URLhaus Database

You are currently viewing the URLhaus database entry for https://vetwestir.com/vqZcE6a/Documentation/JuNZATh1KBaX/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:546714
URL: https://vetwestir.com/vqZcE6a/Documentation/JuNZATh1KBaX/
URL Status:Offline
Host: vetwestir.com
Date added:2020-09-17 17:09:07 UTC
Last online:2020-10-06 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 17:10:29 UTC to report{at}parspack[dot]com)
Takedown time:18 days, 19 hours, 8 minutes Bad (down since 2020-10-06 12:19:09 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17dat_2020_09_17_WSH479841.docdoc 647179cdbeab69ec354c8f6763c4db7d70e28e7637f6c39589a547915dc1f347Virustotal results 32.20%Heodo
2020-09-17file_2020_09_17_VBD019.docdoc 14e476c161d3f8ac920d9952493c507a6f5305c9661333847059ed101c75ecd5Virustotal results 32.20%Heodo
2020-09-17list_2020_09_17_25100.docdoc ba0c0591a4c66d1df253cb44649bdd2a14903ea5fda1161df9e1aaf10242d9b1Virustotal results 32.20%Heodo
2020-09-17rep 20200917.docdoc e5c379900d7e18c7eee5477d6e7172e592542bc6f638b4ec96dc09e0b3ed1110Virustotal results 32.79%Heodo
2020-09-17INF_YE90360.docdoc 6d190f3bcc3048ca2a325645cbae33b1048a29fcc362baa184af48c9080b108dVirustotal results 32.76%Heodo
2020-09-1722422441 XVJ84135.docdoc 9377f00f0c506d7b1d51679767340ba4632827a2ba7e8450aa85a048c669dd49n/aHeodo
2020-09-17MES 2020_09_17 EBJ874204.docdoc dc601e89c617ab5b7093519f49f80b27b1a51a6de9800a06f9802d566cb8d671Virustotal results 36.21%Heodo
2020-09-17K6466 2020_09_17.docdoc f86a5fb18dcfc72a906b7458e223f40121d3d51049448370f73340890cf89993Virustotal results 36.21%Heodo
2020-09-17Doc_20200917_56940.docdoc 914758e51d1ade5c8370a8bb0aa8d9039b2b5901690911f007b77ad221f118dfVirustotal results 35.59%Heodo
2020-09-17arc 0395.docdoc e8e0ee1f225b4a605c085d0a5261d9dfc0c633676b294f5f329881ff8c242540Virustotal results 37.29%Heodo
2020-09-17Arc-ZDY2230.docdoc 47c0e29cfb88541480f39ddfc2d5db1491af396a026356531efc1df143c6d6d8Virustotal results 33.90%Heodo
2020-09-17Mes.docdoc 7116b8982d2e5c63be2e3edf350d562b991314205feda61eb9c8d33cfd8ce0e4Virustotal results 33.90%Heodo