URLhaus Database

You are currently viewing the URLhaus database entry for https://immivoyage.com/test/1lz01nklo/b54000129846898lmi373k0vecni/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:544769
URL: https://immivoyage.com/test/1lz01nklo/b54000129846898lmi373k0vecni/
URL Status:Offline
Host: immivoyage.com
Date added:2020-09-17 11:24:35 UTC
Last online:2020-09-22 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002942184 created on 2020-09-17 11:26:05 UTC)
Takedown time:5 days, 0 hours, 37 minutes Bad (down since 2020-09-22 12:04:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-18INV_WEG_090120_BUE_091820.docdoc 7b8485c7067c35f26898e3b893e3f3832bedbe6002242a18835c42a78f48f581Virustotal results 23.73%Heodo
2020-09-18DOC_92680004.docdoc 6abcae841dce14d172e12d2c27729756c194836844ccbba13a69617a31dbdd07Virustotal results 23.73%Heodo
2020-09-18DOC_QHQU3SIYR03.docdoc d2a69c58abe4e6aa189d2eb2df014d31d32208d552627e3802565ae231cbc587n/aHeodo
2020-09-17DOC_KC0605646225IK.docdoc 9de91f69583b1765c182e6952a78af003dd26df75c249ca6c8091fa96fbc5fedVirustotal results 31.37%Heodo
2020-09-17BAL_AH4870611722IV.docdoc 58e9e29b2ad9adffb9050f55dc81946e45a9f4dfbf263e4b4a1af049f2897148Virustotal results 33.90%Heodo
2020-09-17PQV_090120_HUV_091720.docdoc 48161edaf6dc6f677f000108096fb60a547709797ada71d0c7e48667f035851an/aHeodo
2020-09-1730823733.docdoc ad55f28a8afc74e7d12b0862d1efc14cccb40e3ff5a2faff1b30c26d2cba6d17n/aHeodo