URLhaus Database

You are currently viewing the URLhaus database entry for http://bjbus.net/isaac/report/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453760
URL: http://bjbus.net/isaac/report/
URL Status:Offline
Host: bjbus.net
Date added:2020-09-05 05:29:06 UTC
Last online:2020-12-01 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-05 05:30:05 UTC to abuse{at}eboundhost[dot]com)
Takedown time:2 months, 26 days, 20 hours, 18 minutes Bad (down since 2020-12-01 01:48:08 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-196113080903902830544.docdoc 6e9220f4a8d666291828738cd4f28e800327f11fef9323a16a66f20a9a1609b7n/a Heodo
2020-09-05E_UMC_090120_NNM_090520.docdoc 8b23e164f16ba0caed21611db9782895ac3a6a1f5b30a16e7cff6a2f8e3c3008Virustotal results 44.07%Heodo
2020-09-05LGA_PO_09052020EX.docdoc 7813e0676b9ac895750acf882aa69b95b64a212515208262219dd072a51117cbn/aHeodo
2020-09-05KHF_090120_PUF_090520.docdoc 908698080dcf9229ad6d3a5b3faa55ad9f3499129372a809d011b6d24ba9d445n/aHeodo
2020-09-05A_01949521930890084882975.docdoc 1e52c0f38822abee6f044ad1cadcd997d709163955787be931b19bdadab0b376n/aHeodo
2020-09-05JMF_090120_FCT_090520.docdoc 7c88f52c679aeb917f52a42b5424f5aeb90901cd44d00fe9aa0608e4f2940cb4n/aHeodo
2020-09-05L_PO_09052020EX.docdoc b47773387ceae19a77df17722ac76711cd26f753da32fb7f1a43302d5523bf59Virustotal results 42.37%Heodo
2020-09-05FILE_PO_09052020EX.docdoc 9dec32ba9b743147a0bb4ae8041825a74aed44d6dba4f1ace85a6a008227cb0cVirustotal results 41.67%Heodo
2020-09-05G_LDZFIFFMOZ.docdoc 8feb6780d88f613f38195bca16b4fa8d854fb0ed44fd6e6d4269e483e7d05af3n/aHeodo
2020-09-05DOC_PO_09052020EX.docdoc 78fe3a4dfe2181b8fb57b9b3a71c67e98d2227eed658230d2a7557db9eadd89aVirustotal results 38.33%Heodo
2020-09-05FHA_090120_DPK_090520.docdoc aeab03e8497908eee0038ab3c13bb6e72a8a085bebb429c81e1d6c6dbc28f0d2n/aHeodo
2020-09-05UP_05054876.docdoc 7a30501200d16da77107068379331700e901268be067ce701617b4df11238b75Virustotal results 33.90%Heodo
2020-09-05BAL_16915614.docdoc c52e2df61b4f195341a6891702424f8b9798ae3cf5a0a29e6978bfe4bc47b6ean/aHeodo
2020-09-05BAL_XDR_090120_QNQ_090520.docdoc 5da552ae322580d7638f987c1c33d95ddf6ce5515f9b5c96ce75ef88111fd5f8Virustotal results 31.67%Heodo