URLhaus Database

You are currently viewing the URLhaus database entry for http://elrofanfoods.com/buvlj/eTrac/fkQkAs59QZsS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:583325
URL: http://elrofanfoods.com/buvlj/eTrac/fkQkAs59QZsS/
URL Status:Offline
Host: elrofanfoods.com
Date added:2020-09-21 06:47:05 UTC
Last online:2020-10-01 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 06:48:02 UTC to DCAbuse{at}zayo[dot]com)
Takedown time:10 days, 0 hours, 40 minutes Bad (down since 2020-10-01 07:28:29 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-23Attachments 520.docdoc 1efc790008eb7e0bfb5daa775aaeb4e590d6ebd45f815e33bf8370be89818d02Virustotal results 29.31%Heodo
2020-09-23INF_2020_09_23_NA23964.docdoc 25a6879db668a83d39e1a4696472ac50058cbca71afbe055fe38e6d7c4b8c8ebVirustotal results 29.03%Heodo
2020-09-23Inf 2020_09_23 8283.docdoc ead5e12d378c9099bd007886c313ffb492b6d6579557cc4cc9288566b7739663n/aHeodo
2020-09-23Mes-9776.docdoc 94a81d329bb24822021c39261484f9010d84154b9f9f9d25506cd221381e55ffVirustotal results 29.03%Heodo
2020-09-23Attachments_20200923_P08335.docdoc 9e4c0d210568ac46fbe5e7a4bd8218589c9388f06859b43fd62a53e9c0a949a5n/aHeodo
2020-09-23Attachment 2020_09_23 4228.docdoc 98c795928098a062d1d20e701e289fad2b5c3e3824cca0715df4bc23d5e3c52dVirustotal results 30.00%Heodo
2020-09-23FILE 2020_09_23 1248.docdoc 692bbf3c78f0c8af1c57acea7c9910b8138ef4e85822096176a8bbd7603623faVirustotal results 30.00%Heodo
2020-09-23rep-20200923-N9565.docdoc 8d9264f42739eb272f340990d05b2688263682781551a47e197cf7fd15f54695Virustotal results 29.03%Heodo
2020-09-23inf_2020_09_23.docdoc bc8d7a492cc45195a67d8500390b631b8106bfba0c324869264f3a255fb0ccb4Virustotal results 29.51%Heodo
2020-09-23mes-2020_09_23-WU589.docdoc 352b0eaafd07102686fb7e59059288bd6f527e4190c6700cc5dd1e6f267bda16Virustotal results 29.03%Heodo
2020-09-23Doc 254658.docdoc dc3e3fef5b584cbf8e923630c4a9ccf834c5140265e79ca13ade90150f9bc1faVirustotal results 29.03%Heodo
2020-09-23ARC 20200923 HDA932.docdoc d03d4795373da32664a311273c0132ee17ffc655feb3849ba4a46450e7aef536Virustotal results 29.51%Heodo
2020-09-23file 999.docdoc 835f71195c622e6d5dee5f8d307078c0efd97045a75c08947600350fb2da5a5aVirustotal results 27.42%Heodo
2020-09-23MES-877590.docdoc da5ffbd8e3f1e32cde22e5e6d87f62a99816d614a29179e6c393e6ee1d1eec8bVirustotal results 27.42%Heodo
2020-09-23file 8780.docdoc e9421ffb031a4df49ce806717de37db551caa063785c2295788dfa979a778478Virustotal results 27.42%Heodo
2020-09-23D062-2020_09_23.docdoc f2e74e9f4eff803c24130a1d601bf039e1c14eb872c3aa0f026982512146ffc2Virustotal results 27.87%Heodo
2020-09-23Rep 2020_09_23 GE056.docdoc 3b12b9e3c5bb951db8bd86ba2ed902362a034487b029eb22199b2a7c28264480Virustotal results 27.42%Heodo
2020-09-239254O 2020_09_23.docdoc 73b2c723dfaf202622c57e8b9bc4504b45f7617e3f644e4097c9489a459ee85cVirustotal results 27.87%Heodo
2020-09-22mes-FNS08965.docdoc 45fbfc15ab5afe1f798ec4b481a02fb42c1f0b2e0a5e7e19c60868541380eed0Virustotal results 27.42%Heodo
2020-09-22LIST_20200923.docdoc a132f8367518b36376bd03160587713674ff98805021fed3d6e3ff58c045a97dVirustotal results 26.23%Heodo
2020-09-22MES-2020_09_23-CI37559.docdoc a5b7961981d9acbb422832a05d2c07c48361000fb79f1d9e07877821e02e2512Virustotal results 32.26%Heodo
2020-09-22N4019-20200923-338.docdoc 685b5b0268f4430b0aaf1a9997ed136457fa9139467eb02922fa3c6210b4f584Virustotal results 32.26%Heodo
2020-09-22ARC_2020_09_23.docdoc e3187dbe7923459b3ea645a3d68b357927471e14d70aa4e542327ad4ef540637Virustotal results 32.79%Heodo
2020-09-22RS972_20200923.docdoc f75097922fc6b528988d0cd8192115dd8ccaf041ef47a0e481e55185fc7dc127Virustotal results 30.00%Heodo
2020-09-22Doc 20200923 940648.docdoc 8031c668f56e12d2f6e1d54f98aea8eca655f14e6dfa3ca6df9da76aaec004f4Virustotal results 29.51%Heodo
2020-09-22Mes_20200923_ANB901.docdoc 6f0e03df41433654a653fde3c2dd49f9839e5c7f59ab54dd3ad0526d2670f4d7Virustotal results 29.03%Heodo
2020-09-22File.docdoc 6a9f1cb57648fe546a21b732a369353a19405aca026db96bad9dc76a943ff11eVirustotal results 29.51%Heodo
2020-09-22list-2020_09_22-445.docdoc 3d797365a4fc8e4c190e44b52e766b13240809683b910a1760721a4d0438c89cVirustotal results 29.03%Heodo
2020-09-22doc-2020_09_22-UQ0172.docdoc 5118e3bd72677f8cda269a8e2c50571beffb5dc3f7dbfb1b05cd1e44a904a214Virustotal results 29.03%Heodo
2020-09-22Attachment-20200922-390216.docdoc cd537ffeb9d0a9e21855ebee9da69cd5b7e1c0839e6fca3be47f0a695a41d2e4Virustotal results 29.03%Heodo
2020-09-22File 20200922 5833810.docdoc 5231a24a90603fcebbe4e812fb2ac981a788534259a9f3bf6343cef44d447720Virustotal results 29.03%Heodo
2020-09-22LIST 2020_09_22.docdoc 0e33b003b9c1cd0b792da43846113a32d28de0d64477f84d90bbbffa40098016Virustotal results 29.03%Heodo
2020-09-22Arc ZN904104.docdoc 9feac62adca8879c6fb77e71311d55feb8409cc5a2a0929f48934970c404f3dcVirustotal results 29.03%Heodo
2020-09-22dat.docdoc f9db2998d811b8c5fc0a11e513e628001fc463d8e4c9a44068939c3668f072b6Virustotal results 46.77%Heodo
2020-09-22File-2020_09_22-XML068056.docdoc ef13496f7022fd77f5c840b34d5fc577bf4c2dcef2a56b1e0b71fa0387d6e8b9Virustotal results 47.54%Heodo
2020-09-22ARC-3756139.docdoc fee44ec3b333796685007e96f4c1478fc810a6a4549ed0d18c4e26fb91e508f0Virustotal results 46.77%Heodo
2020-09-22REP_065.docdoc c4699bc83e2c480aa53af341f4b67b5dfb27cb5d28fb09a7619b55689b686ae3Virustotal results 45.90%Heodo
2020-09-2291366351_20200922_G8135.docdoc b58e849ff15fd90ea845ccee23fb2884bf9666f6dc705ac84dc556130a1f90edVirustotal results 45.90%Heodo
2020-09-22mes-UI519.docdoc 1a1117fee8d79bc4f17cd8256e6f5a71a970665243bac9ee7b6a475271cfb524Virustotal results 44.26%Heodo
2020-09-22FILE WCD38747.docdoc 8ce52163ceab79b32f012e6129070434d32ea30dfab92da2a9e62e79da693497Virustotal results 45.90%Heodo
2020-09-22Rep 20200922 MHU334.docdoc 5dd221021744417bff46bb5b349b66b0417efc8148a1f40263013ea591e10ba0Virustotal results 41.94%Heodo
2020-09-22list 20200922 336.docdoc 288be7752a470617650f5882ebf631b541951c5c4fc685fffee2de9650e31bdeVirustotal results 38.33%Heodo
2020-09-22Inf_20200922_280917.docdoc 1af6f1965d4e602979e445d1fd72691e2fc2abc5c9bf5fd7ed175c7fcb76dd87Virustotal results 35.48%Heodo
2020-09-22Arc OZ389364.docdoc 2684fb0d066483f383653d701aada35989b0f0115ef080dc1383ddc2afb00240Virustotal results 35.00%Heodo
2020-09-22mes_724.docdoc ec0011702614cd33aa57769c23abfa9106382cc9b99ec9a1f9bb57204cd157d9Virustotal results 32.20%Heodo
2020-09-22Dat_575146.docdoc 2d2a4e7c1a6c9db989a9a9a887c1ab4b0b89d35453aa857abda9b06dd39cbaabn/aHeodo
2020-09-22list-317.docdoc 8392b428becc751330ef038d88f6b92a3b1902a9f23acebd360f8f7cb11ee9f6Virustotal results 29.03%Heodo
2020-09-22inf-2020_09_22-05129.docdoc 482b54b8d99750fad27a5d6131580e9639eb71432b6befb5dd5ca0b27f67881fVirustotal results 25.00%Heodo
2020-09-22Untitled.docdoc 62a247c06790b9986416ffa1044dc5d8bff40b6b706081e25f4db985f613afc6Virustotal results 22.95%Heodo
2020-09-22Untitled_20200922_MRZ375.docdoc b218573be430d04bc85df63886bc59d6608ed0e84d058f52456224f9f7f06a8eVirustotal results 24.14%Heodo
2020-09-22File RI779.docdoc ba056ab0905369eb27251a5f366173bafe84869d58365340e7e4c9436ee6273fVirustotal results 23.33%Heodo
2020-09-22Attachment-20200922-8994649.docdoc edb38f20a57df9726e7a8a2f78f122e7a968a390fa006a996d93e06a040df87bVirustotal results 24.59%Heodo
2020-09-22mes TTE4817.docdoc 83c6179da780f419a2c33e82aa72779368169c6dfa0c13b5e1301c3ad3d33baaVirustotal results 23.33%Heodo
2020-09-22INF_2020_09_22_L20906.docdoc bbcbb69fdee99a6460a7164c67fb3a2a7e9f378dd900e36e87682845d0606e56Virustotal results 23.33%Heodo
2020-09-22Attachments 0870204.docdoc 76c0630543f301f3fe63e8ca4ddef6171019fe2bc21d3c891bceb80774bb4cafVirustotal results 25.42%Heodo
2020-09-22File_7899.docdoc 1905997bc71b596381c75393456d143e27aeb93fec85e5b38a5cb4892d5da8d3Virustotal results 24.59%Heodo
2020-09-22ARC_2020_09_22_4906.docdoc dd39121ba5d3e898c2eb476a46cb2afe029cf388f1265f01ea1293e1c49f6e9eVirustotal results 23.33%Heodo
2020-09-2200454ID 2020_09_22 GO878.docdoc 5d282237d6e5c0b30771b81556082a026563fc848280761cf0b375a39f36245fVirustotal results 22.81%Heodo
2020-09-22arc 2020_09_22 Z82849.docdoc 6194b93de778c4ed12b833a8a06150e0ff059a8a82ea4089e1f0d35aa73c4ec1Virustotal results 50.82%Heodo
2020-09-22I247_20200922.docdoc dabf1341ef6fa0792b0a910cb351a22a740371db69bda55201dbdbccd746d9afVirustotal results 50.82%Heodo
2020-09-22Dat 2020_09_22 144531.docdoc 3a55d135adcf77677eb1ba21e4b5425ff19a8198264e313df904dc6982bf1a80Virustotal results 50.00%Heodo
2020-09-22Untitled.docdoc 5744548adb59f24037bb5500e559b80bc6917502f107b28a16b38ab4e6abfb71Virustotal results 48.33%Heodo
2020-09-22file_2020_09_22.docdoc 0d70d473dd82d66be63e961914b3fccdaac41677e69ee91706bb0be406144501Virustotal results 45.90%Heodo
2020-09-2210969_20200922_709.docdoc bba3849ec67263bb32327cd4462beff2e001ff9db4a576d683df43961006394fVirustotal results 44.07%Heodo
2020-09-22Arc-91681.docdoc 3d12017589f14be9a98d02b6c5baec7ea82f462d13cdc018cc2fe7b235ca723fn/aHeodo
2020-09-22list-2020_09_22-24054.docdoc b3bc13c79571b2cf77ab2ad7a593e512bbaf1bf61f0ac3eacb10e78e840cb9fcVirustotal results 40.98%Heodo
2020-09-22dat 20200922 0465696.docdoc bc077632ea6bd7e0d83fe02cd1b706c078d7bdf7a18b0c1477c0c3f94d2f14b1Virustotal results 40.68%Heodo
2020-09-22Untitled GXQ651582.docdoc 050f8c672a68de19be1fc1f6137e6a572d8abc551e67d2477a567dd5f94d4e5aVirustotal results 33.33%Heodo
2020-09-22inf 2020_09_22 617.docdoc 8e31bc6780cc77125d2c78fc762ac2cdf7640be4edf71770f144fd26adc4721aVirustotal results 32.79%Heodo
2020-09-22DAT 2020_09_22 EF1023.docdoc 90f5fcbadecf831b2ea1ad31be2ad24a539c2886611a270e23975355d3ba2692Virustotal results 33.33%Heodo
2020-09-22inf-6246790.docdoc 34ac58d19f9561fbc90d00ebe4890258f9cf30d98f4fea91a7f13113e2a30787n/aHeodo
2020-09-22rep-2020_09_22-ES58781.docdoc 3d79182bae912b50a6834604a96ac90b10ca5e1ce72ea2355fc0e9e3b38995feVirustotal results 31.67%Heodo
2020-09-22Mes W157.docdoc ddabac18016628a7b4e14df72caa0012c52af6a318df5c236615b4869b257546Virustotal results 32.79%Heodo
2020-09-22ARC_LTU26436.docdoc 08eddac7838ced651892ee94e145a639d010807c45f3bd00e9752dbc1590add9Virustotal results 32.76%Heodo
2020-09-22UNTITLED_2020_09_22_RB511819.docdoc a817507562022f31451f066e1fa331d53cf580488007476987751c5c9b0113ceVirustotal results 32.79%Heodo
2020-09-22INF_2020_09_22_416.docdoc 8a2890bb71a8c5efcd1478ee7b30ed6d9c942d68f9a2b98bcbce5ebeef693071Virustotal results 31.67%Heodo
2020-09-22JA13919_20200922.docdoc cbf5b0482bc2cdc04d1f4ffa6c39d4517ef6793289339305a64f7820553bdeacVirustotal results 31.15%Heodo
2020-09-21DAT.docdoc 6a0b69f7aa83a9052858c1c98fe25792ae8d393fe5133baefee848ba652038faVirustotal results 30.00%Heodo
2020-09-21mes 20200922 3200.docdoc f2936defc5fc2976c78eb875870a7e003a079975fdeae34fbc2a652f0b488ba5n/aHeodo
2020-09-21Untitled_20200922_X501192.docdoc 0394eebf7602baf22b2e45b390f4aa5854b0179e671b3a2607dbf44a5130870cn/aHeodo
2020-09-21inf 2020_09_22 L29396.docdoc afeb53f8204c23e2ff8f5733e97220ecfb71466eb4f3f9ad1aef0807fd216973Virustotal results 30.00%Heodo
2020-09-21Arc-SI537.docdoc 408b12e331000ac29de83635501b2c1ad800d8465e28a0a8054f10c4fdcb091cVirustotal results 30.51%Heodo
2020-09-21FILE 2020_09_22 443.docdoc 0ff979ea9674b24eaaf44e80354ff0126f6a59acc790907ccb1fc48c8e1384b8n/aHeodo
2020-09-21Mes_20200922.docdoc 30ca3b2aed5b521c1a38f66bbaa8d0bcc634cf59c59493b8388dd894d048ef74n/aHeodo
2020-09-21REP P129.docdoc 868eaaf542a2552458dbab990542114b9eae6c1c9ab0de7dbab93ad7d932cb24n/a Heodo
2020-09-21list 2020_09_21 54435.docdoc 4e8b907a2a9db801e5ac5e63be51c941944aa0432de155955a9b8f7741387890Virustotal results 27.87% Heodo
2020-09-21REP_2020_09_21_9846943.docdoc c8ec1b5a11693054c13c42e45d83be353dc88a30205b63b6e820c12c9b38a13fn/aHeodo
2020-09-21ARC-2020_09_21-GA289.docdoc f49e5be00aeff785a79ef91f4ddcea3c074c7145f614e63dc439657f8068c49dn/aHeodo
2020-09-21X83076 745.docdoc 13d74ade49feace676a6bb678121492f29faad5dfc83d2512b9ce9cf872a375dVirustotal results 27.87%Heodo
2020-09-21doc-2020_09_21-V792.docdoc fccf528f0152705715608cfaccb8952b64971c5f5c8a3479f035b979b8e51631n/aHeodo
2020-09-21List.docdoc 817dfa0131f4686e1849deaf26ff7ffe1f5b2eb30526bc09a6753ce13185f502Virustotal results 26.67%Heodo
2020-09-21MES 20200921 TI29256.docdoc 716299f97023ee3e7f0a20ad1843ee7284684da8a503b9031fdaf0aac7e81671n/aHeodo
2020-09-21List_2020_09_21_0230.docdoc 61eb0d422b0465e3df0a4d5167d820688c9b0435aa4d28b8a09cf216487399afVirustotal results 28.33% Heodo
2020-09-21List-2020_09_21-4973.docdoc fada4708605505ec08d2045110877e6a7cd8fb2037b0d9bc3c32c5607a23c21aVirustotal results 28.33%Heodo
2020-09-21Inf_2020_09_21_S718.docdoc 22a29b66bba17966a31c3cd3286dc31fa1c99e45ab2fa9bd84eeee1bd847f58eVirustotal results 27.87%Heodo
2020-09-21LIST 20200921 392515.docdoc f7e288414ab9e74bc1a11ae2adad7f9308badadd13b048f166a403029ce4c272n/a Heodo
2020-09-21MES_2020_09_21_RIC2670.docdoc 80a8b5600bf204df850aadf7d4e7833263ef3c4771208d62fcb53e662007b5d3n/aHeodo
2020-09-21Inf 20200921 GOT4483.docdoc 8444b33aede1c4250ebffcce3e2abc7f96072003c7a5981b85a10bad9536ecaeVirustotal results 23.73%Heodo
2020-09-21mes 20200921 X4516.docdoc f2e681ee5b79805f8cf54b83b821ad59c1c4b7daa53deeac54ac5ac3ee7a6421Virustotal results 23.73%Heodo
2020-09-21doc_OQS677.docdoc d6b49fd8cd1ae8ef8187df86ab91bb6b2b0c19b4025834915102eb597a04e0c8n/aHeodo
2020-09-21Untitled 7394449.docdoc 6351168d14cfa0372803482062882590c98d717dc4f4eb2541fe3a154e8dc40fn/aHeodo
2020-09-21Attachment W88882.docdoc 012c334db958a84f1f475fe44c1a86195a783c7701b6aadeec5c06b539158fc8Virustotal results 23.73%Heodo
2020-09-21Inf 2739.docdoc 42f29aa41b1f7d9de698db6b2a4512a76e4c54af72ab7ce26542fc3666438084n/a Heodo
2020-09-21Attachment-20200921-HQ3484.docdoc 0f3dcf665c7ea9ad31fbcaa324e8f714b5611ca2d55c539279fe724acbf61cfdVirustotal results 23.73%Heodo
2020-09-21UNTITLED-20200921-D215629.docdoc 164898a09b7b291c8898d773c7d1bbf378552734b76b9ee7ce6f8ec296cca217n/aHeodo
2020-09-21Attachments_20200921_L80767.docdoc d514c46c30e752ee22291f4cfce174467d0b7c6ee1506f12d854a4090fb65ef0Virustotal results 30.51%Heodo
2020-09-21List 2020_09_21 355414.docdoc 006eb3de7c7d6ef36973d365810c036529acdcfeb2f53c7b8d9d3f36231d584en/aHeodo
2020-09-218759439-20200921-FB08262.docdoc 5b553de983ac2fa97b6d41a6bc545e330a7e725deb81c7d4ebb0e795becacd4en/aHeodo
2020-09-21doc-20200921-ENA58692.docdoc 3a3066eb5fc603c6bd26e82784e4692ad45e2ceb005e34ef397224cb38b9800fn/aHeodo
2020-09-21Doc.docdoc 712fb1d60ad43d0063de94b64d1db09629a00d5803efef4ce9a6055f82b26ff1n/aHeodo
2020-09-21doc-2020_09_21-371980.docdoc 5d4548534f15df03e54ccccf8eaa3a7cd08ac7482dfe65414a7758507e96d7f3n/aHeodo
2020-09-21LIST-20200921-79533.docdoc c011f657db09823eeda192e8f301d95cd0abb5aa4fac1ef4d53c5169e951bbf0Virustotal results 20.00%Heodo
2020-09-21dat-2020_09_21-730.docdoc 8b160c5e14e6cdc95718a1db66d62bdfe791723e5f08bfeaaf2937f7ba9e74c1Virustotal results 20.00%Heodo
2020-09-21DAT_I42838.docdoc da3050b0d91467358dae813cc2436cdf839c08206d0651e0703b74a81caf1ebdVirustotal results 18.64%Heodo
2020-09-21Rep_K7427.docdoc 374523e9d054ba30d59eaaa8686fe97fc74a10882a0b467d52b21de5efddc31an/aHeodo
2020-09-21arc_2020_09_21_162.docdoc c1ebb641f36328616711fb377d95f38319840fe6a0ace1c0858b64d7b75f96b5n/aHeodo
2020-09-21ARC 2020_09_21 R10561.docdoc b16ecce47c281646295a38b45f138c8d0fedc872f816e7467e881dbf00fabc45Virustotal results 18.64%Heodo
2020-09-21DAT-1315520.docdoc 3af20e9e67353d36d683c97554fc2e0a1ecb6659ae0c4ee670cf6d4a54d68b8bVirustotal results 18.64%Heodo
2020-09-21file A991.docdoc a3019d963b212893540926b54307b6f2af7f7a30749c0afe950b18ae5ca323e2Virustotal results 17.24%Heodo
2020-09-21File_1485539.docdoc cacf05026e9ff252718354854402d119747a0a0ff3390f908044e7ee222b1f83n/aHeodo
2020-09-21rep_2020_09_21.docdoc 249d6573f4f79e8743e529bdb81be6c11f86e83a53873ab864ed86b5cf603c92n/aHeodo
2020-09-21INF-20200921-VEV26812.docdoc 42bd5694c817a1711d186dcf4dbb1b59c343ad3edf28117ce218fa55fec28bf6n/aHeodo
2020-09-21Doc.docdoc 206dc1c940e5109e2e121fc275c21edbf294ddc5c4d14fbda80d08b35dce5053n/aHeodo
2020-09-21ARC 2020_09_21.docdoc d7eba393957320094938db5221da24c71a0f9d6d29d6e05ec1d2015a6d824a95n/aHeodo
2020-09-21LIST-050553.docdoc 19f032cd8a2f4e54a759740a457eda11b94fae08920917346e2094949d218546n/aHeodo