URLhaus Database

You are currently viewing the URLhaus database entry for http://hm.dp.ua/FallaGassrini/sites/5464318412/d5uwi3pm9-00006882/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:444423
URL: http://hm.dp.ua/FallaGassrini/sites/5464318412/d5uwi3pm9-00006882/
URL Status:Offline
Host: hm.dp.ua
Date added:2020-08-26 13:49:50 UTC
Last online:2020-08-27 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-26 13:50:06 UTC to abuse{at}hostprolab[dot]com[dot]ua)
Takedown time:15 hours, 41 minutes Good (down since 2020-08-27 05:31:07 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27Invoice 068843.docdoc 6618ae9fbbf615266ce3a04226305b4569758644d9bab2b4c4b4f116c96855b4Virustotal results 45.61%Heodo
2020-08-27WZB-080120 GPNZ-082720.docdoc 469ac8a418f2dbb4e433d022cc757fe2ddb270878b4c7ab13ebf4f8a316c30e6Virustotal results 41.38%Heodo
2020-08-27INV_6684.docdoc dbfbc13ff098e5c8ed87a620e5e73f075dc9ac85963d50111843d28ea929a4d1Virustotal results 41.38%Heodo
2020-08-27Payment.docdoc a7de5e7039339ecbff062dcb58d75a469ea8240a5f7d1549f67e69e56443865cVirustotal results 38.98%Heodo
2020-08-27TW-080120 TONZ-082720.docdoc b87a064c66cdd9719e97ee49c21b6435c4f769164c1195b5d14cf15b9dc81a19Virustotal results 31.58%Heodo
2020-08-27INV #001661 FOR PO #0536003561.docdoc 09b034c3633cb570e31c95ee4d58988a6e55907115f8a24912d5f653adae9875Virustotal results 30.51%Heodo
2020-08-2705768939878.docdoc 0cbddd5eeb728ba41f56bd3066629b9ad20536c1373057891cc5ea201d70c2d2Virustotal results 31.58%Heodo
2020-08-27Payment.docdoc a12169bfd5b2999a36e090c627578d1d8c9a00225ae68ec13361f8c61de5cee6Virustotal results 28.57%Heodo
2020-08-27Inv. 008864467.docdoc b27e8c6c5a1f2ca799c9e70469734034437ef96227b7c5394ab56dc4d55ca8b8Virustotal results 28.81%Heodo
2020-08-27Inv. 02843951105.docdoc cade1ffeb7c4023e29d6f908dd96b6ef4f6d21c0a78dfb0728a0b358302e7563Virustotal results 28.81%Heodo
2020-08-27X24 invoicing.docdoc f0f0b47493858a336750af576adda44472e0e356aee227c530620df0f158e3b0Virustotal results 29.82%Heodo
2020-08-27invoices 30593 & 1013.docdoc 305e0e9a329ac85f97dacf909710fb3ae485af0e09b6ed9022f8a4dc901623e6Virustotal results 28.33%Heodo
2020-08-27INV_7911.docdoc 45c6293b87ea5ec369c3130d674caf51a96048a1fdd88636c9c15626edf8b375Virustotal results 29.82%Heodo
2020-08-26Inv. 0014983147156.docdoc b11bd4b83e89bc246bf2b88dba510f02dfbeb9742d55087260bfeb43f0049000Virustotal results 28.81%Heodo
2020-08-26Invoice 0500831.docdoc c0b72b161a48dab0be1f4cf804079f65cae5827a62e982b8af3fe00a2281dc0fVirustotal results 28.81%Heodo
2020-08-26August invoice.docdoc e1404d1cf1e4aa8d288515108f44ba0670bcf15d7fa55eb971e4185364134a31Virustotal results 29.82%Heodo
2020-08-26form.docdoc 8d1ed93b4b818cdc5fa85348c03845e9dd6a15c09ba7b89d5430512b44cf58adVirustotal results 27.59%Heodo
2020-08-26Invoice.docdoc 6ed646f54add9ca22852e2fbe34861573a88cadccac53c9ccdaeffe7db82d284Virustotal results 27.59%Heodo
2020-08-26INV_2832.docdoc 1862df6f40d11380f7d581fd9f613d34ff81f2f61ca92d8178a226434543ff52Virustotal results 32.76%Heodo
2020-08-26Copy invoice #4544.docdoc 89861158cf9124252fbe1391e796281b6339c99c567adbe068f12ef9c084b2b4Virustotal results 32.76%Heodo
2020-08-26August invoice.docdoc 3cdcfd402295132011280acf8653159748e400b26a6057084157365e7e06c65dn/aHeodo
2020-08-26Invoice 0015261.docdoc 076bc18d0668b058c58953da9ba2a7d4b91afa72bd91d9795daa2819c4e00dbbVirustotal results 31.67%Heodo
2020-08-26August invoice.docdoc 77a31068690b93fd195f54c02b476d0ccce166f745ed7cdc5a41f8e64c9800bcVirustotal results 30.51%Heodo
2020-08-26Form - Aug 26, 2020.docdoc 9ffac8bef31ebd56cbebcfc72af4123249110602e0f345374b1561e6cca6de52Virustotal results 31.03%Heodo
2020-08-26RD7805508959YM.docdoc 0f0b74426e298cc56cadfc501811886784426e93a8bc21004cc8b7e33e499951Virustotal results 30.51%Heodo
2020-08-26Inv. 005516.docdoc 780a3556d90b9f661377e352986ee8776ad3196409ed4c112c6422014ca9edafVirustotal results 30.51%Heodo
2020-08-26Invoice 3646379.docdoc f38515019660b0e150490b8106218bff50246d9260cb621feeb7aee778fdda3bVirustotal results 29.82%Heodo
2020-08-26G2853204487OD.docdoc ecdc5a652ab75c601cfdae6753765673737714e942da6f1ea1d7c9c13289f435n/aHeodo