URLhaus Database

You are currently viewing the URLhaus database entry for https://www.cebucoolstuff.com/image/attachments/XwJ6AFopQt9kwsOef/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:558339
URL: https://www.cebucoolstuff.com/image/attachments/XwJ6AFopQt9kwsOef/
URL Status:Offline
Host: www.cebucoolstuff.com
Date added:2020-09-18 17:25:35 UTC
Last online:2020-11-09 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-18 17:26:14 UTC to abuse{at}syn[dot]one)
Takedown time:1 month, 22 days, 3 hours, 38 minutes Bad (down since 2020-11-09 21:04:19 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19XY561-20200919-0366.docdoc 7d635d13a89e28fd6b0237c35f566e2be9502c55ae2dee5b94c1b5281c018152Virustotal results 35.59%Heodo
2020-09-19Mes 20200919 42485.docdoc 32f41a25d60eecd90e5e66e0ac2850bd6fbe4f97ddb2dd1e1c3998ab3089f391Virustotal results 31.67%Heodo
2020-09-19Untitled-78116.docdoc 034a97e7614fadaf9552e4fbc5992139431bbc6bc905b9af8adea4d60b741f3eVirustotal results 27.12%Heodo
2020-09-1905582YG 20200919 54506.docdoc 0b20a73da9e858ca63b3e038817d2cd82a98535eb4ed6c1dbb214e3e066bede2Virustotal results 23.73%Heodo
2020-09-19ARC_0439.docdoc 17b333cc6c291651161d6bab9f62df4f89a31b13b8b8db8722c6e6d069d1bc30Virustotal results 22.81%Heodo
2020-09-19FILE_20200919_UAC6173.docdoc 75e37e5c3591743af109482748f2a48e550f1a9d767316a8cece66fb4fe8c222Virustotal results 22.03%Heodo
2020-09-19inf_2020_09_19_4802.docdoc e4873536ba7b163dc9a87dd2dc7d447b502e63eaaebf88fcf4635d423772db47Virustotal results 22.03%Heodo
2020-09-19DAT-R703557.docdoc f5ca634bdeacd64ccc52ea932bd221762cc68524fcef2df96c77ecd777d16670Virustotal results 22.03%Heodo
2020-09-19Attachments-20200919.docdoc 0b58ba1859d47221ab95122240157d9d4bc885723fb94b700f1c36cb28edf3c6Virustotal results 22.03%Heodo
2020-09-191955S-2020_09_19.docdoc ff17fcb2563e69e3f433d120bdcb9410c992e3abd0502b96fc663d2adda5bda0Virustotal results 22.03%Heodo
2020-09-19XNB01349-20200919-61318.docdoc 85c0fbbdc250f9ddf13c8a438a1c90ada6ff0e475cddaa45cbdbcfdf18c9dab9Virustotal results 22.81%Heodo
2020-09-19FILE 716.docdoc 000dd08101567f408a0ee2b7d095d3baa02f532ed3839f66b60b9d64ce065d17Virustotal results 22.41%Heodo
2020-09-19Arc-20200919-AD095.docdoc 7e37d762b881d0b1d6897e3d3c7ae449bebad8d250e6573923944ad8c0c22c28Virustotal results 23.33%Heodo
2020-09-19File I632.docdoc f0e6815411621dc6ccb4ca55c8c1ceba4ed59cc0f64b6884f0d93d49f9493bb5Virustotal results 24.14%Heodo
2020-09-19dat_20200919_YRP91065.docdoc 606c981a35630090fe7df6ea2bd78be7c01eb20f5d266ba2432b209e9bf26eb8Virustotal results 22.03%Heodo
2020-09-19Doc_20200919_556.docdoc 9ad2fe8f74ea62256c9ad4c199d69c91b8c76f9a605cb5c038fcbec9d0e85054Virustotal results 22.03%Heodo
2020-09-19arc_20200919.docdoc 8750d49fc1ba34c16ce392d088b1843101a6669f5407b567c2dff708351b81ccVirustotal results 23.73%Heodo
2020-09-19INF A778.docdoc cab5f70f9a6d1f300828e8c715696273befca7a141ca5e75b69b5a408ee432b2Virustotal results 30.51%Heodo
2020-09-19Rep 2020_09_19 52783.docdoc 7914bb6c3d6664a065cdb3f06cfc21a7f85fd7423e3b5af3468245d1f03edf5cn/aHeodo
2020-09-19file_FS5532.docdoc fca26f8a9f6995a0a5dccd24f54b77b3d5c855fe48084f99f9b2da3382f88c2fVirustotal results 30.51%Heodo
2020-09-19file_20200919_MY21729.docdoc b81a03fb70bafe2e7fd636ad7371dd77cd8fb21b274fda2b5bfb4b2d4356e91en/aHeodo
2020-09-19inf 2020_09_19.docdoc c67445bd4a7a3846de10ecccfc8117f4c144d3c2cc2ed29bbd934d3e06dd7e9bn/aHeodo
2020-09-19list 2020_09_19 O35905.docdoc 0af0e4a065d036488bc54043089879cd5e6b6a4db8c164ba0b7f45140aa616cfVirustotal results 25.86%Heodo
2020-09-19INF-2020_09_19-423.docdoc 610c4e7f9d0c567d7d8a230edc8cbe856baae5fb20c5fbebe2a43c7c7d007feen/aHeodo
2020-09-19INF 2020_09_19.docdoc d2f7410370f98bd4b8df1da90c315498ed40486e84d2c1a4951935f642fb8d3cn/aHeodo
2020-09-19ARC-2020_09_19-BR9576.docdoc ab4d0777ea8585140a9d19ccb330eaddeea2151248785fff7e097912d0a3af25n/aHeodo
2020-09-19Dat-V128.docdoc 4186791608fe67e3dd4a2f61f52ed52ba67c4d7d75996cbf27f8379a44509f18Virustotal results 22.03%Heodo
2020-09-190794630_2020_09_19_6482.docdoc 12184c3b864ed546a8c1c0b94d18631228a2cd6caa38e1d6c332c113d327f21bn/aHeodo
2020-09-195395 20200919 096018.docdoc 93e1254e65773ffb3d3f3aeeda414a5356482c00d5ecc36dcd385158ac7c8fb4Virustotal results 22.03%Heodo
2020-09-19Untitled_30968.docdoc 61df427b7811925c65b7097f247c0c66efd9be4177b08926eadc161d854b61abn/aHeodo
2020-09-19Rep-2020_09_19-0061.docdoc 59ee3757e66be242efc0972dd6c65966fd25efedac6d7183bf2ebb22f73ed835Virustotal results 22.03%Heodo
2020-09-19ARC_20200919.docdoc 9b15f15ca0fc3748ef3b9f9a91bae081e2b5c076d1b39e7e16cfbe3a08cc5070n/aHeodo
2020-09-18File 20200919 KG839853.docdoc 3eb7679ffcb5eb0cd537545d2e28ad49fdb4bc89366476f731659703b6707ff5n/aHeodo
2020-09-18List.docdoc c23cc89488404b578a22052d1d946ea0e421961bb77a5c4b002d890506c2aba6Virustotal results 22.41%Heodo
2020-09-18List_2020_09_19_3787290.docdoc df50fc4b87844f590011e4655d981e4aa7d498dec2d0940b554aea8538567352Virustotal results 22.81%Heodo
2020-09-18dat 2020_09_19 459784.docdoc f56906e33a9a9bd3b074b3b5c24c2e98ba58817c4c61452977054f27d0d9312dn/aHeodo
2020-09-18REP-2020_09_19-XK244.docdoc 03caf29484a047db9c68e15e6117f665c59b1cc6ea7cdacba9042f80149861b9n/aHeodo
2020-09-18Rep-191.docdoc 52ec22303a14b98735b2056a66731212dbd583c099eca26f8a12fcebc1724760n/aHeodo
2020-09-18ARC-2020_09_19-RTM669.docdoc 5dcb34b82840165da4c8d3f693522093656d8731ab6ffade09c8f5d2b8376408Virustotal results 23.73%Heodo
2020-09-18Doc_20200919_21405.docdoc 7234cb8db24e20ba0abe1fb9f9a177573e1e83122a6f3b8debd45e34b67a7775n/aHeodo
2020-09-18file 20200919 CB93264.docdoc 8aef0f99e6ad886e7a947f5a99fd0b0016cfdd32cf2c62ad525364452c8c7c41n/a Heodo
2020-09-18file_IAR83216.docdoc a4ea07f63c702a260cfc87703c09e635cf2fab0a0ed510439a57936ee5f6d4b8Virustotal results 27.12%Heodo
2020-09-18Attachment_H103.docdoc ee54db7e18eb7600da577fba32adbac6e86a7bd9fc9134fd1ed5020bc4b7b03cn/aHeodo
2020-09-18Mes-20200918-4346.docdoc 6582b37fd7a1c9ef797e7f6db679df941000a9f14475cff833abe8d4b78e51f7n/aHeodo
2020-09-18Doc 2020_09_18 TRV219.docdoc f8a679c8dd6ae3c69e27a43a59ad55018d6e6ea9d4a7107431420e91747e0be0Virustotal results 31.03%Heodo
2020-09-18REP 2020_09_18 35127.docdoc 0993a8e2a1ede660ab29dac20d8b95443ba1577a1247c423d7c7fce39820fb51n/aHeodo
2020-09-18list-UCY568351.docdoc 799cf64025403edb028118bd2dd2cb46f0af67fe2bc92310035fc1389e1f4bc3n/aHeodo
2020-09-18DAT 2020_09_18 020.docdoc 54ac560845b09ce00a48b604ac7c440331cbde4362839a3dbf14c378230bee21n/aHeodo
2020-09-18DAT 20200918 681498.docdoc 50d66616676d8ca532ea8333e2d545587d54e83abd08f0720012392cba583f26n/aHeodo
2020-09-18INF.docdoc 851a395186b32fd0d0176d07440e7a1a5c05a5eabfd843b7dce3d2586c1ecd01n/aHeodo
2020-09-18rep_5183.docdoc 437dab8ba10eb91c00d79f3019265d85eeec7dcd944ee86186a542f24a31b596Virustotal results 25.42%Heodo
2020-09-18MES-20200918.docdoc 528cc8d3ea6fed5fceaa0bd0918bd41dfc6a2ac19f22b397892544b1e7200d6fn/aHeodo
2020-09-18ARC.docdoc 39ab2007df6e588e7a2eed34c24f22b1584c9fde9877b59dd8b7441962940d38Virustotal results 25.86%Heodo