URLhaus Database

You are currently viewing the URLhaus database entry for http://zurfluh.net/PDF/balance/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:444026
URL: http://zurfluh.net/PDF/balance/
URL Status:Offline
Host: zurfluh.net
Date added:2020-08-25 23:26:07 UTC
Last online:2020-08-26 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-25 23:28:03 UTC to abuse{at}newtekone[dot]com)
Takedown time:23 hours, 20 minutes Good (down since 2020-08-26 22:48:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-26INV_36561611259.docdoc c1010a64991ed1fa9519bd2ff0ee0abc2b87853d34efd4a6c2e3f6a7b4fbaa75Virustotal results 30.51%Heodo
2020-08-26BAL_03285717.docdoc bf3d5149b15fa4399dfadac2556d328a9707b9332e9f063dae1d4c90e36c480aVirustotal results 30.51%Heodo
2020-08-26DOC_KEY_080120_YIT_082720.docdoc 48d23f9dd578db5e9182540eb52090352d60ee4c49698de167f1273e4e22e449Virustotal results 30.51%Heodo
2020-08-26INV_PO_08272020EX.docdoc 4e48203902e2971b1f0046c8b0e664760e818aad6c055903981a67549c91eab6Virustotal results 32.20%Heodo
2020-08-26INV_PO_08262020EX.docdoc d30dd5e885a79fb037d8a45fbc54cdfc8a4d0186cdb5f1cad6e3554458a5c69aVirustotal results 30.51%Heodo
2020-08-26REP_68193556683913958519943.docdoc d6f8e60e80e4142bd6e6c2162f5b44596f03cf98b415d29a0099e3462bc60dc1Virustotal results 32.76%Heodo
2020-08-26REP_83493472.docdoc 5106dc79c277efaea0994fbff2d9683e1a6cb42184857e27a7fd36ef275026f9Virustotal results 30.51%Heodo
2020-08-26DOC_72641714.docdoc 65d504b93571392cb6513b7fa5bed4bdd2a2ae7e3d7666e409f0b13e56f1e314Virustotal results 30.00%Heodo
2020-08-261447447697194.docdoc adcff3f1b60e737879478f5ffe1450906166be8f4b197343ea2684bcb11d1f1bVirustotal results 30.51%Heodo
2020-08-26KOU_PO_08262020EX.docdoc c63d0a1da663784ca7f4cece401282c716aa51b606e8298350c1fd4807cb4613Virustotal results 27.59%Heodo
2020-08-26INV_68945861913.docdoc 39fffa400541356137e91075849e49947cd4864baeeacbc328e6aa73f52ef4fcVirustotal results 33.33%Heodo
2020-08-2653981354.docdoc de6eef8f559ed20487bd721dbd7d2d2c26871567abca7c8ed929e8a16a3be992n/aHeodo
2020-08-26DOC_PO_08262020EX.docdoc f704c7aea8849d0ae729aa1436b9590e92291e62204821e5d7550db4c49b2c1dVirustotal results 32.76%Heodo
2020-08-26FILE_30640071.docdoc 09e6e19b4d2f660e0c19d8409c453f633dee0d483be92c0d795d00c6ed0f1cf0Virustotal results 32.76%Heodo
2020-08-26IQ5451969098NJ.docdoc 73bd8ccbf6c6ab32472c5784a7979a150437174459c01a7398945c2867eea506Virustotal results 32.76%Heodo
2020-08-26REP_UKFS5N8DG.docdoc af5e077f1915828d85cb8b2e854ac2c634e10cd249bc9ca36bfdce6210a78289Virustotal results 30.00%Heodo
2020-08-26ED_MGN_080120_NYE_082620.docdoc 230ab4fa2ef9855a13c29c152fc59b6de56233f75e523a408a709175c7b68953Virustotal results 29.82%Heodo
2020-08-26IROA_XBF_080120_DGD_082620.docdoc 45bf1064efa2a04f4bed2c8f62d414e6fa68f63c92672c6438fb27c9dcf53d9bVirustotal results 29.31%Heodo
2020-08-26KJWU39MCRMP91OZ1.docdoc a431f7a715ae2294f803abd31c677aceded29507e07a580ed361bdb73c8ebf3fVirustotal results 29.31%Heodo
2020-08-26BAL_HOL_080120_VTE_082620.docdoc a356e5e255cba02c8e3e973edcf986a20bff8764ba83a2bb53b55dba03d5529cn/aHeodo
2020-08-26M9TTAYQ7ELQ5O.docdoc 5bb2d9a1cccac6473be88f29607cf03906957bce32e053883f1461be084fb439n/aHeodo
2020-08-26NM0881601421EO.docdoc 16ba108b19b54a215fdffb4ada0bf198814e65190ae73a686c300bdfb5eb2ab6n/aHeodo
2020-08-26FILE_RMXYHBUN45.docdoc 0fb8cdd6e033deca3e95931c9f20ddab1df2d839911cb271774ae42cf5460094Virustotal results 28.81%Heodo
2020-08-26T_09706073.docdoc 673dfbd1e8a6cae6500c6bc52686bc69101e89a34d4f579b1f3b5a45174ef250n/aHeodo
2020-08-26BAL_9XZPUU9OT.docdoc fc8d4d45930f6975b843b9efc608897012e01b772d88025fc4d2762e24802adbVirustotal results 27.12%Heodo
2020-08-26INV_PO_08262020EX.docdoc dc167ca9c82110cbd8c275bde50770d2cda4d232986e4018107994b92009862cVirustotal results 27.59%Heodo
2020-08-26REP_YUX_080120_ZBU_082620.docdoc 92ec3d4c98f50093628224f537985cfb37e32143818fed1d9f96aead95d6bf61Virustotal results 28.07%Heodo
2020-08-26PO_08262020EX.docdoc 0322eae38619df582bc680d8fbde3a8a8f4b9e2c02b689db2d863c62f88c559aVirustotal results 26.32%Heodo
2020-08-26652163087.docdoc 9997c20c3de08d0e953e96b71964a91541de79d10d355506c06c65cbcb92dc53n/aHeodo
2020-08-26REP_QU4762472891YV.docdoc 300cf0fd3de72ba9c28fc5428b8fac05aa455c7d7ffffbf3ae72db863f7fec1eVirustotal results 29.82%Heodo
2020-08-26FILE_PO_08262020EX.docdoc 45f3d708478cd8e94ed0efa61d005fe07c3a6b3bf0c83e532e7714a6c8eaf529n/aHeodo
2020-08-26BAL_11714950016846403322178.docdoc 4bd3f235dddaf5272d64b7eac130efd338f7ce76a1e6de67054f79d5a859bd83n/aHeodo
2020-08-26KUQ_080120_KNM_082620.docdoc 861a91133536133ea84bc5713b33210804439902c0f6f0fad1c38346c7b6f22cVirustotal results 29.82%Heodo
2020-08-25FILE_OFW_080120_GSX_082620.docdoc 86b0083e2d041b94f517ccf38d1df2c2dc97edfff8ca508c9ec3ed80bc4abe86n/aHeodo
2020-08-25BAL_DKJT4LZM8V5SX.docdoc 2038aedc5bf31e456979b2a8af18933898144dd5d5e637e78d178565cc3ec135n/aHeodo
2020-08-25FILE_805551995936.docdoc 334456b3a472ed6d017c3cca2d1768dc77ed7a60ec7220ca07fba9fe646d33a0n/a Heodo