URLhaus Database

You are currently viewing the URLhaus database entry for http://mendozagroup.ca/cgi-bin/http:/Overview/4EVhvzDczSKoXOQ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453206
URL: http://mendozagroup.ca/cgi-bin/http:/Overview/4EVhvzDczSKoXOQ/
URL Status:Offline
Host: mendozagroup.ca
Date added:2020-09-04 10:31:17 UTC
Last online:2020-09-04 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 10:32:04 UTC to abuse{at}iweb[dot]com)
Takedown time:4 hours, 15 minutes Good (down since 2020-09-04 14:47:34 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04FILE-2020_09_04.docdoc 1a2267bf7b914a9de28507fa9a91a5ae83a2441428bd581f461b67abc2e84423Virustotal results 26.23%Heodo
2020-09-04OXY519-0212.docdoc 7160ce21f102d1b919bee53947094d83fd11055b2eadb90b11d5923498d504c3Virustotal results 29.31%Heodo
2020-09-04List_20200904_494820.docdoc 533b65838696f229623a8367b9367b80001a7af8125899e324d550f4b4c64456Virustotal results 26.67%Heodo
2020-09-0487273-20200904-428721.docdoc 794287d8176f07c6943cc4ca303d03de2ec84b37ff7262e148c0451087177c86Virustotal results 27.12%Heodo
2020-09-04Doc_97905.docdoc d0faa29d011a7abe3a5e2d03346780cebd6a5dc766e52241014b96e58b4a99d7n/aHeodo
2020-09-04file.docdoc 22541ac301b5c8fdf15f74cc06df0c5a237bfe5593f910699acdaa3ae869edd9Virustotal results 23.73%Heodo
2020-09-04ARC-2020_09_04-3441647.docdoc d05c6ba705d84768f55f4f0c3adaaca4ecb47bca2960d53b0b110b9634eba759Virustotal results 25.42%Heodo
2020-09-04Untitled 20200904 WLR15547.docdoc 2e6992209a57f96c89556ed36c0e872bf312cc0e79e673c6888fe3b263c1ce06Virustotal results 23.73%Heodo
2020-09-04inf C01910.docdoc 29ffe94790ecabfa236c6b248a97808417fc07a48c0460dc56eac0c1820b0182Virustotal results 22.03%Heodo
2020-09-04arc-20200904-9401.docdoc 0348b2d84a9245b99853803db4a5d8a6bb6b89ba2b30d2d201dffbe97b718d82n/aHeodo
2020-09-0481073_2020_09_04.docdoc 5e01f376491f37354db3791f6ec1c53893e852d5874971655f2b8c0c9bfa35cdVirustotal results 20.34%Heodo
2020-09-04542154.docdoc eae2a3c4e7a60e5476ac2c92926540cf3c70568a318f1a20a996ebeb53e8749bVirustotal results 26.67%Heodo
2020-09-04LIST-20200904-686.docdoc 8c4a8a1c7d4ddbfd0b727a5f169b6bc78e7997fd2b0947299d663a215bb3a9d9Virustotal results 27.12%Heodo
2020-09-04Dat.docdoc 2ccde651fa61c7cd21ea8fde6ff8dbbd3945693f2e19a1ee1feebf25294199cfn/aHeodo
2020-09-04Untitled-2020_09_04-5588.docdoc 3707b5de1e09741a173a932af10c341420b9303dd71c5e228345a8a9076edc11n/aHeodo