URLhaus Database

You are currently viewing the URLhaus database entry for http://valleymedicalandsurgicalclinic.com/ujftb/statement/wr7hoba7i9hz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:494116
URL: http://valleymedicalandsurgicalclinic.com/ujftb/statement/wr7hoba7i9hz/
URL Status:Offline
Host: valleymedicalandsurgicalclinic.com
Date added:2020-09-14 10:47:04 UTC
Last online:2020-09-22 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 10:48:27 UTC to abuse{at}choopa[dot]com)
Takedown time:8 days, 3 hours, 12 minutes Bad (down since 2020-09-22 14:01:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17INV_43164216.docdoc 1696e01404af8e515a6ed2d5b48c04a659ac1ac279a678816278240d1ce7b9e7Virustotal results 67.80%Heodo
2020-09-14FILE_LP4764879444ZD.docdoc 21bdbf6ef88670da6f32d97e4d4d1ddaad79bbee1a8d10d476ef78b5a63e14b3Virustotal results 23.33%Heodo
2020-09-14MDC_PO_09142020EX.docdoc 3df3dbd30ceac68478a45ac4777aa409218d8ba43eed7546cd42682c95c17478Virustotal results 21.67%Heodo
2020-09-14FILE_79015650.docdoc c2e8f7c925f56e68086ee279048349eaede27f3cff8aea65d4298610fd97a3d9Virustotal results 21.67%Heodo
2020-09-14DOC_PO_09142020EX.docdoc 35087d749d504d6fcc9959894bd3cec2ff4aed21cc086ec8f4b945dc25e0ceb3Virustotal results 23.33%Heodo
2020-09-14SKBS8ILYMUW5II.docdoc 44dd298e5761ecfbf28b770c3adc34854679aca9c88565aef9e0f7d426749cf9Virustotal results 24.56%Heodo
2020-09-146748256232722575614852915.docdoc f14c6bc62e459f57fcbf3044108e087966c7f90e706b655248f9707410094bccVirustotal results 23.33%Heodo
2020-09-14OY4221548985GU.docdoc fa69858e237719a046347129a4fa0d2bad1890e1843c54a8e5d71568337ee2cbVirustotal results 23.33%Heodo
2020-09-14PO_09142020EX.docdoc 093763d4cb36fc3e586ed3f34a6168b60a03c5f26c4c7b517235e4b2edf8507fVirustotal results 24.14%Heodo
2020-09-141798350045796.docdoc 35d228bcb40d6ffeeeb2b9fc34835a7f18201a3f6b691a33a47e8712ae098011Virustotal results 24.14%Heodo
2020-09-148385346623925498883040.docdoc 31abb0e2ba0192304333d56aad7d95895e53a406ac2a34a4eb5b3233461088baVirustotal results 24.14%Heodo