URLhaus Database

You are currently viewing the URLhaus database entry for http://ballatstone.com/cgi-bin/attachments/VH7WfaAMIe86fm18ljS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:540409
URL: http://ballatstone.com/cgi-bin/attachments/VH7WfaAMIe86fm18ljS/
URL Status:Offline
Host: ballatstone.com
Date added:2020-09-17 02:41:34 UTC
Last online:2022-03-14 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-13 23:40:08 UTC to abuse{at}ozkula[dot]com[dot]tr)
Takedown time:1 year, 6 month, 3 days, 5 hours, 51 minutes Bad (down since 2022-03-14 08:34:26 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-13n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2020-09-19File_MWM7867.docdoc 75e37e5c3591743af109482748f2a48e550f1a9d767316a8cece66fb4fe8c222Virustotal results 22.03%Heodo
2020-09-1957940RKV 2020_09_19 4259.docdoc 4f95474b074798a5301ed054cc87ee6768a0c44b9d2a39f679750741537dcea0Virustotal results 22.41%Heodo
2020-09-19ARC_20200919_337206.docdoc e4873536ba7b163dc9a87dd2dc7d447b502e63eaaebf88fcf4635d423772db47Virustotal results 22.03%Heodo
2020-09-19doc-F2291.docdoc 57335ffb483da81d9154676109daceab8f15e679af95fe3d0313f09d70619d85Virustotal results 22.41%Heodo
2020-09-19ARC 20200919 2840.docdoc 23c8490e131915effd12a2adf737b6fb74515b1b54759d0bb237eb7392338c08Virustotal results 22.03%Heodo
2020-09-19Dat-20200919-820395.docdoc a6d4e72568e642cf4b7ebface0d1efd59bb14b348af845c74bd132af71733f53Virustotal results 23.73%Heodo
2020-09-18inf 20200919 36082.docdoc 000dd08101567f408a0ee2b7d095d3baa02f532ed3839f66b60b9d64ce065d17Virustotal results 22.41%Heodo
2020-09-187194252-930613.docdoc ea48e310224317a3a93d7679dbb50ae967383d973cf7713613d8a240224ff454Virustotal results 22.03%Heodo
2020-09-18REP_20200919_289.docdoc 1b92e7710017ee24f07eb3119de1f3556bc53d686201c428cf4538d133fa8fa7Virustotal results 22.03%Heodo
2020-09-18File-243632.docdoc f56906e33a9a9bd3b074b3b5c24c2e98ba58817c4c61452977054f27d0d9312dn/aHeodo
2020-09-18Untitled_20200919_HXK963313.docdoc 8750d49fc1ba34c16ce392d088b1843101a6669f5407b567c2dff708351b81ccVirustotal results 22.41%Heodo
2020-09-18dat-20200919-52373.docdoc d28151cda4058aa8e8c1175ab6fea760c7c6812f758570a50fca1ad2b52eea2eVirustotal results 22.03%Heodo
2020-09-18Inf 2020_09_18 1131845.docdoc 59be634c99d32cc1d2bdfc3663c81ef4a20e38bfb841fb02cf3152233aa9f7b2Virustotal results 25.86%Heodo
2020-09-18780 20200918.docdoc c3b361e3ab7b82eb20f5af057abff8f96c2369d0dbc47472ab1430390ae8de1aVirustotal results 25.42%Heodo
2020-09-18Untitled-N8634.docdoc 77dfe2eeed80414b4e3a1702fd0d7443e23a4b8ea93460bef56458aac2b2983dVirustotal results 25.86%Heodo
2020-09-18LIST_20200918_84742.docdoc 39ab2007df6e588e7a2eed34c24f22b1584c9fde9877b59dd8b7441962940d38Virustotal results 25.86%Heodo
2020-09-189148 20200918 Z321.docdoc c4f84b019ea7621f6f614e11c9bc04c8c47ef1b99e136e16715ec26d26e9f24dVirustotal results 25.42%Heodo
2020-09-18525EW-20200918-907121.docdoc a5ce864f2c3bca89c24abc1fa1068e590b7df70133a6f8d4ddbfb26f3f72a85bn/aHeodo
2020-09-184392_6196105.docdoc 3c932359391f21f99046ff99927040cbdd34c0bb1d8d14a2ef54724ef8dc1df0Virustotal results 25.42%Heodo
2020-09-18ARC_20200918_BV309.docdoc c150a6907d073e3342215712f5898b7b4f1bbbd09664f2163c973bbcae0e2c40n/aHeodo
2020-09-18Attachments-28509.docdoc ceb0ab5a4fac60cae54222c2db10571693e9aab0a23fbe42bfdccde11f0a5b2bVirustotal results 23.73%Heodo
2020-09-18Mes-X1193.docdoc 6176a4b0335761a51b3ccda4f327807782d3be21fe059f2419327b75d42fb5aen/aHeodo
2020-09-18Attachments_2020_09_18_821234.docdoc 15516d337875587c5b3c679d8c166d4e00d5da295727956ddb935e5972ab2aa1n/aHeodo
2020-09-18File-2020_09_18.docdoc 47dd03d21da43926252b2684001feb039dbea83bcc5753aae3d30f193a799ed2n/aHeodo
2020-09-18ARC 20200918 K627.docdoc c82c3dc7341a149248f768f8f7da5e9f1ca7dcd9f2d1cd61a56386cfef07ff7bn/aHeodo
2020-09-18Rep-72673.docdoc 44fc387cc55c1a2b5fc409d86cef0344a9015e93f8bf7ec6f4095485281bbf88Virustotal results 18.97%Heodo
2020-09-18dat-2020_09_18-99849.docdoc 926646a1836f587ca813319f3add693a168a273ba2e60e58283cb000d9ac3b6dn/aHeodo
2020-09-18FILE_KVT71310.docdoc a980ad21eced39ab6179666648e571be61547ca21fc8dfca1d016158af5036c8n/aHeodo
2020-09-18Arc-2020_09_18-751395.docdoc 8e4b5c75dfd8ad1acefed08603f4a69c435e29f076db8183c17703d238ea71e1Virustotal results 20.69%Heodo
2020-09-18list-2020_09_18-7387307.docdoc 7ea8a1c6a1c4f2aeb6aa23ca6a072593db27e100b923c825538f3049e8f2972bn/aHeodo
2020-09-18file-2020_09_18-HA59139.docdoc 82e331bd54e99b710c3f3446239c18c0ac59e4b668cfcc1b78c1d4217173f865Virustotal results 23.73%Heodo
2020-09-18Dat 20200918 915.docdoc 4943c3503cede95a329c908942aa9f465a135fa27dfbe0c2a228bcca9d3621b2n/aHeodo
2020-09-18ZB302-2020_09_18-196708.docdoc 48ac9d4cbe603c96770da6fe47ffaf9f077de0eeba0afe7a94c1158cdc4e2c49Virustotal results 23.73%Heodo
2020-09-18list_98508.docdoc 6e9fc3559e42b8f89e02f650d056188acceaf34fbe3737cc98a6b4a3b5d560d9n/aHeodo
2020-09-1833728RRL 2020_09_18.docdoc 4da1b994d65f75f6dd7560b6a7a456fb11ec4c14383e56265807c38505ba696dVirustotal results 20.00%Heodo
2020-09-1863815033_20200918_2643.docdoc 594585416433605da17c1488ae1060b963d6ee101a0cb4661e8fd9218d96acadn/aHeodo
2020-09-18doc_2020_09_18_880.docdoc 23cbfb675b38359788fb1f2ea9602ba6ad72c26ca1765dfe3c24d4c61b2e21e4Virustotal results 19.30%Heodo
2020-09-18Z441-2020_09_18-OF458962.docdoc d82770d0173c57ba1ca3434b381c95f27754da818c5843476b35475d9beceaf3Virustotal results 18.33%Heodo
2020-09-18file_GT19495.docdoc bc49b2fdb8c323ba1383820a93a3b9350f9bb9bf47f34769b1ca0fd7ada96483Virustotal results 18.64%Heodo
2020-09-18UNTITLED-AC838112.docdoc 9dc810c0e94b657b92a14013ab5effbedb791c6d9bd8addf3cfd176fc1ea7874n/aHeodo
2020-09-18Attachments_20200918.docdoc 1de0cc359d911b8ea7f0d8e8e345d5d3b0565076570c85494e6e4ea147f271d3n/aHeodo
2020-09-18LIST 20200918 09052.docdoc cdbddc6e344dca0161e590649d5937d6271bd7c6fd53cdfac8ac5f235b4b2ad0Virustotal results 18.64%Heodo
2020-09-18UNTITLED_20200918_8066.docdoc 1451a6f5cec836396725062e85afd50a7fa34abb6d99cf0ab08af0e765610345n/aHeodo
2020-09-1882230713-2020_09_18-0172670.docdoc 75bf970f98cfafd5b377938aa46073f7818011dfa98561c7592703fe34dd1c92n/aHeodo
2020-09-186272128.docdoc 8cc271a3c843d86d10e06a206bdb54c29e0879fb671d22d8eacee4b90ce21f38Virustotal results 18.64%Heodo
2020-09-18LIST_2020_09_18_8217355.docdoc 4b552a4b1d58e620d17d255c9d618066b0dfceab6d7146304cea2afbfc53b4efVirustotal results 49.15%Heodo
2020-09-18DAT 2020_09_18.docdoc 6f17adbca4f52f4dced97d473ed1b7b29e91b09a0433a5febfa6292962d92803Virustotal results 49.15%Heodo
2020-09-18doc-L293.docdoc 0df431c411b6f60ead1ff2fdea0f2d4d694e639e4abe69a078792118997f8a84n/aHeodo
2020-09-18arc_2020_09_18_2600568.docdoc 93343d4d5ac39575750388f42909a8ff470366cbae5a3ad577f5bd9af07ccf3bn/aHeodo
2020-09-182309056-20200918-90422.docdoc dca5c450c7d663b7ddd8657472fba6593c71ce0a7d7bff9eb98f72a5bcd57228n/aHeodo
2020-09-18UNTITLED-OZ071.docdoc 186ef4aa313417e178a272142392d6f289c1b9e3c9bc3818b3c04a399670b2e6n/aHeodo
2020-09-18Doc_20200918_68630.docdoc 2ba5f1cb9ab9fa0b8b9386c32eaeba767f452f946a467c92713026a7096e413fVirustotal results 45.76%Heodo
2020-09-18Inf_20200918_OJL04569.docdoc 96d436517f2e35248a049283382d963b8924ec0a569f93a093838f1cce8e3708Virustotal results 41.38%Heodo
2020-09-18dat RP924946.docdoc 1cba542ea755572052ee0ee05629e5f1a0b3161fc11106ad6e2679fc5ee2a6f4n/aHeodo
2020-09-18doc_1368.docdoc 2c884afcd8cbdb6504dc36a8d6f0e78415d4de142b7c977fcbaadbfdbe667479Virustotal results 40.68%Heodo
2020-09-18Arc_2020_09_18_X036512.docdoc f6255c1d9d5c191c0265b5b1fbca564c2a9f38fd1e93cb25ebf3073f0e560e29n/aHeodo
2020-09-18Mes 2020_09_18 IGG676179.docdoc ba2672913493f1b112bd60bf5b2a277361c1ae2122c208c3ce55e55f14da909bn/aHeodo
2020-09-18LIST_2020_09_18_173.docdoc afec45f4897df0117cbcbec6972de56bd81af8ee3e6b1cf88507764596a9f927Virustotal results 39.66%Heodo
2020-09-18Attachment_2020_09_18.docdoc 1aa763675bb57de2419ff0c6db6954df9d9b83b1d05a49fbc33d8db379753db2n/aHeodo
2020-09-181117595-R2318.docdoc 3db14a0f76fa86e356c825ad449d554cdb00374a712dc8ec992b8394c8756b56Virustotal results 37.29%Heodo
2020-09-18LIST 20200918 OB1352.docdoc 0fa784f6a6eaad808c6f9037d5515f435da8c204edba06b50d4839499bccd481Virustotal results 37.70%Heodo
2020-09-18Arc_EZZ8893.docdoc 6d7657e6644c4ace4f65f6639704f74c9f7dd6d2e7e3e3be74c0651d5fc7346an/aHeodo
2020-09-18FILE 2020_09_18 UZR9681.docdoc c386868e3f526e0cd5d9093ae760761ebadb17cf74591886e56d8de0d3097f1cn/aHeodo
2020-09-18List-20200918-ZLA02196.docdoc 48d9902f9387ffc07af22ed14eaaebb093f37f8f63d4942f0d76744ae6f14f4aVirustotal results 34.48%Heodo
2020-09-18File 2020_09_18 587172.docdoc fd6a23dc8063cd09eb09f8a8e111fb0c19101361ec55802cc799481e9047ee69n/aHeodo
2020-09-18REP_20200918_C997596.docdoc d0c7c0505d58965408f42b32eb3cab08e31769ccd07dae21ed285fa67c97f04cVirustotal results 33.90%Heodo
2020-09-18list_7514.docdoc f9a9596b06fd6053fd9fe2f73a3cc010078c12423f3e963d553675df3a02b77bVirustotal results 34.48%Heodo
2020-09-17MES 20200918 288.docdoc 7e471a0df104975c9e269668322c7a09a6892fc3a375150e2c8b0eef6b7b6f23n/aHeodo
2020-09-17MES-20200918.docdoc 5fd9e10406e6fb2c743d52aab24b37441334d06a9dff4df20769ea386e670e37Virustotal results 33.90%Heodo
2020-09-17mes 20200918 W669.docdoc feb00cf0951b885f06436d5b736151889e0ec20fe5cc1b48f5431eaa9878c209Virustotal results 33.90%Heodo
2020-09-172121 21822.docdoc 578663ca789cbb8f68ad4c1a55a609f0cfe21226ef04719d8fe894db5932f181Virustotal results 34.48%Heodo
2020-09-17Attachments 20200918.docdoc c43420735173dd32559323fc0e7ea6023f065502b927b729f76385672da93640Virustotal results 33.90%Heodo
2020-09-17Doc_20200918_H402878.docdoc 2a17a0bcb3ed1f0bbc6df20f64db1e8c7cfef71e891012fa303ab3bc0de7b0f4Virustotal results 34.48%Heodo
2020-09-17MES 20200918 132.docdoc 4b536ae01569d815968afe883cf1029c39d9e7b4fcd925d98b3bfcf28723a201n/aHeodo
2020-09-17Doc-20200917-DT442008.docdoc 4619c7c0dfd83d76ff1daf51de6f5e714cd8fa4f5298fb4cc4f113cb2045cc29n/aHeodo
2020-09-17REP_20200917_415.docdoc 69b92a13de9bc9189abf0d3e05336bc19c4d2aed4299571a7bd3537567279461Virustotal results 32.20%Heodo
2020-09-17Untitled 20200917 31270.docdoc c17a1457a32fa56ac31ad5c80d2b6fccbc071a5cd3705a68603ee176f93de1b4n/aHeodo
2020-09-17Y30598_20200917_K839.docdoc 14e476c161d3f8ac920d9952493c507a6f5305c9661333847059ed101c75ecd5Virustotal results 32.20%Heodo
2020-09-17Doc-2020_09_17-64834.docdoc eeb00ac2c23ea0f07d1616f8811c5321ca5d60eed5c1c427fc9a36e0acdc406fn/aHeodo
2020-09-17rep 4508.docdoc ee3d9beddb37d34ac9153c4bf717005b5922b64eafc401378621594713ec5bddVirustotal results 33.90%Heodo
2020-09-17Arc_2020_09_17.docdoc 58f089f35ab451b3970293989462d60ffff53a9e2eb17d9c8d136af5e9b5faefVirustotal results 35.59%Heodo
2020-09-17Doc-2020_09_17-73195.docdoc 7b1c371b484f9023040b2c33f3dc93e9269363924eaa089bef3e4f734362ccf2Virustotal results 35.59%Heodo
2020-09-17File_VVR7014.docdoc ba4ca05c27fc14b63451084fd11836fa20c151d3cd4922bb664da0425b870672Virustotal results 33.90%Heodo
2020-09-17Arc_99521.docdoc e5c7cf685fc8a492d002057fa7a17c4bf0931ec66ab71cfe60631b0c5b80ae7bn/aHeodo
2020-09-17FILE_GZ755.docdoc 914758e51d1ade5c8370a8bb0aa8d9039b2b5901690911f007b77ad221f118dfVirustotal results 35.59%Heodo
2020-09-17Arc 20200917 47879.docdoc 2c5f61a9c5804f5a6afb49d1ef674687f18d7d4cb2c32c8bd02bd33990d2fa5fVirustotal results 35.59%Heodo
2020-09-17REP_20200917_C113200.docdoc 4bfb255f0a5d54fc694522cd694b547d5f8fe3dcc5ad5d672bba90fd7f7d65b5Virustotal results 34.48%Heodo
2020-09-17file 20200917 185703.docdoc 64ae28f2c561d7c759e03cc1459923c6cbb5089b7d5760a953d98ef19f3bd6d2Virustotal results 34.48%Heodo
2020-09-17FILE-20200917-NDB2105.docdoc b0a9ce0b9fd719fe2a359bd524f9555231f7e32201f9e49e0a681661b3792ee0n/aHeodo
2020-09-17Doc 20200917 YN49088.docdoc e696507a6a8bc034da78b0504f248b60a7f30588f68d5c4bd157b63f0522678dVirustotal results 31.03%Heodo
2020-09-17UNTITLED_N430.docdoc 4cf247b1b9a309c6c2678bbf359470e57f209f744db25da6bd8f716bc9c6cc82n/aHeodo
2020-09-17Arc_20200917_K912884.docdoc 50db362cc012c66cfa25736d7c8f5e65996cc1f8568c50e137d53e5583058acfVirustotal results 31.03%Heodo
2020-09-17file-20200917-84567.docdoc 66fb843e926bb1fa1f592b757a5839d23b6856850e3654dd7ef264088056641fVirustotal results 30.51%Heodo
2020-09-17REP_20200917_18192.docdoc ee85a0bdecbfab3602a18ed18ea83afaa88eac221fc0c30861c810b4250cc71cn/aHeodo
2020-09-17952_GLV47446.docdoc 1ee37e9d15c8e0ddf602115c14744881a35377665b3ebeb7d07b8fc212df29e3n/aHeodo
2020-09-17inf-2020_09_17-04436.docdoc 88082b4fa0ffe399c39e10181fcf84aeed4782b05a3543457c8bd74ae156be22Virustotal results 30.51%Heodo
2020-09-1772322DQ_2434748.docdoc 70d6a0fd478cf0d96c4e3429875dbbcefb7f6a49269218d1e2ce36e2cc659432Virustotal results 30.51%Heodo
2020-09-17file_E1447.docdoc 8f91dde780ab0a7bcf8fcf57511eff5c919226d21b835ae1754b7c72bc8d391an/aHeodo
2020-09-17Dat 20200917 3160.docdoc 85c87bfb4c6929ad846d0af09880e91aa5d90e56d0607010f80397b6091dc1ebVirustotal results 28.81%Heodo
2020-09-17Dat 20200917 3160.docdoc 85c87bfb4c6929ad846d0af09880e91aa5d90e56d0607010f80397b6091dc1ebVirustotal results 28.81%Heodo
2020-09-17List-MBS09095.docdoc 5e8c0fcb644bba90bd0c0ac83f40b70427fa7bf21c0538c4b5739ee5e81a7633n/aHeodo
2020-09-17Untitled_20200917_56748.docdoc 3516f6fbe7b00c65f9397cc9b3d9881570ef3c9c1b36500de8137d8021d046b0n/aHeodo
2020-09-17Rep 20200917 011.docdoc d3a0d1bebe19f71b0659a0b872335d15b031adb5fb6b2d554d21b4ffa2566f84n/aHeodo
2020-09-17INF-541996.docdoc b8df8ad18c3d755eb12ee45b59cf06643c3edcf77b47e869780b3be3cb1ab4b5n/aHeodo
2020-09-17Rep 2020_09_17 0797.docdoc 2f52d043d3663e2f9b2162352307f622a5fdfa13563207f9b303d2a0489f3e31Virustotal results 34.48%Heodo
2020-09-1738923840 20200917 B527.docdoc f61d46dd57c4f0fab9586e96ed2990da9e5c71b02a46561cb6ef0ba0c222e62aVirustotal results 34.48%Heodo
2020-09-17rep-20200917-2695.docdoc 81914767a7650f3fb662df4da7d27100f40a2467208426cfc15b4134847e9e5eVirustotal results 33.90%Heodo
2020-09-17arc-3618857.docdoc e3b8a6317a95ced172f2f8d639765d3562c92716bd106434dc0cc7bd82e0c1a1Virustotal results 34.48%Heodo
2020-09-17doc 20200917 N60751.docdoc b12f771df24eb6c3dc5d839637eace60ec5627a149199735953d808e79878b31n/aHeodo
2020-09-17List_2020_09_17_O5667.docdoc 87ded30e3ef6563b9027510c19fcb3b8893f48503ff9fc715d14c1fc049c0b14Virustotal results 33.90%Heodo
2020-09-17FILE_20200917_7773689.docdoc 8b3bb9945a2eb820c15eadfea72c9594ca9d1ff936bd1c50f157a30681807ac7n/aHeodo
2020-09-17FILE 46563.docdoc 276c1e19a028de75969db32ff6537380bed379b468823028f3f643433581f056n/aHeodo
2020-09-17Dat 481.docdoc e28b9264ec1942c7107b3ccf9259d754b9892e28eb458349bcabc8946b0c15e1Virustotal results 30.51%Heodo
2020-09-17FILE_20200917_4795946.docdoc 1f64a497472f131bd638d8d60f3ab298df3ae3cea56813b309b8f41d84f4a13fVirustotal results 37.29%Heodo
2020-09-17DAT_2020_09_17.docdoc 6ad7d6517b01019c7b440ffae67f0cb3a1234ad5ef679615f69741aac503b38aVirustotal results 37.29%Heodo
2020-09-17File-2020_09_17.docdoc 0dbad315cddc667cb29f30d02de18c3d5ff0547e0814c5170510ba1a11766b7aVirustotal results 37.29%Heodo
2020-09-17UNTITLED_2020_09_17_OH2418.docdoc a77e984be739cad27f7467d2e8110ce90b290a1ecdaf0025168e1087107a8e1aVirustotal results 36.67%Heodo
2020-09-17List 20200917.docdoc f2e99baaaedbd089392d2cf3fe482c71b0730b27875748932e3b9dad90a4728dVirustotal results 37.29%Heodo
2020-09-17inf-FJ1370.docdoc bc3727251a38cfc083089eebaa80d9f03b1143064cf2ce8e18e245b6b72dd223Virustotal results 37.29%Heodo
2020-09-17list Q868231.docdoc 35088b84f2026bcbde876c9c9188d18287ccaf07b304b1fa9910f476c7aa36a7Virustotal results 37.29%Heodo
2020-09-177173B_20200917_WC2932.docdoc a5da9c7c791c0c911dbef2332dc03be1f01cb406f25c6aa8b313bbdf9b6ea68dn/aHeodo
2020-09-17INF-20200917-I215.docdoc 65bf16cbd3175b7dda73dded17b19b4dc8d8501e4c40140b053ba45dcd480ffcVirustotal results 33.90%Heodo
2020-09-17rep-2020_09_17-4433.docdoc 9d74d4c490b8d1894ba95fece089f3917ca557122da591a3176f6e8bb182a926Virustotal results 33.33%Heodo
2020-09-17List 20200917 G7260.docdoc 68b722df7ebc8c17375e2a8490c5054b77530b12e82fbb5645bac262b6fbed82Virustotal results 32.20%Heodo
2020-09-17LIST_20200917_78944.docdoc cb0e277830f887c3f59725a4c7388bb0a8053518414d95f6831f1e8f4672865dVirustotal results 32.20%Heodo