URLhaus Database

You are currently viewing the URLhaus database entry for http://blivegrp.com/wevqp/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:521552
URL: http://blivegrp.com/wevqp/swift/
URL Status:Offline
Host: blivegrp.com
Date added:2020-09-15 23:03:16 UTC
Last online:2020-09-16 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002939404 created on 2020-09-15 23:04:05 UTC)
Takedown time:11 hours, 11 minutes Good (down since 2020-09-16 10:15:26 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16REP_LP7043970450JV.docdoc feb760d598f3b0a810214edcedd3e0ccefa48d12ba8c1dfb200aea8d382b4070Virustotal results 18.64%Heodo
2020-09-1607078214.docdoc b8684570ff020824676af136d3c0076181180c4d7abe963ffb04a340ecb68186n/aHeodo
2020-09-16FILE_PO_09162020EX.docdoc e94ff7ee99e57be629d1e0f2be3bada9aa1ae3c87560e031697f35d0d1799945Virustotal results 22.03%Heodo
2020-09-16REP_PO_09162020EX.docdoc 43458ffd76ecd54f2773f4de6f0428edd6be448d42400dee02d183cfa15acea1Virustotal results 20.34%Heodo
2020-09-16REP_LAF_090120_HXQ_091620.docdoc 4a540bbe5b28ae60eb0653093f20bc61ff4d341954306fda4239dc26a7a342e1Virustotal results 20.00%Heodo
2020-09-16DOC_XP1B5DF.docdoc b0a0b8c0689039bcb63108626720aa99a3bf7a6b09f92dba5ac5243bdc3e61deVirustotal results 20.34%Heodo
2020-09-16FILE_G354K4RUR2KZA.docdoc 02be4df68e31c4b3e1357d80caa4f107b113888ff35908ef3d8c4eaa057731b5Virustotal results 20.69%Heodo
2020-09-16INV_19828553.docdoc aebb79d00a5e16152918873b637b5c9a059d85715ebaadaea301faf34273ce01Virustotal results 19.30%Heodo
2020-09-16383802202288576377033521.docdoc abd53fd5f66e4ea484f4c037e59274f3933de850d9e618d2cc9123d48a571affVirustotal results 20.69%Heodo
2020-09-16Z_HH9682434430HB.docdoc 1bb4012e89aef09b80eda22d99a564f0d3e923f96cbf25dc4a78ff6de6dbb31fVirustotal results 33.90%Heodo
2020-09-16INV_RAE_090120_FLQ_091620.docdoc 8b8af9ba9bacf4def64c2e201f101cf7682ad791c1d170e1571b05a144a2e1a7Virustotal results 32.20%Heodo
2020-09-1632961402.docdoc 38ecd62b04b76c28921cd29f65b7ccde2a36b4414a258682357c05b925825953n/aHeodo
2020-09-16BAL_YJE_090120_EIP_091620.docdoc 4925033a50cdf185c0bf7ca724be9b934b182fb4052da144b80a85f5f58bfef4Virustotal results 30.51%Heodo
2020-09-16BAL_VVX_090120_PZQ_091620.docdoc b75415103d2353ac48eeb8630f5fb9c840dc5b1653351fd68b9a18b4bd070b5cVirustotal results 33.90%Heodo
2020-09-16PO_09162020EX.docdoc f8033b99d4728d0e4ad633cd47aa7df527d0cfe6aa3808bbb2f120f4f6c7d931Virustotal results 33.90%Heodo
2020-09-16IC5271833916UV.docdoc 62fd09a1ff4be50f0ef342f12c9551165d6f9743f510cadc096752e52e0b296eVirustotal results 33.90%Heodo
2020-09-16REP_81639828.docdoc d4b79b30c6abd6633d513bd08d8b3b9b3de6f0705245b72b3e2ee09e0d03746fVirustotal results 25.86%Heodo
2020-09-16DOC_8TD8OLY4IY.docdoc 17ee903ed9c7b72546d333ce76b2e0996a4688e758937667ff466bb3ff005c00Virustotal results 25.42%Heodo
2020-09-16INV_87500062115.docdoc a4161a1c0ab452048658bdf4e30fe550fe9da9f47ea4525fdb2858949f42887eVirustotal results 32.76%Heodo
2020-09-15ZAM_090120_FFW_091620.docdoc d2939ee7042da0a88a76cc4e60e5a8cfbc83e5b4fad03c547ffb13bb006a2c5fVirustotal results 24.14%Heodo
2020-09-15INV_60891542.docdoc 8869192957c4d226cae4679243a3a7ac5a193866a2e1048e37ca60f29d9af28aVirustotal results 26.32%Heodo
2020-09-15DOC_15481479.docdoc d4369f512f97c8b7c76bc433989129b9805389a353801dfb3ba84b6a296d5ef1Virustotal results 30.51%Heodo
2020-09-15DOC_PO_09162020EX.docdoc cef5fe8cb42c84d6b646353c977ec12cd7118000eb906b2ff5625158c998c8b5Virustotal results 27.12%Heodo