URLhaus Database

You are currently viewing the URLhaus database entry for https://www.valetourvirtual.com/vapor/https://attachments/gQBRRJsPTMB40Ikn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453272
URL: https://www.valetourvirtual.com/vapor/https://attachments/gQBRRJsPTMB40Ikn/
URL Status:Offline
Host: www.valetourvirtual.com
Date added:2020-09-04 12:25:06 UTC
Last online:2020-10-14 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-04 12:26:03 UTC to abuse{at}lacnic[dot]net)
Takedown time:1 month, 9 days, 17 hours, 29 minutes Bad (down since 2020-10-14 05:55:38 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05Rep-CW646510.docdoc 4c3f9a91ab8bd67a7de8b61f6d5e49c34a0c3ded123f63205f02d17ff570c204n/aHeodo
2020-09-05Attachments-6704.docdoc e598cf9a18d4db4fa8174ec8f921eb470f8b844063cec6fa35185f7f8f1d2b4bn/aHeodo
2020-09-05UNTITLED-20200905-62651.docdoc 99b355a60a9590d4a7695c3e6dbd12bcc643041c7f98e39ebb7bd29d4300b770Virustotal results 27.87%Heodo
2020-09-05list-2020_09_05-XGH241777.docdoc 36db57afc7d4faa57d7bbd559db7ca4ae2bd483caacaa9fba1a3cc6839b240a3n/aHeodo
2020-09-05file 20200905 IEF417.docdoc c687016b2136760124efe54694e2980e93b56aa5278ec587b7290a01f02c93fdVirustotal results 30.51%Heodo
2020-09-05Mes PRK60241.docdoc 54fac54bf401937afa1a48e9545b32e46ac8be7c543918e4a841177baf879ea3Virustotal results 30.51%Heodo
2020-09-054656027.docdoc 523e87e4ec97f2222463589b553503e6fd1b248fb7856dc28bb5a67f05709a6aVirustotal results 30.51%Heodo
2020-09-05List-6511.docdoc 0274b67e43f98e65033f7b7b9c341a6560e515e61187693dfa5b941a2545309fVirustotal results 30.36%Heodo
2020-09-05FILE-8991.docdoc 27ad65edce895a8ac105708b7510859313c9f88cec6a66611b581bc480ad6676n/aHeodo
2020-09-05Doc 20200905 CUA2774.docdoc c1658fd6974ace7a621b0e46c9d3f1bbb8ad7d3ddeb3032082937f3133c1c063Virustotal results 30.00%Heodo
2020-09-05Inf.docdoc f71c39920ac9463b4be57b2c9ef5a795184d8adab4c0a8761d0d491ae6b5a140Virustotal results 30.00%Heodo
2020-09-05Rep-20200905-CES523973.docdoc 62cc3eedb06b43f8a3e286b0a9f04cbf36fe240a532b217d91950ea20fa0ba9cVirustotal results 28.33%Heodo
2020-09-05LXF41714 2020_09_05 46671.docdoc 1fde53646d2021d4bd959bcc2ee2b8c1db5ca4b112b58af96efc114ffd4dc6e6Virustotal results 29.31%Heodo
2020-09-05mes-20200905-YYE876.docdoc 5b82741c8587a1a90e3ce044387a541c69a916330391030a4daa50aa1db6a445Virustotal results 28.81%Heodo
2020-09-051847_20200905_846.docdoc 4845d731ee51494da878e4a1e0c22ad0e6e1885aebe593bb6b3adf115f9c84d3n/aHeodo
2020-09-05Arc-2020_09_05-540.docdoc b1d37441a65187f53492dcd30fe0d3fafb9de343694c7ac79d3ce5434cec9350Virustotal results 28.33%Heodo
2020-09-05Arc 20200905 GCX876.docdoc 206feb1d69aba0e52a7d33975a49cc2a9443deb7bcf9fb4f8a6428ffcd95c97bn/aHeodo
2020-09-05arc_20200905_N294444.docdoc 206feb1d69aba0e52a7d33975a49cc2a9443deb7bcf9fb4f8a6428ffcd95c97bn/aHeodo
2020-09-05Attachments.docdoc 7b33fe4f09c06251aba09bbc5407ae8fd899bae0a40d3e7d55f3806a8b6a74a6Virustotal results 28.33%Heodo
2020-09-0560506WOJ 2020_09_05 37535.docdoc ee2869e612b62baacd8f12266c98e851549e6789343a4020cc424755ae55326aVirustotal results 28.81%Heodo
2020-09-05arc-20200905.docdoc 2ddd8ba7251afbeee6c41576c377265c1a2a9f5370cd66683c24db0c89a0062dVirustotal results 26.32%Heodo
2020-09-05ARC_2020_09_05_WXS1464.docdoc 346db091f843b130bc229ea6a6cf9d569e0a9d2408e413dd9a5087bb25437652Virustotal results 26.67%Heodo
2020-09-05DAT-20200905-X126.docdoc 0917f0cbca78c19301ba65aa799b29dcf90ee3666fc9f8b83f00c5ea34a0eba6Virustotal results 26.67%Heodo
2020-09-05inf_2020_09_05.docdoc 6914af81ae643d0106a7cb16454991e2b4d29053551e92e659456ad592120f57Virustotal results 26.23%Heodo
2020-09-05doc-20200905-22498.docdoc 8d7ac57ba3c19f60ff3e7d2e5bccfb5a790b9d05c84fd5237e4235be91fde6a9Virustotal results 26.67%Heodo
2020-09-05dat-20200905-02780.docdoc f3c01505f223d53a856b4cbb5201b5cbad5706145be5e214e266f4570491a8ccVirustotal results 26.67%Heodo
2020-09-0584138687_2020_09_05_G563960.docdoc 2572ca226200ecc1019e9813f939d7484962a7f90ecc62921f7efb01e5bdefeaVirustotal results 24.56%Heodo
2020-09-05REP-20200905-11526.docdoc d933cd9a8fdaa58bf021074d4dcbca7f3fed26971db346a66f8b2435afb70b50Virustotal results 21.67%Heodo
2020-09-05doc 2020_09_05 1243976.docdoc 92bc3c4ef5b89ad046cb64e9cd6ee2eb8d1053b1b07620f1a0aa6503912b05efVirustotal results 21.67%Heodo
2020-09-052989470 20200905 987936.docdoc de7201ce2995436691a764734f9d6dc4395dba5066dc1c6c469fb2684daa58cbVirustotal results 21.67%Heodo
2020-09-05rep_589040.docdoc 349685f93e08324717dd09b79130205af7e095872a599905ac58c453d5a4f25en/aHeodo
2020-09-05Mes_2020_09_05.docdoc 3c51d26e98137dad5c907c872c1af3b0faea7094df4acb08d71d8873e8800a9dVirustotal results 21.31%Heodo
2020-09-05doc_20200905_LM529.docdoc a0c340e5b8f401a13ec7ea03f405623ed8532d1bdfc9f708d34ad94a2c14ac47Virustotal results 22.03%Heodo
2020-09-05BW83676_5801.docdoc e5b5640cb999ccd3a5fa07ef28ecdb37ea16dbe142bd3cec619837a9c0c3baddVirustotal results 21.31%Heodo
2020-09-05Attachments_20200905_IZ826408.docdoc 5d1e5bc11522b6d4daf399dbbd1a18561ee98aad33dce8f798e2aad3a2a5c329Virustotal results 22.03%Heodo
2020-09-05MES 824196.docdoc 78ed01b95752a63330a863810431b4d58ebbae0e20a745b6df4fe6799a0a8f1dVirustotal results 22.41%Heodo
2020-09-04mes-20200905-PSE41444.docdoc 4501204cd406a353ac88516bb9f133148c882ea030d84403dc54bd0297f68b6fn/aHeodo
2020-09-04Untitled 2020_09_05 H048.docdoc be5a076cc07b81d54fda54ef3c56f2d60ee214c3d1fe46de3dc59a1df619dc29Virustotal results 21.67%Heodo
2020-09-04Attachment 20200905 RFQ412.docdoc 6d8bb4cc926450189c32b7634d2940fba6556c2865096d7ccafec6b4b6e0c396Virustotal results 21.31%Heodo
2020-09-04Attachment-20200905-1912435.docdoc 88d669402f9cb6d3c39a7de76b5e16c45d5db2b7a4e5c5f2b9ec112d299f85d6Virustotal results 21.31%Heodo
2020-09-04Dat_2020_09_05.docdoc 137b5a0cda220100df4caefac31efe6cc85c4bd72580fe2ce1987887901d3ed7Virustotal results 22.03%Heodo
2020-09-04REP-OE11603.docdoc bb32a5e79b853e76e64596002da4cf3b42d9e2c10db3f2b7fc7fd805fa43ff71Virustotal results 23.73%Heodo
2020-09-04Rep.docdoc a8e4d449c8018f90196d3de6e14d75cdca5c5f76b989880e012890f87d43f6c9Virustotal results 21.67%Heodo
2020-09-04arc 2020_09_05 CR012.docdoc 50d0908dff351c8fcdfd307f4c93cad6065d4c10c2614fd4201209f862681cfdVirustotal results 20.34%Heodo
2020-09-04Attachments-2020_09_05.docdoc e3986d10ba408aefe9c0f44c298dafcd5501ea916fc093cbff42c479194a9309Virustotal results 20.00%Heodo
2020-09-04Doc 20200905 3562.docdoc 79b65c86df194fd9f4a7d42889a26c715ccfeca32a0e1eecbb9d65ebfac19ac7Virustotal results 20.00%Heodo
2020-09-04Untitled Q7069.docdoc 4833c57c4ff48c2720247aa3bc9c8d62222f9fe3d095924030c344bfa8673847Virustotal results 20.00%Heodo
2020-09-04DAT_X88102.docdoc b177d6304e1239837128c14fc3423ded464e3877b918bdf27db3d2f40375c398n/aHeodo
2020-09-0447296VI 2020_09_04 772475.docdoc 9f003b20287110dbbea8826454c0666aee189fbf57cb907e8cf072dfe3829b18Virustotal results 20.69%Heodo
2020-09-044252N-20200904-ORT12133.docdoc 924f9439383931103e48f1a8618e3b5b0dc6e56ba52261116659d5dd2bbc3050n/aHeodo
2020-09-04Doc-2020_09_04-UWF762807.docdoc bd6fabb51f037d2253220c55129be8125a21f63b579dd69ca9d82604f0208b60Virustotal results 20.34%Heodo
2020-09-04mes-2020_09_04-024.docdoc aa3db031e17cd90af00951bc4d86c18c8e42328f47e9014b552993ff1b29c557Virustotal results 20.34%Heodo
2020-09-04doc_20200904_7233.docdoc 623ee20c1b2e5a53a0bbf6eb21f4b87cb0e6392e023f1e08267abc08c26e5bbfVirustotal results 20.34%Heodo
2020-09-04796HO-20200904-939559.docdoc eb98e413719e07262040b6d92f4ffbfd9cad979d4fd8e59932902374dd33cbd5n/aHeodo
2020-09-04A6785_2020_09_04_854.docdoc 627615216c18d1e8f7e1fd2774e09f54950e8068ccf5712cf072d21fc266763fVirustotal results 39.66%Heodo
2020-09-04Attachments 2020_09_04 QVI0664.docdoc 4c213965b64b715680686d5c98d5d0129fdccb424a5e74f561c6969fa785d75cn/aHeodo
2020-09-04file-20200904-272070.docdoc 53e22a87b7381a9a4a9bea066f9d1b435964fddef4e38f321f372fe6abc16854Virustotal results 34.48%Heodo
2020-09-04Arc-CH120.docdoc 4500dc04802c13fe7026076c983b30e2762694f15df4a35bec777b09e64b899dVirustotal results 36.21%Heodo
2020-09-04Attachment_7872079.docdoc 9db91d669af1bf809886ca92ed83858aa55b59c031db7bcfcdb470ec77cfb0d1Virustotal results 35.59%Heodo
2020-09-0446460_90534.docdoc 380c46aa7a6ebfb32b4e005930aa368ca90386ecf02e2587a0c6f035569df404n/aHeodo
2020-09-041997 2020_09_04 134009.docdoc a49d6ff985f57e4d6e09893b343f97b9da664ae8c0b7c0e95f18f1a8f119f1a8Virustotal results 35.00% Heodo
2020-09-04File-2020_09_04-2048.docdoc 1aa05e276c9fc45289cfe940287e1141128258a93052f3ac4d5d7b78c9b0f15cVirustotal results 36.67%Heodo
2020-09-042199717_2020_09_04_TV837905.docdoc 07499f73c1b2290d3f1628c566a91f8f3bda896e9c9774c4de22d614a8b1381eVirustotal results 35.00%Heodo
2020-09-0477999.docdoc 403170a4ca043be478bde432c994bc04e0ec0bb95f4d457928890829a998e46aVirustotal results 35.00%Heodo
2020-09-04Untitled 20200904 364029.docdoc a7f35b06b6d94b7aacb7aaf4681b81b3373a4051b74e97e01ae6d58a2f052b27n/aHeodo
2020-09-04INF-2020_09_04.docdoc d21d369a575521b056524693121464f2aa51cbbc0790a6b01069bae6bb4dbb32Virustotal results 35.59%Heodo
2020-09-04646 2020_09_04 S9112.docdoc 4f574c1f2f33241e9d1d44b74075d96778a9a152808b8c397f19a51c1b16ab2dVirustotal results 33.90%Heodo
2020-09-04Rep T45404.docdoc 0d5e301807f834486dc3a5e55e4e04056e56cb6b8a2f2136c64f55a0ba12f1f3n/aHeodo
2020-09-04Dat_2020_09_04.docdoc 0fd7dcfa200a1b0da02cc3578b15e97fdb192f4085d66ac383db864551155bffVirustotal results 35.00%Heodo
2020-09-04File 233913.docdoc 4ff12f48cce6bd43cadbeb06f54c727fa688da49d56903348dc190711e4d0891n/aHeodo
2020-09-04Mes_20200904_RBU0601.docdoc 20f0a0ba4cd0dac615e918dd489d36a9dbe9da8eccd28074379ccb9297f44202n/aHeodo
2020-09-04UNTITLED-2020_09_04-PD7896.docdoc edbc22e742e12b2af45a775673812f2c751b4f9071a83b9565d3d547fa380655Virustotal results 30.00%Heodo
2020-09-04arc 2020_09_04 66491.docdoc db32c617fdfbe03a214b3ea0e57620c34459f86b3c99d815fbc869c3dc5e5fe6n/aHeodo
2020-09-04ARC 2020_09_04.docdoc dee17f41722ce96f3e95ac1ed9a43b57ddfef3fbcf6ae699f9adf0bdbdc15debn/aHeodo
2020-09-04REP 2020_09_04 38356.docdoc 6fe4e70594d98f07fc43fc54e2e24a57ba80babf404b803336a8c7cca7f4bd70n/aHeodo
2020-09-04G298-20200904-D2798.docdoc fe8b0f5cf9354ea102596195bbbf5947c2103a393c585873166112b4734d3169Virustotal results 27.59%Heodo
2020-09-04Inf.docdoc e04a181d4f71e29d0e1dd60e7ddaa50e20047dff94667fefcd0f582f5e3203a3n/aHeodo
2020-09-04File 2020_09_04 SBA979.docdoc ed63266e67ad9944d1501d2221c8390e1585ed5aed9397212441db07dea0b7e9n/aHeodo
2020-09-04mes 20200904 PD87026.docdoc 3b8964cde0e41b835a06f77a2d1834dac132f78cdebaf8b6e89214daf39b8752n/aHeodo
2020-09-0462589199 2020_09_04.docdoc 3e0a5ec179e243321f58a84f26f80b56360e394bea0576cb2d6afdf21f0e6595Virustotal results 25.00%Heodo
2020-09-04dat.docdoc beb360bbf4f0bf929e1a8d6e734b006c12269cf4e034909c884cbdd8a9374c65Virustotal results 21.67%Heodo
2020-09-04LIST-U19242.docdoc 0c906246c9944d2f025bffd01313418c70c77ee5e3ff89cc68fa7ecce69782bfVirustotal results 22.95%Heodo