URLhaus Database

You are currently viewing the URLhaus database entry for http://terragondwana.com/terradivine/public/s9552979246579cgklimcl4dj87r2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453286
URL: http://terragondwana.com/terradivine/public/s9552979246579cgklimcl4dj87r2/
URL Status:Offline
Host: terragondwana.com
Date added:2020-09-04 12:39:08 UTC
Last online:2020-11-16 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 12:40:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:2 months, 12 days, 19 hours, 56 minutes Bad (down since 2020-11-16 08:36:33 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05M_PO_09052020EX.docdoc 8b23e164f16ba0caed21611db9782895ac3a6a1f5b30a16e7cff6a2f8e3c3008Virustotal results 44.07%Heodo
2020-09-05PVX_090120_DYY_090520.docdoc 7813e0676b9ac895750acf882aa69b95b64a212515208262219dd072a51117cbn/aHeodo
2020-09-05HJ_PBL_090120_GWX_090520.docdoc 908698080dcf9229ad6d3a5b3faa55ad9f3499129372a809d011b6d24ba9d445n/aHeodo
2020-09-05BAL_VUA_090120_CYX_090520.docdoc 3c64a79cdd49b1710bd9042cb9988c215e0050e9ef57e604f4679c45abcafd73n/aHeodo
2020-09-05I_PO_09052020EX.docdoc 1e52c0f38822abee6f044ad1cadcd997d709163955787be931b19bdadab0b376n/aHeodo
2020-09-0539609587.docdoc 7c88f52c679aeb917f52a42b5424f5aeb90901cd44d00fe9aa0608e4f2940cb4n/aHeodo
2020-09-05BAL_4131321843159202004.docdoc 2e997a833026463ee1ddc2b571d97d90c94ac88cdb614cc5e5803d48b640391cVirustotal results 43.33%Heodo
2020-09-05BAL_80914481.docdoc 8feb6780d88f613f38195bca16b4fa8d854fb0ed44fd6e6d4269e483e7d05af3n/aHeodo
2020-09-0582094305.docdoc 2b7b0ff44457a586cf0ca88f5b8f4bee199a18d6c52e494b2ecbbe083c3baf5fVirustotal results 40.68%Heodo
2020-09-0562750521870630107606.docdoc aeab03e8497908eee0038ab3c13bb6e72a8a085bebb429c81e1d6c6dbc28f0d2Virustotal results 38.33%Heodo
2020-09-05INV_PO_09052020EX.docdoc 52dc2d3655da2e0bec58667337f8c1b82e08d7eeb4a73341345f236d3321e9d7Virustotal results 36.67%Heodo
2020-09-0501728045115297063262424.docdoc 5391bbb94eaab89d4864ca7408da299a029611928be8cb4e99c97eabc0b46e4cVirustotal results 33.90%Heodo
2020-09-05INV_688532315861429.docdoc c52e2df61b4f195341a6891702424f8b9798ae3cf5a0a29e6978bfe4bc47b6ean/aHeodo
2020-09-05FILE_506822910686775.docdoc ebc24ae3a35b97e088396a839e1b94a2a71fc528915607e809c1d56780cdf030Virustotal results 31.67%Heodo
2020-09-05P_PO_09052020EX.docdoc 5da552ae322580d7638f987c1c33d95ddf6ce5515f9b5c96ce75ef88111fd5f8Virustotal results 22.03%Heodo
2020-09-05REP_988062628870.docdoc 8d8cc6bdd5c9ff157d1d4967a626d0638a66654fc8ed2af24e807dbc11746e43n/aHeodo
2020-09-05J_59601695.docdoc 8dadb1448be18ff1a6f7368dbef2f14f940b87b1d8133d3a8ef264d547457451Virustotal results 22.03%Heodo
2020-09-05REP_136845768887650749.docdoc 9d71de685c2563ad92db03b5326737a9022c9acc2a3d4ea671e1f96d297d7c88Virustotal results 21.67%Heodo
2020-09-05DOC_15IDIUR2FM.docdoc 7332b5582ed72e5d0f8ddd61b24b1329f4a0e3b5083cbe586c00e49f88e04b46Virustotal results 22.03%Heodo
2020-09-05DU4540911777RT.docdoc 60b865bf47919000a88deabae15f03836f7a97fded9224d81a04722c88461f93n/aHeodo
2020-09-05REP_PO_09052020EX.docdoc 3c0391237b2adda4499615dc19541883ee3a71e7c2db9eb3b3eb02f1b15d8578n/aHeodo
2020-09-05KOJ_090120_IZH_090520.docdoc 6289f2e9039d8290e8166b5e1251bcd8d8317a3c458b4d21b7e210f113245c7fn/aHeodo
2020-09-05INV_PO_09052020EX.docdoc 56c847d2b7384b5406bac28244f2abc04230c231e066dfb357bbf635c1d9d368n/aHeodo
2020-09-05L_72093060.docdoc 6e94c41aeb7553891486189934d9ce6825f6cd5654d06c01dbeb75bad2f298cdVirustotal results 30.51%Heodo
2020-09-05I_GUV_090120_MVT_090520.docdoc a28bed0e6c711eeb502a3010ff335a7ea57b90b01015b2272fed8989245ba6dbVirustotal results 25.00%Heodo
2020-09-05INV_18313149.docdoc 4c903b5a31a9f3c899eef444b340a7b8ef976419af252bec53202c9f06614150Virustotal results 25.42%Heodo
2020-09-05V_WUF_090120_CCB_090520.docdoc ebfcd70ebff55e62fec45d3a0788f6e8c9c17580d337ada36af00299b4fc89f6Virustotal results 23.33%Heodo
2020-09-05FILE_2187304266725823627533.docdoc de2503e4fb1d6a3ffc85f8c066f1573bdc8ae0aec1a0dedeae271c96d1b558ebVirustotal results 25.00%Heodo
2020-09-05FILE_22658689.docdoc 46e3ae5d8bee1778c4331df7909c3a49ad88fee188495744d4fdd8e6828a7184Virustotal results 25.00%Heodo
2020-09-05REP_14945635.docdoc cf6719f39578634ece9de98d7e1fae9627af684f706d094e9f022876dbf8e9baVirustotal results 25.00%Heodo
2020-09-05BAL_JK6388109991BK.docdoc 8d5986085cd34ff48a11330bc6fdb74cfb01bc4f473cbdde5f7d4e8ca5cf637aVirustotal results 18.97%Heodo
2020-09-05YVEKLS9J0JDS0.docdoc c32724190cce2c08e0ff24aec9d392c06d60d948d66449850678496e1427640bn/aHeodo
2020-09-05XM5752455524VY.docdoc b0cd6dfa37b5ec1f7aa767cc0ba3e8a177b5aad0da60b21f7a494635de26a792n/aHeodo
2020-09-05PYVE_NHQ_090120_XCW_090520.docdoc 7606b8d97f6f0d095e872da44df2bb9031c8a2ec357607c82febb8cfa5b6060aVirustotal results 25.42%Heodo
2020-09-04U_PO_09052020EX.docdoc 1ea07b1f6a176869b2f12e0c7cd4f06eef620ab6246efad4b6d74cebbf441c5dVirustotal results 25.00%Heodo
2020-09-04BAL_58307801.docdoc 2f43042095548e57c08e93e9da55256337e669662c48bcae3ebc01a9b3113cbcn/aHeodo
2020-09-04REP_0002144281679801.docdoc 42fa7e03e642ef8e9b55006d837fdcfe0edc2260c882eae114f1505365f15475Virustotal results 26.67%Heodo
2020-09-04Y_66908449.docdoc f4ed99cccf3436ccf82ee81f454adc4b8f7a7d2aecc14226aa8675e95f42b0e5Virustotal results 25.00%Heodo
2020-09-04028323051780586188253860.docdoc c208f04ecc5199d2aa6be7c3c9ca89a5ed6501d3c090cbf7775566b0a40d4570Virustotal results 18.33%Heodo
2020-09-04REP_PO_09052020EX.docdoc e3dc535e0f5a45859e8c323deeb9865a9d02594ce15fc062b0a65984ff34023an/aHeodo
2020-09-04INV_76N9O5OTPL5RS0.docdoc 39fad32ff15c2ae8485f5b1e8d4c14cd1a34797e7c59d7569ee52834d69c1b02Virustotal results 18.64%Heodo
2020-09-0467651962.docdoc b5533222607313c1e5318c308f318224a53034815f0c64c398f7a47c3a022efdVirustotal results 36.67%Heodo
2020-09-04SH4057833556HP.docdoc bd40eb02dfb6582a0297389d221e0c4e0438e0e49084f6b38a362f9e0ed59d0fn/aHeodo
2020-09-0445701456.docdoc b68a67814fb5dc91945cdd229252bd373e46dc667e3f5c91e37f1ffe0fb546d3n/aHeodo
2020-09-04BAL_71514675.docdoc 36175bb468657b427148c493fa79bd8b5a274d61b18bf20ae6de60800a42e644Virustotal results 37.29%Heodo
2020-09-04BAL_39295648.docdoc a7680798d59287fd95857a80ad4476ee4e1a98ed04c97a6afcfa5f523ab1ecccVirustotal results 37.29%Heodo
2020-09-04XBP_090120_MFC_090520.docdoc 5ca09a4a4928ed469d1e0eb9dacd92fe2003d0551aeb380a0c662ced78d6fa25Virustotal results 36.67%Heodo
2020-09-04BAL_72077251.docdoc 4ef546f286f47adeb1332f3d817a9aaf39d7ecc531a022b9791eb14fc9de79acVirustotal results 36.67%Heodo
2020-09-04FILE_25341125.docdoc 0ccc2086f49d393bf08092469d40a557d9b68c3653500e5826e7479b69b84c6an/aHeodo
2020-09-04DOC_S4Z84QRKZU10TWVM.docdoc d23faf09d666b06ecc0248933f0050591863e4e0eca630cb4c1be7f58512fb3bVirustotal results 36.07%Heodo
2020-09-04ZZLL_R48J5JJR353KUUR.docdoc 07389e60fd9ae8ed3322e4d0d71325e58d8beabc1b3a0e18bbcfc7984505e598Virustotal results 36.67%Heodo
2020-09-04PO_09042020EX.docdoc da9a6385696d505459b043b8444346c7faa2614fd5f77a0e0df5110774036e08Virustotal results 37.93%Heodo
2020-09-04BAL_30087168124359056617.docdoc 0885a2c59985b958177938ea4e58d7fb455576cdb7c36958e0207b29f7f52931Virustotal results 37.29%Heodo
2020-09-04DOC_X465KQJZHRJJX.docdoc 0a5690b216f895e3721c8a4309a53c779fa420b6f40d510309d69d27ffaa84a7Virustotal results 34.48%Heodo
2020-09-04EM5012748307GH.docdoc b704f4df9369996d3f77982e46cd1d4b080de1817ffbd8d68f5f4a82e16b1993Virustotal results 33.33%Heodo
2020-09-04B_01049676210921979147.docdoc 5b90408d4dc272f4943f37e60d8892e8663d56e2b299acec7cc5d8ad5be7a40cVirustotal results 33.90%Heodo
2020-09-04BAL_PO_09042020EX.docdoc a2fdc9abbb2377b367097472c437e5a8ffedbf8e9b27eaa1e230d8cde71f89f7Virustotal results 33.33%Heodo
2020-09-04FILE_19108520.docdoc cfe4b358946c9eef325f5aa66f80f7db38ac84fbd985117f1bbf039bba8a3d9fn/aHeodo
2020-09-04FILE_47693698.docdoc 3212bb6c80b78835f1e18093791987c2ad8b31e57c295a67264ca87c4edb0ad2Virustotal results 33.33%Heodo
2020-09-04VFI_090120_LMR_090420.docdoc f265c11e67bd9353ca8c6d02ba6c752387a993a73e75006a6b28857634c8b7cbVirustotal results 33.90%Heodo
2020-09-04R_PO_09042020EX.docdoc e518aef76084cd1d89c2f34eb4960ee623c0f2f87dd31121f0f4f70c376753f3n/aHeodo
2020-09-04FILE_PO_09042020EX.docdoc 478c0a63a9f6339a032b46388e0228f0306a3be3f5938e8018e26169347460e3Virustotal results 33.90%Heodo
2020-09-04GXO_10529589.docdoc 2130681c6aad2c8f3371feaa59b9a21724fa49c49a4fca8fcd6773e0b27e2bbfVirustotal results 33.33%Heodo
2020-09-04I_PO_09042020EX.docdoc 121bf03a4ab3c4b45e699994504ce2bc327aea720cbac22a23c8b3fbf220e5a2Virustotal results 33.33%Heodo
2020-09-04WOD_090120_MUK_090420.docdoc f19b7c3502d8e70e4a41fc4676cf0ba7a1de47cc19b1e961be4ceb8511119637Virustotal results 49.15%Heodo