URLhaus Database

You are currently viewing the URLhaus database entry for http://barber.joeyrigon.com/qap51w3/OCT/CL20o19tea/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:529656
URL: http://barber.joeyrigon.com/qap51w3/OCT/CL20o19tea/
URL Status:Offline
Host: barber.joeyrigon.com
Date added:2020-09-16 09:53:45 UTC
Last online:2020-09-16 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-16 09:54:36 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:6 hours, 29 minutes Good (down since 2020-09-16 16:24:35 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16inf_0864990.docdoc dcc3ee11da81996e905f2f00e24483150c0c38eebcfa3d3a8019a6ba1a098b34Virustotal results 25.42%Heodo
2020-09-16Arc_20200916_425618.docdoc 3345219199def661640c5182b7491c413702216149790bcddd8d884e9bcd112eVirustotal results 25.42%Heodo
2020-09-16LIST 1228174.docdoc 4c63c7e06daab078d631af54f867ea7d069092968d6f13eebe34486774a74d9fVirustotal results 25.00%Heodo
2020-09-16dat_20200916_QTV824.docdoc fab310e91d04203eb4a5911d81b2d387893e1913d380f5bd01a0d7d28bfbecbfVirustotal results 25.00%Heodo
2020-09-16Untitled DKN45791.docdoc 9c2e02ead173d8f1fe22a0b2adf237ebd75b82444b7ca8747e428e3e02f9ff58n/aHeodo
2020-09-16dat 2020_09_16.docdoc 1312e631f80e724ea637d1b035eb3342f09a32208ab559bc85cd5820956a5755Virustotal results 20.34%Heodo
2020-09-16UNTITLED P704328.docdoc 94097ebfa15f3baece5e692831305b0e4efb4463b935f178bc21ade65ae153f2n/aHeodo
2020-09-16Attachments.docdoc 7d1dc823474b31494db6b7952b36178313dc9c253934583398554aaf04d4fb4cn/aHeodo