f5fcea02d5777af1f45eef1669e7834311632f223524b7e773c4Virustotal results 55.00%Heodo
2020-08-27FIU_36799312123922222159647.docdoc 04d53867d9a85922c8e95c2c5ac2e27ba3c75ec87d1ceadc4ba5b065e4b51c96Virustotal results 31.03% Heodo
2020-08-27BAL_2UUP79ZD.docdoc eff311d3b50ec2d22d39013b7c24123c3720782dd02375e8c95f5b873c78c71bVirustotal results 31.03%Heodo
2020-08-27BAL_047463848018641343.docdoc 16d6be55ee176b177950348259b45429b0337137e64ff4f1584f44e6efa449b0Virustotal results 31.58%Heodo
2020-08-27INV_Q52ETZ8RGWOFC.docdoc 4e78ff2d8f46718a5e53083c2f96401ea3e1174f112b70c741448aad402b9132Virustotal results 31.03%Heodo
2020-08-27REP_1DRT89R3XD.docdoc 9284c7e6b91850c02fecc222938859e5545d62484b7d969c48c182c17b4e328bVirustotal results 30.51%Heodo
2020-08-27C_PO_08272020EX.docdoc d30dd5e885a79fb037d8a45fbc54cdfc8a4d0186cdb5f1cad6e3554458a5c69aVirustotal results 32.14%Heodo
2020-08-27YDOL8ED8O0.docdoc 5e2acb078bf706a90389d90636ddaf5d332c47325336781c2ab14600e34adb05Virustotal results 31.58%Heodo
2020-08-27PO_08272020EX.docdoc d20d5bab876240cbf908d60dc4ac87b57258f02fbd9202d50733891f22d29592Virustotal results 30.51%Heodo
2020-08-27PO_08272020EX.docdoc 3dc40e9a60c8557b94a21581a58c4566273a45eef074c0fc78b62bf39eadf667Virustotal results 30.51%Heodo
2020-08-27SX_YI6489146219SA.docdoc 4ce815a9423e52b38ceedc5af97bd2f02672b7ffde760730599452b87050eb7bVirustotal results 32.14%Heodo
2020-08-27FILE_V051FI5OMUWLC3O.docdoc 5106dc79c277efaea0994fbff2d9683e1a6cb42184857e27a7fd36ef275026f9Virustotal results 30.51%Heodo
2020-08-27FILE_11213890.docdoc c2da9f1e760b2054a7244c442736269184220a1e7639e186f9eb4022ed7dba3dVirustotal results 30.51%Heodo
2020-08-27INV_PO_08272020EX.docdoc 898606ce53cb944570ef3226fed74c7f3d6cfab92352cacf96d3a190cb045145Virustotal results 31.03%Heodo
2020-08-27REP_400W7448.docdoc cd0f5f2cc1f1f1bc7dc7bb9fe38aed374ad228315804fa2a759639ab42a35d89Virustotal results 32.76%Heodo
2020-08-27KKH_LLA_080120_XHW_082720.docdoc d8b2892cb235a6a574651012133c78ab0928fdd3ce752cc0699681a373778c04Virustotal results 28.33%Heodo
2020-08-26MOVK_34015045.docdoc 538f09c0b0e7a2ad7a2238635d7e136726a91b996a98d144ebe8a8b3b70fda38Virustotal results 30.51%Heodo
2020-08-26INV_7QYZ1WIUAZA37.docdoc 969ce710e1eab7279ae63b1556e1913a3db4dddefddc28803789fdb9b880e1c7Virustotal results 30.51%Heodo
2020-08-26DOC_PO_08272020EX.docdoc 91a308c86bae5259dbb93a07177c2302aec9aa1d99efb3aebcf38eeec736806eVirustotal results 30.51%Heodo
2020-08-26UA2020401766SD.docdoc bf3d5149b15fa4399dfadac2556d328a9707b9332e9f063dae1d4c90e36c480aVirustotal results 30.51%Heodo
2020-08-26INV_MNP_080120_YVK_082720.docdoc 48d23f9dd578db5e9182540eb52090352d60ee4c49698de167f1273e4e22e449Virustotal results 30.51%Heodo
2020-08-26FILE_76974446.docdoc 55d5759159806913f0fc3cc9e68b4f8a8a22968181d6a6edc64dcdf698110b70Virustotal results 29.82%Heodo
2020-08-26S8GD71C589MP.docdoc d6f8e60e80e4142bd6e6c2162f5b44596f03cf98b415d29a0099e3462bc60dc1Virustotal results 32.76%Heodo
2020-08-2655093265.docdoc 7fe66f85659a10160846a834f8b4befde4e554e2c6e6586097218eed58c96790n/aHeodo
2020-08-262RVTCYI8CBX.docdoc f80629914c9555da3d9e7caf2082092d7898f702397f8fbb4a5ab84da12633f3Virustotal results 31.03%Heodo
2020-08-26FILE_BX4544156382GS.docdoc 7e6ae0bfbd08090276dc8821dbac500fae364dab68dad84b1fc2c4d971080dccVirustotal results 31.58%Heodo
2020-08-26JDP_080120_BMC_082620.docdoc c63d0a1da663784ca7f4cece401282c716aa51b606e8298350c1fd4807cb4613Virustotal results 27.59%Heodo
2020-08-26DOC_5151811942231639251.docdoc 39fffa400541356137e91075849e49947cd4864baeeacbc328e6aa73f52ef4fcVirustotal results 33.33%Heodo
2020-08-2618365959.docdoc de6eef8f559ed20487bd721dbd7d2d2c26871567abca7c8ed929e8a16a3be992Virustotal results 32.76%Heodo
2020-08-26N_RN9466539420KZ.docdoc 0f2cb825f2ae6121c1d0df8ca0ef470ee20e0ec764837f22cf112e4097c3e1a0n/aHeodo
2020-08-26TCF_94384683.docdoc dd471711916613ac1e38ee1a757f5b743a522d49535d62096de0d3f248c5465eVirustotal results 31.03%Heodo
2020-08-26D_GM4383148328IR.docdoc 0a953f644228683e0bb38596c85648caed8360f40e81ef42897acc1e50292392Virustotal results 32.20%Heodo
2020-08-26LZI_GGY_080120_SQG_082620.docdoc 6172691b40af326e4401a41208b54f047786ccc000cabda70b3afc6a0d434278n/aHeodo
2020-08-26DOC_24814936.docdoc 230ab4fa2ef9855a13c29c152fc59b6de56233f75e523a408a709175c7b68953Virustotal results 29.82%Heodo
2020-08-26W_6ULSWJF.docdoc 45bf1064efa2a04f4bed2c8f62d414e6fa68f63c92672c6438fb27c9dcf53d9bVirustotal results 29.31%Heodo
2020-08-26VMB_080120_EOE_082620.docdoc a40b452daaaef1e757d3c55171fdbefcbfaa8342757d2037b3eb3e451f292008n/aHeodo
2020-08-26BAL_XGFZ3HS.docdoc e7e9a708f2e5bff9d190fff614117ebbea1b47bb4429c7d13a0451ad35706136Virustotal results 29.31%Heodo
2020-08-26DOC_YPO_080120_VLB_082620.docdoc 676c878bed2e541c7e1adcbb0f141462e8f98125e82ff705dcda881165585452n/aHeodo
2020-08-26OWB_080120_DNB_082620.docdoc 16ba108b19b54a215fdffb4ada0bf198814e65190ae73a686c300bdfb5eb2ab6n/aHeodo
2020-08-26ZYC_PO_08262020EX.docdoc 0fb8cdd6e033deca3e95931c9f20ddab1df2d839911cb271774ae42cf5460094Virustotal results 28.81%Heodo
2020-08-26WO_UQROWAL1OY.docdoc 673dfbd1e8a6cae6500c6bc52686bc69101e89a34d4f579b1f3b5a45174ef250Virustotal results 28.81%Heodo
2020-08-26INV_BN2127733390TT.docdoc 0c22f0ad057fa28d31a047a34391f1275438a034d1c42d951637ee89c5252d24Virustotal results 28.57%Heodo
2020-08-26VOC_080120_BDF_082620.docdoc c2e51843833af341e0041af71442fb6dfb6991c35fb6a54ad3e2e23fbd3d691dVirustotal results 27.59%Heodo
2020-08-26I_PO_08262020EX.docdoc e14c5eae5d7ce85445fc7463becfb3896307625e246e3b97df5def0501570eedVirustotal results 28.07%Heodo
2020-08-26INV_34954716.docdoc 66d9e9f340163d1c3be2cc282e4b2871834a870392f970f4a1121da1c578b7d0Virustotal results 25.42%Heodo
2020-08-26DOC_RF4570683608TT.docdoc dea98698a907a95e646de347286e7bc23d8d095022a89d3e4dc22b1652eaabadn/aHeodo
2020-08-266564878458422607333.docdoc 300cf0fd3de72ba9c28fc5428b8fac05aa455c7d7ffffbf3ae72db863f7fec1eVirustotal results 29.82%Heodo
2020-08-26INV_PO_08262020EX.docdoc 40387fe6e6a66244dfe24e5e9f6f88ca7111c0331b4239de96114a8d3b9b2b63Virustotal results 29.31%Heodo
2020-08-26DOC_YNM427Q4.docdoc b8a9e11759f4c916ebdfad5cfab584cf315a1048647d699c994d6a7b60471781Virustotal results 29.31%Heodo
2020-08-26REP_PO_08262020EX.docdoc e2f93f504fd4eaf83abee9ba616dd2ff6264f7805737a5556899e37883c7cdc0Virustotal results 28.81%Heodo
2020-08-2592213787.docdoc 8fca1b7834abd4c497c08643e11210ec88d3dc33c3d75a94f72f2039b584bf94n/aHeodo
2020-08-25BAL_WLK_080120_XTV_082620.docdoc 966e05abf8db8638c7e4ca88db7b7943092c05b18f44597801128b6f7ba41254Virustotal results 29.31% Heodo
2020-08-25FILE_RG1866969954XE.docdoc 865d52edc31aa31b8287bf614e69b7641f1ee0acfaff1cc0f0f8fecaeab6db69n/aHeodo
2020-08-25J_59797794.docdoc b1ca916b92d165de27e73baa5354d6285de6d4fcfe95960c95a6b8ada54fd2fcn/aHeodo
2020-08-25FILE_96138709.docdoc 696268abaa7fca009d2d755c96a4aab42d5aa9d20f5e586480896798e975b44eVirustotal results 29.31%Heodo
2020-08-25BAL_80094149.docdoc 2b4bb20ea93c9f29faee954202acbeb0c854e447133aa1b04132b80e83961f1cn/aHeodo
2020-08-2546883715.docdoc 2eeec2892926e686de8fcc29fc57c57b10a4f37e49cee06ec4b5c864dcf5cfben/aHeodo
2020-08-25CMPT_YUT3VHB.docdoc c0bc03edcf17373ca7bcc145fddea1578f8998fb6f1d400d3701ebbe4ac1c833Virustotal results 29.31%Heodo
2020-08-25REP_IPE_080120_KPZ_082620.docdoc b7d31d0d2e6624c23fdf8a2c989875d78052e661f92c0839d379c4197a188415n/a Heodo
2020-08-25DOC_X115HOWMTNQ17IW1.docdoc f83ff86a7b80e435264d444c0bec91a81e09cbc5df01e1f2f155d3782e456eeaVirustotal results 31.03%Heodo
2020-08-25DOC_LKC_080120_PIG_082520.docdoc 96eef74c59d9b8b47979fbaf2552a9735dcddef28df0b5b87655a4c849f9d853n/a Heodo
2020-08-25BKJOSOOLDM.docdoc c83c6353d36706d9ede8b73d387db5ea74ea2977900f849d802d7cf17669c266n/aHeodo
2020-08-25REP_PB0148240456VF.docdoc ebf572465108b8645ca9637d9c17b4fe717d4d99f3d4dd29046a22a8f608bcebn/a Heodo
2020-08-25MY_HH1508336975JO.docdoc 263db302489a8ee87cd55bc7cdcd6853b02d39b711ec9a671afef6737154e2a3n/aHeodo
2020-08-259080146095849403390.docdoc 0afcf7a35acb62edb01ee3f2827626deac6bcb7f7cfc799a2f56132d916b571fn/aHeodo
2020-08-25INV_YW0609644188PE.docdoc 7cac6f200ebca1722e73de9a75c49af7370e59a87960f9ce3e36a52975a7b1bdVirustotal results 40.68%Heodo
2020-08-25N_CZI_080120_PHR_082520.docdoc c52d43a72bc36aa33659558cfb0788b7c919cf70f6d6c98be550891ce51556abVirustotal results 43.10%Heodo
2020-08-25F_23981732.docdoc f0842ff3c4163d604958e593b4b63b2519467663122da0e9cb70fbc0f4494e91n/aHeodo
2020-08-25HN7N5Q2T.docdoc 23b985aeba6423e4a9a4b3c2c30d057fbf0dd29f65d0700581a45b8276eae366Virustotal results 40.35%Heodo
2020-08-258XHDHIL3R8I4B.docdoc 5ea798c77e148ba56c705159bad7572cc32b08d35f1490759356a6d114d50a2dn/aHeodo
2020-08-25XU7968754147JV.docdoc 3dce2355e30fc9c2bcf1011d6e069107e0f65eef8e4b8dcab989ecdf8bc55407n/aHeodo
2020-08-25PO_08252020EX.docdoc 9e285624cad29ab6abc3514e6b6953d0ed47ca24c1cb8e7db97f1fa652a8766cn/a Heodo
2020-08-25X_40022108.docdoc 340c0a7bd1dea55284f43e599ed5afbb240cbe03d66e478ce327abac2358c230Virustotal results 32.20%Heodo
2020-08-25DOC_KM1043953487TA.docdoc b378fe416dfcb63d2ab446b973223719a1fc95e0a6e8e7131da3e65dbcec601an/aHeodo
2020-08-25FILE_DHY_080120_XLZ_082520.docdoc e06211b96198e300977ef5f59cf0badd6899b4e387a2b82068e4d0aea2b1d40dn/aHeodo
2020-08-2517447103.docdoc 10216de03866c86a163d074495bfd71636ac299c24a2c6f0d482a733a5582c62Virustotal results 29.31%Heodo