URLhaus Database

You are currently viewing the URLhaus database entry for http://mendozagroup.ca/cgi-bin/eTrac/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445424
URL: http://mendozagroup.ca/cgi-bin/eTrac/
URL Status:Offline
Host: mendozagroup.ca
Date added:2020-08-27 19:45:10 UTC
Last online:2020-09-04 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-27 19:46:03 UTC to abuse{at}iweb[dot]com)
Takedown time:7 days, 19 hours, 7 minutes Bad (down since 2020-09-04 14:53:52 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-2938714673.docdoc cceb7527580365dbd4c0fca8ec156753c8b73ecb210acbb01ffc90cd09892bc4Virustotal results 49.15%Heodo
2020-08-29BAL_PO_08292020EX.docdoc 13578d79d08b5589c902aadbac67c0eedc5f0f9ad6391aa10dd47cf7744c9923Virustotal results 50.85%Heodo
2020-08-29JMQO_11517349.docdoc 913b0a2a72baaf9c1d03b04ca8e98d1ca3fffade6ff4f1a770d0d1642e4c5ff4Virustotal results 51.72%Heodo
2020-08-29FILE_PO_08292020EX.docdoc f3077969e8408af5ed00319f97bc3cf89e31143c0e98423d5b6c64a264a0f905Virustotal results 52.54%Heodo
2020-08-29GH6671085594UY.docdoc 11804e3ccad6ca22980e317b7aecd775413d5a042508cb18aa2dadf7e19f4570Virustotal results 50.88%Heodo
2020-08-28N5PBSX6E5.docdoc 9c6f98f54b5f8b43d3ced2c547a09d7ea30578c696263ad60666ea9e75a22daaVirustotal results 33.90%Heodo
2020-08-2898203817342.docdoc 642f0b1333a6ccce34906af2c3332ee52c9580f7b91ce7e4fb658e0915b43e73Virustotal results 33.90%Heodo
2020-08-28V_PO_08282020EX.docdoc 626afa7c2b32a78e2a1fe772f4ca50f868034b791fd3c465f5836c4f67329049Virustotal results 33.90%Heodo
2020-08-28EO5184933027HK.docdoc dd585fa2ba0d6fed90358f7f48b7a7afb9b551a59e451d038ef343b132e816ddVirustotal results 32.69%Heodo
2020-08-28OHGR_18769369997250635409617.docdoc d15d207c796247cb72e865fb89b2d86126c3ae9e3f7f84d6d799a5c179fee17fVirustotal results 31.48%Heodo
2020-08-28HH8992405107UB.docdoc 1777a62fe7df40cf57e27aeba4a8c8c50dfc4b978a2ef0e383dc2a63fd6fbf8cVirustotal results 32.76%Heodo
2020-08-28REP_6730198663433105.docdoc 8924cd43cae04cf71c93149b8d2a6729ae28edc120bff304e833416121085341Virustotal results 33.93%Heodo
2020-08-27EIGE_25131572.docdoc 56a5251ecbef61368cccbef64fcec4d5a5d2355f2187f9a26708901b205441e6n/aHeodo
2020-08-27FPQ_080120_XKR_082820.docdoc c9fd82536c7ab23bb6fc3e34bd11940d5c580abd2ec8aa7d18034aae20df426bn/aHeodo
2020-08-27FILE_PO_08282020EX.docdoc 5ea25ce6387f4fc4d741273dda0eefc709a68ab1fe384cffee188f091a2945fcVirustotal results 32.20%Heodo
2020-08-27BAL_PO_08282020EX.docdoc 4970709c24107de7ffbd685d56c1c61b7b363ee758ee8704515648173c59eabeVirustotal results 32.14%Heodo
2020-08-27DG8481273491ZU.docdoc 41944366953e90e2ac766eaabd79ffe7025801a5561368e1d9e382f9288c4d3dn/aHeodo
2020-08-27DOC_PO_08282020EX.docdoc ea1ce5f9d12c67465b28319cf9b23a41cf938fe17878362a3a58f68bd85a9703Virustotal results 33.33%Heodo
2020-08-27MV1506164147ND.docdoc bc591a14fc5b3d958ddf47dd0ab1ec96d1d8c2a5e2d3325f5f5814672df4f17dn/aHeodo
2020-08-27C_XW5359055924FA.docdoc 493671484f84dad38024d17bd7abd744b827836b03d67c3d1ae8f24e2617c29aVirustotal results 32.76%Heodo
2020-08-27FILE_MG49DKDBO.docdoc aebbc22ec298ff9ceec0324b8ec99931c2ad41c220935c5baed852233de7d61fVirustotal results 32.14%Heodo
2020-08-27GM5082645989PL.docdoc 49b0709d22536eb3ddbf6b3468a63cb48491a014a7895436ceed6e3749888f5en/aHeodo