URLhaus Database

You are currently viewing the URLhaus database entry for http://ecoferma23.ru/contacts_files/Pages/GFC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:444645
URL: http://ecoferma23.ru/contacts_files/Pages/GFC/
URL Status:Offline
Host: ecoferma23.ru
Date added:2020-08-26 20:00:07 UTC
Last online:2020-08-27 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-26 20:02:02 UTC to abuse{at}nic[dot]ru)
Takedown time:11 hours, 44 minutes Good (down since 2020-08-27 07:46:08 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27invoice #58859.docdoc 08531c896c900816e373957872ce7e55db50203fd681019719dca8fc27882b40Virustotal results 28.81%Heodo
2020-08-27Inv. 84885.docdoc a9bd74574df38d6a8e51cb22d26dd85383aa10a3d8e4f8ff2a7ef30663b77aeaVirustotal results 28.81%Heodo
2020-08-27Form - Aug 27, 2020.docdoc 8961b61c4631b8c84367078e44fc1066f57830e0bc0622af1de7769f82e6442eVirustotal results 28.07%Heodo
2020-08-27PO# 08272020.docdoc f663b206e32202cdb2b7fe26738d009a4c1fb76352cb8e9a46bd1a7bc6060bb3Virustotal results 27.59%Heodo
2020-08-270296386764ZA.docdoc 95feb4a035233bbf6d90619d2c6d9948385cc06b894dfdd7fd10cd378797df32Virustotal results 44.83%Heodo
2020-08-27ZK004 invoicing.docdoc 021d2338b8a706fbd77f04cf43db3bf9dea03a1afff732ece042614c35e369edVirustotal results 44.07%Heodo
2020-08-27Copy invoice #36640.docdoc 518cef1391f1fd9cabab66c2c32f6ee1428a399147f181ff433baefecb0e8c45Virustotal results 42.86%Heodo
2020-08-27Payment status.docdoc 7f33bcae335d18da18a8cd7474dffc2399131f6e66ce9e7a8099718810cdd350Virustotal results 44.83%Heodo
2020-08-27form.docdoc 6618ae9fbbf615266ce3a04226305b4569758644d9bab2b4c4b4f116c96855b4Virustotal results 45.61%Heodo
2020-08-27Q026 invoicing.docdoc 469ac8a418f2dbb4e433d022cc757fe2ddb270878b4c7ab13ebf4f8a316c30e6Virustotal results 41.38%Heodo
2020-08-2764245.docdoc dbfbc13ff098e5c8ed87a620e5e73f075dc9ac85963d50111843d28ea929a4d1Virustotal results 41.38%Heodo
2020-08-27UW004 invoicing.docdoc a7de5e7039339ecbff062dcb58d75a469ea8240a5f7d1549f67e69e56443865cVirustotal results 38.98%Heodo
2020-08-27Payment.docdoc b87a064c66cdd9719e97ee49c21b6435c4f769164c1195b5d14cf15b9dc81a19Virustotal results 31.58%Heodo
2020-08-27August Invoice.docdoc e45a7277159aac8916096aa45b400cdd23c26f876fb6a1753d95e1119c352259Virustotal results 31.03%Heodo
2020-08-27Electronic form.docdoc f92eeeee023f763c255c41615d314bdd95628f511d7650771f8bbe9ef73742b9Virustotal results 32.14%Heodo
2020-08-27WZ0032 invoicing.docdoc a12169bfd5b2999a36e090c627578d1d8c9a00225ae68ec13361f8c61de5cee6Virustotal results 28.57%Heodo
2020-08-27August invoice.docdoc b27e8c6c5a1f2ca799c9e70469734034437ef96227b7c5394ab56dc4d55ca8b8Virustotal results 28.81%Heodo
2020-08-27invoice.docdoc cade1ffeb7c4023e29d6f908dd96b6ef4f6d21c0a78dfb0728a0b358302e7563Virustotal results 28.81%Heodo
2020-08-27invoice.docdoc 55e8bbf2a59f439bf5dc58b7fe2236ab94b9552b4abf1a74ea194498ae32199bn/aHeodo
2020-08-27Form.docdoc 305e0e9a329ac85f97dacf909710fb3ae485af0e09b6ed9022f8a4dc901623e6Virustotal results 28.33%Heodo
2020-08-27Inv. 048282.docdoc 763a511d6b6e45d6386a286c0da9cc275171965046f20bf30ba106f6dedc740fn/aHeodo
2020-08-26Inv_94800.docdoc 4527a593cc4ab81b2e6974e43e63dc1c5f6505449e5a738814fd74d1392326b6n/aHeodo
2020-08-26YA08 invoicing.docdoc c0b72b161a48dab0be1f4cf804079f65cae5827a62e982b8af3fe00a2281dc0fVirustotal results 28.81%Heodo
2020-08-26invoices 171 & 9689.docdoc 4e2e9c00a518654ed11ca5bdbcb739c816524d665f519789f77cad7c1ee6d78cn/aHeodo
2020-08-26Inv. 1391601778.docdoc 900e897c3d7f08039833fa89748e84c98a62d959e4e8e8cc54c832acd902470dVirustotal results 28.81%Heodo
2020-08-26invoice.docdoc 6ed646f54add9ca22852e2fbe34861573a88cadccac53c9ccdaeffe7db82d284Virustotal results 27.59%Heodo
2020-08-26Invoice 082719.docdoc 1862df6f40d11380f7d581fd9f613d34ff81f2f61ca92d8178a226434543ff52Virustotal results 32.76%Heodo