URLhaus Database

You are currently viewing the URLhaus database entry for http://www.arrecifesciudad.com/live/public/0239962415228375/mh6350c-00148/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445524
URL: http://www.arrecifesciudad.com/live/public/0239962415228375/mh6350c-00148/
URL Status:Offline
Host: www.arrecifesciudad.com
Date added:2020-08-27 22:01:06 UTC
Last online:2020-09-01 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-27 22:02:02 UTC to abuse{at}ovh[dot]net)
Takedown time:4 days, 8 hours, 59 minutes Bad (down since 2020-09-01 07:01:51 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-28August Invoice.docdoc 56385c138dcd6e1f59be2fadd0cb3e78305d5a8b74de904c00ca85d68aa84809Virustotal results 31.03%Heodo
2020-08-28Invoice #16116.docdoc f518586d760ddbf3ef58ae4e7f8bc570d1154c9756e793135770a886901385cdVirustotal results 30.51%Heodo
2020-08-28INV #97142 FOR PO #00251872939.docdoc c5a9757906c65f2a2961bd352aa8d42181b2b26e9cf2b82e01d6e824d94bc00aVirustotal results 31.03%Heodo
2020-08-28invoice.docdoc 67fe9aa6843a58f85b959469d70926c6b028d3cd880f1ff36bd050e9d50be649Virustotal results 32.20%Heodo
2020-08-28085207.docdoc 635e1141dfd9268f184274a609f325fe1aa27d7af0a4153fabd3ea891164543eVirustotal results 30.51%Heodo
2020-08-280093348.docdoc 5fcecf8fdfc590ef687d6590209ea3c2ea0ad746b5f4746e537cd64813fce05eVirustotal results 30.51%Heodo
2020-08-28Invoice 04015454.docdoc 8369cd1f9e4a1892c61f02631be1abae0346cb1972cda90b4cb4a36ede626e7cn/aHeodo
2020-08-28Invoice 0973951.docdoc a03a331036791b2d25681114c722041029d9e995c684190654e5f664efe761a0n/aHeodo
2020-08-28Electronic form.docdoc ba1bac226c7ba525e1b2706a7f0a7a0ddec1272db21044df1e28cfd777804a3fVirustotal results 31.03%Heodo
2020-08-28INV #0265 FOR PO #092445804.docdoc 2012064cfc4ba5e01f3677d2f52053612232c932876a8266ac2bd8bd8a35af6bVirustotal results 31.58%Heodo
2020-08-28Payment.docdoc 1d2b270375ae00907412647180a7dffae422dac066c42966c9cca4bd1dd8dfe2n/aHeodo
2020-08-28Payment status.docdoc 7e0d6fc8bc7a69d5e27e2130c83b434512af52a5337145098c2426f62abf97eeVirustotal results 33.33%Heodo
2020-08-2767206.docdoc b1f8d82d19d6020ac3606afc8e0699ddde66a03ce07d5d7f6b6bc45a238084f2n/aHeodo
2020-08-27August invoice.docdoc 474fe5a4009da897047f91b9d9b8f40aaa5d674955f0815934507029c7038976Virustotal results 33.90%Heodo
2020-08-27August invoice.docdoc 7314c132ed2bd783a95997d7bb4306ebfb97de0cd23e31c78dbf77ebb4dd61efn/a Heodo
2020-08-27Inv_0642.docdoc c0585477220770048a8326b7b7dd1ac706601ba7e09459f20bc5d6cd08991a74Virustotal results 33.90%Heodo
2020-08-27Electronic form.docdoc 058a814da324c518a1848ab62bcaa8cecf5322d81fc07d96288a0b5f319ea276n/aHeodo