URLhaus Database

You are currently viewing the URLhaus database entry for http://webito.eu/old/eTrac/uxtcju/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:529753
URL: http://webito.eu/old/eTrac/uxtcju/
URL Status:Offline
Host: webito.eu
Date added:2020-09-16 10:05:04 UTC
Last online:2020-09-20 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-16 10:06:18 UTC to mo[dot]sadafi52{at}gmail[dot]com)
Takedown time:3 days, 23 hours, 24 minutes Bad (down since 2020-09-20 09:30:22 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-18K_PO_09182020EX.docdoc 83676faad35894bb04262d898f1279995a52ca4f91f343223e0403b6c915311eVirustotal results 49.15% Heodo
2020-09-18REP_QEC_090120_YOC_091820.docdoc 1783b7210fc11d49c254e9d01607f32e9124044eebc736c34bf7d3fe06d7c0b0Virustotal results 49.15%Heodo
2020-09-18FILE_95148163.docdoc 81098064cd4ad8fdf1ccf43093703418fee8dffb9970aa44e9f9be469df9a310Virustotal results 49.15%Heodo
2020-09-18REP_FGP_090120_LQX_091820.docdoc c5860ceb1f0030db0b4e716f600d818fb77b6d0ae4a2154291cf4fae1856cd7bVirustotal results 50.00%Heodo
2020-09-18DOC_PO_09182020EX.docdoc 1a9901bb02a8db1051d8eeeb1318426ca8d790cf5a1e39ae48545bbe0e7a0f31Virustotal results 49.15%Heodo
2020-09-18BAL_KDA_090120_UGB_091820.docdoc 58061f1266dff582938c173bf8f0d73a71593d7d31e79899973ab5eab0d0596bVirustotal results 50.00%Heodo
2020-09-18FILE_LLL_090120_OTY_091820.docdoc 4401b8e76e1cba8daffe10ee7151f70d1ccb78a6857c49598c33f9b8bade1541Virustotal results 48.28%Heodo
2020-09-18REP_PO_09182020EX.docdoc 37058579c0adf49f3f4170d008f3e01704bb07a33edd9b8bb1173e8127c85904Virustotal results 40.68%Heodo
2020-09-18AW5648153503RD.docdoc 58bd7739a1a006ece6b332089b3495f7a5d43baf7f66aa3dfcce0ff1c5e8e098Virustotal results 40.68%Heodo
2020-09-18INV_48485935.docdoc db5b2b2884b15b7c147a886a252cc856516d36b4c8fb587dc9a46063f39153a1Virustotal results 40.68%Heodo
2020-09-18BAL_PO_09182020EX.docdoc 7a087796ba52981da1f8e06f79b5bd1bdebeb961afe1f01af7864edfe071712eVirustotal results 42.37%Heodo
2020-09-18FILE_ILCQW5SJORF.docdoc 7c59a227af18d0ce74f71bcd465aeb811332968c24b837a6d9761a61bf0b2abdVirustotal results 42.37%Heodo
2020-09-18S_BLY_090120_MOT_091820.docdoc d35c221d6da8fb62ac4d9b14ed2a8112b1d26af20f8f82a0ee4b60fcaa759903Virustotal results 43.10%Heodo
2020-09-18DOC_WV6849665357IV.docdoc 07610dc0b3d7c1c61c9b30505f85c5cb407258560a13dd183500c1693dec0dadVirustotal results 38.98%Heodo
2020-09-18REP_01877575.docdoc 57c17b60cd1c361ac69813484b6a4f453aa7cf993c0ec2338665a320341e496bVirustotal results 38.98%Heodo
2020-09-18N9AISOD81.docdoc ed98997bd450d0c8f1285f0677f4735e52e35f8504b6ab44ca0af91650f29ac4n/aHeodo
2020-09-1882002174.docdoc f6bd46837e705aee39428d412f28116876f6351e1148b7ce01d5e1848b7d0061Virustotal results 36.67%Heodo
2020-09-18BAL_WM5693493604OT.docdoc b157c7e4296be966f45fa1efac02053cbc78a6c2012faf885bd9654287f0f35dVirustotal results 35.59%Heodo
2020-09-18RE9540691116OZ.docdoc 344be8e47a1c334ca0f6e8d6383c509d62ca9004f050e5a368e064e87e2e947fVirustotal results 35.59%Heodo
2020-09-18BAL_UG1689136202WL.docdoc 5c9ee841d3f2ca4934e2df7970319d3d7eaa875a68f3df8f691f19191fd138feVirustotal results 36.21%Heodo
2020-09-18INV_833750814115348927765.docdoc 043a2eea0e970c626f6ff1aa5ec43ffd5974bb5192e55c0595ca6b3ef0404fd7Virustotal results 34.48%Heodo
2020-09-18O_GNSVMT4J2IZMI.docdoc c63f6783c00a837e235c2c2405fccfe135bf4358704dad7525b4660588e6ed3aVirustotal results 36.21%Heodo
2020-09-17MB5CJJR2ULXV9D.docdoc 0606ba599bf7a4fca591dc6e4c5b29805cb37284a37a2cefd0f5237a52ce46acn/aHeodo
2020-09-17MVY_090120_XKX_091820.docdoc 3d0e327579a0412b41e40642776caf0be54df0872df9e9ce553e048802249ac0Virustotal results 33.90%Heodo
2020-09-17DOC_PMZH2C362Z91COQM.docdoc ebce78b8c9a54b4d497ed1c424eb689cd0959596daf9f6748a46b65aa84b91daVirustotal results 35.00%Heodo
2020-09-17DOC_617203507467819.docdoc 11cfbdf8ce4f99c93816a1ed7ff7410d051b0cc978efc9ff9fa824db596374e5n/aHeodo
2020-09-17REP_70196054353344700544.docdoc ee811cdfd43ecaeeeaa64d3ce8c80c91740d968333e17fec9cca54341338c471n/aHeodo
2020-09-17PO_09172020EX.docdoc 794d05a964943c6e59eef584b6bd5ee060dec7907a990ec1a0d71260e641c74dVirustotal results 47.46%Heodo
2020-09-17GB2720590408PG.docdoc 594c81be9be769fefbfc0df02c470a9ef138fac68992f136b55532e736d0e93an/aHeodo
2020-09-17QOM_XA2564141954VM.docdoc c3398d0143d68598160025f752138b7d986b35d277e83d05c6afeca8f7cced55Virustotal results 35.59%Heodo
2020-09-17INV_035556319564537864468.docdoc 9d101c9ae5aad02aab0e581cf566b9cf7e1f0e39db512e79045e651ee42ab9a6Virustotal results 30.51%Heodo
2020-09-17FILE_N0YBDZZ0NTR8R2.docdoc 79d28b1f906f26beea84fa259a3953fa6fedf70176ec6a5bcd77e724f4d326abn/aHeodo
2020-09-17WINL9POSA.docdoc fe6c61d58e613b1737dd42c11ceb421b40f8f854324adeecb71245e245ed3a34Virustotal results 36.21%Heodo
2020-09-17REP_IPGNQG3G7QWP609.docdoc fd0f987936c01acfb91bb84e9e9c3e6f425f55d07887f14ee595ec418d252849Virustotal results 40.00%Heodo
2020-09-17PO_09172020EX.docdoc 51d460db7db57fd212907c9aed23bba4891c43175f73978da2c791c60a412c43Virustotal results 38.98%Heodo
2020-09-17BAL_PO2687999520HG.docdoc e64cd0cc87e91f49c5f464ba9d431f7c1aee4d72efec763b2dc96e32d698ebaen/aHeodo
2020-09-17PO_09172020EX.docdoc b01858672d33ba389a6a20f1c3d0cdf3987bb6f7d3009d178478ec6bf0fbd674Virustotal results 37.93%Heodo
2020-09-17REP_956586118235892508794.docdoc 9e4278eac329ac03d6c9b60c69594f50d2efb41914b428309216bdfe5ae15904Virustotal results 39.66%Heodo
2020-09-174749983974712707665733.docdoc d15ec5002184364b882e5c3dc5c4fad1d083eeac52de352b2d263205c92e3165n/aHeodo
2020-09-17700261713.docdoc bd1df420c9abd76301cf6f1f9bc3fff3ae1c4e3601ac5beccb4f54777402c959Virustotal results 37.29%Heodo
2020-09-17DOC_PO_09172020EX.docdoc 163a09323a2678ec297914024703f458b53d81470967ee69eb352bb51a5d4f92Virustotal results 33.90%Heodo
2020-09-17DOC_TM4XAAGLZTYZE5X.docdoc e09973ac979e2a9efbdb59ea10416f8714545ff719579b21a48327219a3ec797Virustotal results 37.93%Heodo
2020-09-17BOTE_IJBWUIWDZPZQCM.docdoc 6758d3603f3eab05e72d8c9e6f7714f93f572ca89397a5018c8104d0c6099810Virustotal results 38.98%Heodo
2020-09-17FILE_DAP_090120_GQX_091720.docdoc a2d7a015bbf13ab37b0062c97dce2a11c02f0657166b6fb813780017ba5de723Virustotal results 34.48%Heodo
2020-09-17DOC_MA1586174266CE.docdoc 430ef6af760d2105f3c14655f66ff5dc191916c938a26256085965a4a536c827Virustotal results 32.20%Heodo
2020-09-17DOC_YUR_090120_IHP_091720.docdoc 524f6d1744c625d4ee827ab1ee1406f5aeef8c8799b8cf6474c2a53014a1dfadVirustotal results 28.81%Heodo
2020-09-17INV_Q4CJB9AUYZHZPF.docdoc 6d9cad95f8aa3d8219f21391e294a8dedbde904308f501b7f4be63eb92a8dcf4n/aHeodo
2020-09-17TAO_090120_FBC_091720.docdoc 528a62bc2a5bb42529a57abc0367b0a612ebe84f846906aa5a6737e759d6ae84Virustotal results 29.31%Heodo
2020-09-17DOC_UN1415694102DX.docdoc ba46d0a65699ff5ec5670d31287ae8d04710450b5d267d9e4a2fdf0e94078194Virustotal results 25.42%Heodo
2020-09-17INV_UW1758873933OY.docdoc 8f96a4ee289f6093a2f1afe8c584cba4a802c054ef22fde70d451254191872fdVirustotal results 25.42%Heodo
2020-09-16MYNF_SC2887390492WS.docdoc e7631c5a69f76fea0835835a14a8e885f2f3b0c0dec2d577278e70d3776eb0a5Virustotal results 26.32% Heodo
2020-09-16019877324895053.docdoc e247f4f69c1be4c95bdf6687e2ae1adbd1635c126ace3b544ad989024da5fb3cVirustotal results 29.31%Heodo
2020-09-16J_XOLG9XZP.docdoc ca5204766a181d5961896a0f4c506ed00718fad078c3a951d9343e52ad7f16d4Virustotal results 25.86%Heodo
2020-09-16WAF_090120_YLN_091720.docdoc 76bf8d09a314a6ed1f11e8794d3027fcedcc3762677e37d8f7a304e4d370837cVirustotal results 27.12%Heodo
2020-09-1684248943.docdoc 11edbb83a5be58e02605322f9c28134420f1aafe0e30a23b264ef751657c70daVirustotal results 25.42%Heodo
2020-09-16O_01154818.docdoc 85ecc831aac84128028e315d8229777d99b91e6adba5a437b18e0f2a3c34e76eVirustotal results 25.86%Heodo
2020-09-16C_34442314.docdoc 39c83fd21ce730714e93e6bbe85f21770a761285c3fd1b2b2473e00644785e82Virustotal results 26.32%Heodo
2020-09-16REP_28954921363154551483253.docdoc d30169f108ec72fbaf16bb8726e798602988e1c42a7b3020b0ef0ad0572f9625Virustotal results 25.42%Heodo
2020-09-16OQY_MFC_090120_CBH_091620.docdoc c0418ebecc711ff38d29eb29f832c78c462b0c3f55201223702aac43a15f8e1dVirustotal results 25.42%Heodo
2020-09-16I_PO_09162020EX.docdoc bdaa75534d024a0bf2fb586f5f1f81f78e42b92858a51b651541537908519075n/aHeodo
2020-09-16BAL_JH79Y0YICUMKR.docdoc f656f7fc2ac175767aea79393803f493b18211403a390c2daf9c5dae720e26e3Virustotal results 25.42%Heodo
2020-09-16DOC_PO_09162020EX.docdoc fd4fb3464a7f787ee4d5b1795fe7b4d8ffde4a1683fc6620602fb78ba52f52a9n/a Heodo
2020-09-1698110510.docdoc dfa214a6c649b4cf4acd5b30977e16134b4357e994a10a0d1f1147a53a9bf383n/a Heodo
2020-09-16JA4285720233PG.docdoc d1df096853342d0030f71b7be3c608ee35fd1c81bce971a45e00b001a7d85d3bVirustotal results 25.42%Heodo
2020-09-16BAL_WMU_090120_JSH_091620.docdoc d7f12b14c351620ca64769a126560507c4746cc966510d04d0fa882e521128c4n/a Heodo
2020-09-16YZ_PO_09162020EX.docdoc 37af168ebcdcec12d2835ecc3a569839ed4660717927ae3ab0cc6a4b8a733012Virustotal results 38.98% Heodo
2020-09-16FNO_090120_QLK_091620.docdoc 1e5ed60832baaf0e362870373615cff90279bbbc4e544c76224f7528687276eeVirustotal results 37.29% Heodo
2020-09-16BAL_BEY_090120_WPV_091620.docdoc b2a8ffc1f00ac5b5f607e6a6e0327888e9578b9e746e49ffd390af493f888136n/a Heodo
2020-09-16DOC_73264959.docdoc 2ed87b6a729e1a7f3e6630bab57b2254b83a7cf47124bdee8823e08453bbc917Virustotal results 38.98% Heodo
2020-09-16PO_09162020EX.docdoc 4254483388cd90e041291de79b3a3d26456908113cb0b2957401b5838c949c38Virustotal results 38.98% Heodo
2020-09-16INV_3198349432.docdoc 1c3544c3d12411b68e3260fa40e9dc0826c344c9a131928a04c7f8f517166645n/aHeodo
2020-09-16JAG_090120_XNM_091620.docdoc 201b4b59a31c60055c285e64737d5bcba8974b4400c27f37765636deea097b30n/aHeodo
2020-09-16Q_AM8709926317DM.docdoc 6820256b4c1c4c5b50146126f828d2317ef12e023043a390611fe9b036cfe638n/aHeodo
2020-09-16Q_86506864.docdoc a424bb668e3635e2ea396355dcc0b960f919760ab25aab75f0e36c95feb46c12Virustotal results 33.33%Heodo
2020-09-16OS7496794643GW.docdoc e5c37ebebf58e59d2a4855aa35821a501f6412b3960604cb50fd0d14009888e9n/aHeodo
2020-09-16DOC_340693587005394759689839.docdoc 895d3180e6cd0f21d0b56b5061eb6a16f029d010fc833dd6fc2b85ebbbd6b76bVirustotal results 32.20%Heodo
2020-09-16PO_09162020EX.docdoc 8f20ff26311834e143d010f2fa23f292d4d619b34cf2639d9d4ef2a7e4df9d8fVirustotal results 28.07%Heodo
2020-09-1687467743.docdoc 7d29e749c79d53fc5303ab43bed236a5f884e21617771cce4518860bd7bec1f3Virustotal results 25.86%Heodo
2020-09-169645538587507.docdoc 453fc431889b51f4fb7acf5fc4e22eaba8197e7d496d65d45233adbc854431f7Virustotal results 25.86%Heodo
2020-09-16REP_PR9881147053KT.docdoc ff0be8f9b0efc6b14928e8ea89ffb82ebe82f74db08241df5ec7713c073dfe91Virustotal results 24.14%Heodo
2020-09-16FILE_PO_09162020EX.docdoc 0e0913f7c913e70406fdc7b5e47f2455d7152c4e461770cc1b9bee581491fab9n/aHeodo
2020-09-16DOC_7828991637099829435712.docdoc 4f21e25c362b1dc72f9dd3b2b0910516918a46a4016a631a2ee276493d7d160dVirustotal results 20.34%Heodo
2020-09-16ST5388992111UQ.docdoc ba11cc626e1527c8dec4bf3fe20af2a338030cdb646252a4e170d19512d19d89Virustotal results 27.59%Heodo
2020-09-16REP_0086457491063136823.docdoc c24eaf2c7e9192b22bdb558cdcb458e6de607d17f373c4d46d92561b2312f1d0n/aHeodo
2020-09-16PO_09162020EX.docdoc b8d558c1ac20808b0809fcfa0c5a017da7e300736b6dbfee52ed1930c7b19a08Virustotal results 20.34%Heodo
2020-09-16INV_XT9384605003OL.docdoc 8398f9c5f37ef0558a84d839ee7058340351a71fe4cf26d2590652a5a66857f8Virustotal results 21.05%Heodo
2020-09-16REP_07312650.docdoc a77ef77d33744bee43471f6efd79797f4e3b790cb616c1a01e546f03a4e960f7Virustotal results 20.34%Heodo
2020-09-16DOC_BBP2QRGVQJ2ABT3R.docdoc c81e73cde0ba06145f34071dd88dcaa6a7a0490d9096b1c3f78886fbf5063669Virustotal results 20.34%Heodo