URLhaus Database

You are currently viewing the URLhaus database entry for http://daoisthealing.com/cgi-bin/776399559744957/34rbx2ixd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:599387
URL: http://daoisthealing.com/cgi-bin/776399559744957/34rbx2ixd/
URL Status:Offline
Host: daoisthealing.com
Date added:2020-09-22 18:41:05 UTC
Last online:2021-02-02 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 18:42:13 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:4 months, 12 days, 20 hours, 44 minutes Bad (down since 2021-02-02 15:26:47 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24INV_AAR_090120_CFX_092420.docdoc 29f8908fad78f532f3e53d23cd10d6289376b52c559e2398ab3a2ceb671ba1cbVirustotal results 22.95%Heodo
2020-09-24REP_BH2318045719TX.docdoc 5cbf1dbfb7530a124b943acb74153419ea9a9f6430256394a40e958a34dcec0dVirustotal results 22.64%Heodo
2020-09-24M_58091248.docdoc fe9b0b3adac87d1fe5b13863ff7ab54660757a7bc0b4996cfe241ff357c57b3dVirustotal results 20.97%Heodo
2020-09-24INV_PO_09242020EX.docdoc 37b5d86751a2c999901df382ddadc7aa72d891a4e24ef527e02266ffab2efa41Virustotal results 20.97%Heodo
2020-09-24INV_RX0061008646KK.docdoc 460d4f1fa3c90d50ae0a56c6c4c26bfcd3d3d22829baef98b7ea3e9b451974feVirustotal results 33.87%Heodo
2020-09-24INV_44718453.docdoc 3321abc9c460868cfafe80f968ccea4254b02ede808bcabe4dd58055ffddb358Virustotal results 30.00%Heodo
2020-09-24DOC_30945605.docdoc b56096621e87ab5d0c7d1a190f5c04257a84ab8e2da5d5335ae48f7759decabeVirustotal results 29.03%Heodo
2020-09-24U_0787038643530204871.docdoc 896f6e1b9eb9656cfc68db252241fc7087192661175a0604505742223f0ef016Virustotal results 29.03%Heodo
2020-09-24FILE_LD3626228533LE.docdoc 62b4929ff251b1ad4f361fa4d8f8980b722d4219e9e7a8c9aea193558deb8c2bVirustotal results 27.42%Heodo
2020-09-24P_7350303441977913684476372.docdoc 673b66564bc293cc5e89a33f4b16692f12071b7984f57342f1e011ddd5cc96d0Virustotal results 26.23%Heodo
2020-09-24FILE_9176081611067886073713326.docdoc c53bc4b67b9b49868bbb7d3a8323cbd2b411a41077e2b691eb9e66516dde0e4cVirustotal results 29.03%Heodo
2020-09-24BAL_YR5556750091JG.docdoc 27dc3b44a37b8d1d2c9fb8be66fc68db20eddfd82efd9aec4a13681328129242Virustotal results 27.42%Heodo
2020-09-24INV_BLK_090120_KDZ_092420.docdoc b917f18fc68c1232bfae7c7930a329fb6758d94bfef9604d75586b41733d2426Virustotal results 25.81%Heodo
2020-09-24ALM_090120_QUX_092420.docdoc d6f4d312b2434777abc97c10e41bb86186836a8a9a2e08b5365e301afae8d0b3Virustotal results 23.81%Heodo
2020-09-24BAL_32770582.docdoc 47c8e3e92b05f289d4c090f3405365aa37f8e0d0bfce6535dc59d999117a2fdaVirustotal results 20.97%Heodo
2020-09-2414771211.docdoc f2566951b2f270b88cd2a864576ae53db3bd5f3fcea221a1b088b8ec0d6f6eedVirustotal results 22.58%Heodo
2020-09-24Z_PO_09242020EX.docdoc b0c9e63cd039da312aea84e7c632e4faab8fa1bf3b6d8382f6fd898635c39941Virustotal results 22.58%Heodo
2020-09-24FILE_TT1624113653FT.docdoc 994c514f41d20931aa98bc87ccd2de05af9f8245435c55b0f29f7d2062c9b5f5Virustotal results 22.95%Heodo
2020-09-24DOC_WXYRKTF4A.docdoc 04c40043a6f85ced583227c163faec46ab1ea268357293dea65e35744895955cVirustotal results 21.31%Heodo
2020-09-24BAL_TLQ_090120_CVQ_092420.docdoc 2cb8e1446721719846acffe071530942784ff1af5081ba4740e713f33ef02571Virustotal results 20.97%Heodo
2020-09-24FILE_XC0036216191KP.docdoc 7439811010be6eb023390a28eff9b2acf598883daf1cb66bf4c6e78bb8f13998Virustotal results 44.26%Heodo
2020-09-24B_20700588675.docdoc e03588b5c327278e634c775b1f13c311c8aa3494cddd7aff114eab54dcae3c5en/aHeodo
2020-09-24PNQU_UPV_090120_ZOR_092420.docdoc 4d6a492ccf58a9712b96c0ce4443b1881fa7405bbda94ce7cc0a92ef06a2daafVirustotal results 40.98%Heodo
2020-09-24REP_OF5273951715IW.docdoc 4e227495a216d86b2e51164a32e9ec057c53cc5e829107af1aeb4ee9764bbdccVirustotal results 36.07%Heodo
2020-09-24BAL_NU8123908708UK.docdoc 3b2da1783943899a3e23e20477670990adbde1f6edb9bb2e2ec1aa640c601f3dVirustotal results 35.48%Heodo
2020-09-24H_NCWEEUDRLUQFET.docdoc 813c3689cf9fecd602a950034dcd90f060f360f68193e239a02e13ed8587c220n/aHeodo
2020-09-24DOC_PRH_090120_CGX_092420.docdoc 460c0444a86100a7f337a9393b066f52417741dda4889c1d41781fb32f917cc8Virustotal results 33.87%Heodo
2020-09-24PO_09242020EX.docdoc 8f054924ac0e3a72b2725a18206bf1e2faaa327460d2e7199b1152126241d054Virustotal results 35.48%Heodo
2020-09-24PR3310824454EM.docdoc 79a7d433152a96d54a0687fd65dae6aab97a6af26dd206692bf88636977729a1Virustotal results 35.48%Heodo
2020-09-24F_88229324.docdoc 8c2167e0297ffcef1e67f0aed9f87dd7de95a4b552865584b7bd0185ac8f98f9Virustotal results 35.48%Heodo
2020-09-24DOC_RZP_090120_YHK_092420.docdoc a71d3dae8594c0336d66e366a3911fe4f349966e73fcb6c5fc9ed3077c8fcb6cVirustotal results 27.87%Heodo
2020-09-24BAL_OT3910106606DA.docdoc a7beeb1521d12c379e5eaf94aa8b734f806e5ee1cada250f51dc5c3be983a7a1Virustotal results 27.42%Heodo
2020-09-24FILE_964700713761523.docdoc 6e7ae3df631cfa3174a4e9e061f71a3453806fe930adca05896343d9e6f07ea4Virustotal results 29.03%Heodo
2020-09-24M_SB71Z3HFKGL.docdoc a6bdea3758ccb519e3736628a467290a74b47562f8a489e89346642276c9f177n/aHeodo
2020-09-24F_HC1613515716AT.docdoc a279b3d82c086e59725b814eb8f6ddde5387efb28b19f197dcb6a82e239f9906n/aHeodo
2020-09-2480582418205011109304390.docdoc b1bc22abca15845684f53bec0ca8fe04943d104d77b2028d65bd63855077731bn/aHeodo
2020-09-23H_WM7163803199YA.docdoc 1c5a69e8a8d964a5898cedf16872a9903fcf2ec9f08ce3ecd9510f8d4453c4b9Virustotal results 29.03%Heodo
2020-09-23WQU_PO_09242020EX.docdoc 7340c303b5ff42ef74e8996ab95aa2b6b742e4efcc852b96349ea6085e592f37Virustotal results 29.03%Heodo
2020-09-23REP_QBO_090120_ZXE_092420.docdoc 928e299ed0670b544432d1c87854ef00421ee91e55581b623158ef13adabf501Virustotal results 27.42%Heodo
2020-09-23INV_SE9144450297KU.docdoc 76435bca763f869f80daabd795435e20bd52e2cff25a5594ccc20c8be946a2e8Virustotal results 37.10%Heodo
2020-09-23REP_RP5561634764KV.docdoc 15d9c4a8449193c0406c1005887328daa93d847ea063f9097f0eee39bc404df0Virustotal results 37.10%Heodo
2020-09-23BAL_61154554.docdoc c9de56d138a927505138fdf267dafe6d598cdd4338db121b7d7b5f9a982a3a49Virustotal results 41.94%Heodo
2020-09-23INV_18989271.docdoc 5d7354671a544c392039f3b512158f3505f576f34e4942109e8a7adf19bd07b0Virustotal results 35.48%Heodo
2020-09-23SSCZBBZ1KWQSXB2.docdoc ce373513080505fd4e582d2b84d8a670e7c84c18db398f74ddce4490adb67517Virustotal results 35.48%Heodo
2020-09-23E_NLMYSK9TMWPQM22N.docdoc af30fde0408423890089732bcbfdcaceafef7e956d54f04df162a7bb72e7a673Virustotal results 33.87% Heodo
2020-09-23NX1584756767OW.docdoc 887fa6a834121789518a2119d59559b212de2d235e454fd67d1e000e8ee7df1dVirustotal results 32.79%Heodo
2020-09-23DOC_YC3389411322AE.docdoc 3d0062b20db4e52a4f9612964699a06f8920aa931e2126424d8190273b7eb948Virustotal results 35.48%Heodo
2020-09-23RBX_24206327591319.docdoc b9b92fd2db926541ffe87cdb4d652394ddd2b33559d51db96c862ffe2e6c2e1dVirustotal results 33.87%Heodo
2020-09-23SNDP_YG9755469783VC.docdoc 275e74c921d4676893e049215cd0a40ade4ca28564af84272af361f86f62283aVirustotal results 33.87%Heodo
2020-09-23FILE_55800615.docdoc dc22889242c4ec3f0a5cbe5050df8ee1ccc8231c28a144700b02bbaea1e2a1d2Virustotal results 31.67%Heodo
2020-09-23REP_7W9LCHCM4FZSI0P.docdoc b09074b0d262c73c66430e4e968ebee0cb946881c69d7b7fd8bc9130a1731482Virustotal results 35.48%Heodo
2020-09-2351278923462644149723.docdoc 87147834cbde11b3f37c516844cf8d9ba78e603010280ee9eef5e29c92b10425Virustotal results 37.10%Heodo
2020-09-23BAL_36641054.docdoc bbb6d73f3985fbf140b54d8d677505a103c94a9bb2c084c3fb92dc9c80e06a80Virustotal results 37.10%Heodo
2020-09-23INV_CSE_090120_YCX_092320.docdoc 189c119c3845bfa395e55f7693e1e1690fd7eeb31e427128db7cba27719cac66n/aHeodo
2020-09-23BAL_NWO_090120_YHU_092320.docdoc bb8142568de9017ef615f6eb92b63a11795c3d48f30b36957efb191f225ee49bn/aHeodo
2020-09-23DOC_KEC_090120_XOO_092320.docdoc 952b656649c633a039c06ac4138ac005b789c82749170299de7fbb2a45f22a10Virustotal results 37.10%Heodo
2020-09-23REP_CRULNY9SM.docdoc d3cf2b43d2a246e276c8ca88790a65e01e230e8c8c39127d094f43247e2f0175n/aHeodo
2020-09-23A_OI1065438277XE.docdoc c980d702be195e7d9a7a06c7a0dab824d1847b8a459dbd633228ce99b0421f8dn/aHeodo
2020-09-23FILE_07941201.docdoc abac1b85fef1b60626e2d74a8f0888a7b908c222303b742556a2226994ddcd39Virustotal results 33.87%Heodo
2020-09-23DOC_46089063.docdoc d4390cd40a3c73248ab3f9394b7f48d2856dcc08e7291ad0514634f0ce5cafa1Virustotal results 33.87%Heodo
2020-09-23INV_PO_09232020EX.docdoc 837c550fff034632d2b0963b5cbef7f23f932fb6439d9ec26b324655c31b1320Virustotal results 32.26%Heodo
2020-09-23UVBL_66645240.docdoc 33debf417ff359cd96e0bb0884610933181957da9e965e52c2f02a2c698ac306n/aHeodo
2020-09-23Y_PO_09232020EX.docdoc bd69ecf726bce791184672d5e8317729c49e46729a648023c07701eb61a005e5Virustotal results 29.03%Heodo
2020-09-23DOC_82358320.docdoc a877dd61b25805e938555868388a8543768fb01e9c45ae6072c261f61264d466Virustotal results 34.43%Heodo
2020-09-23DOC_RE79PW1TSXIBHSEB.docdoc 936e0b3b696a31047618a5ffe005e0500e2dd472581d4df1580db803e19cca8aVirustotal results 35.48%Heodo
2020-09-23FILE_04967547.docdoc 0e75f83d188cce264243b1d4f3674c4772e6aeb39415aeba5a32b20362127e33n/aHeodo
2020-09-23PO_09232020EX.docdoc ddf9cd73acc0f44cf4ae5e63e11779ce316031dced2882ea971ecc4a99a37b80n/aHeodo
2020-09-23INV_33897763.docdoc 4e02784f17b866165db458c9ae3f13edf8dae02967921cfec16074018e8cd2e7Virustotal results 35.00%Heodo
2020-09-23YDU_090120_KRR_092320.docdoc 710beefc4939b7fe4e0362f66fd592fc87a04fff8aacf8424eb0bd4858115fb6Virustotal results 34.43%Heodo
2020-09-23U_BRQMMV7524U1OPX.docdoc 1ce7da03432f012ef79797a1eebcc19389de8f1ad5f493fe02e71ac4d324464dn/aHeodo
2020-09-23DOC_EI5344862497QX.docdoc 23228721f30ca78a87d92bafd441f784d43b35778a46e3fb21fcca990fdc778dVirustotal results 35.48%Heodo
2020-09-23BAL_PO_09232020EX.docdoc e701a67030bc767a30c999f4bc07249218be0f846de4294b4ca96b3a64ea169dn/aHeodo
2020-09-23BAL_99821095.docdoc d883db39359e5a0cf794c3c7892eec5ae89669110839e909876a1b5aa527ddbfVirustotal results 30.65%Heodo
2020-09-23V_DNM_090120_HWY_092320.docdoc b336f37fbeec6b771c4d1282df6155ac6cbf6fa00c89ecf7447ab97611be4d97Virustotal results 43.55%Heodo
2020-09-2347163710.docdoc 660f78796bad236818c239f650cb2139c4b079a2f0f5dfd4d0bc59eed2b85035n/aHeodo
2020-09-23INV_08276896.docdoc 66aa75aca1e5a0fae3797f424ff58868d5a813eeef2d2c287a893e91b60769f8Virustotal results 30.65%Heodo
2020-09-23DKG_OP9019309433RH.docdoc a764b97c10642b54bb233b7b21600d0fee72a50715fbf578956ad7ccb2371f8aVirustotal results 30.65%Heodo
2020-09-2371022859181936.docdoc b84c54a1704a22ceac88f79804b5a23b2a64547cadf21d76291d01f84b0e77d6Virustotal results 31.15%Heodo
2020-09-2341722959.docdoc e543adff7cba9ec05fc7d78a55b89e22cea00ca50df6e67e06250420b9f2ec48Virustotal results 27.42%Heodo
2020-09-23INV_797611620838495090.docdoc e446be795bac5464b1bb80859e2ffd0857fe8d26f1f6973457b491498010f0c1Virustotal results 26.67%Heodo
2020-09-23FILE_F1JUWWBWQVE.docdoc 770a13e4b2ad169f027bbdb1dbd5317f83cdd7a7b28e6ac67e30614cdd534a29Virustotal results 27.87%Heodo
2020-09-23INV_HB4481983089ZP.docdoc dab27520c5577f059d11bd78d22f8d5cf492cdc0150781ba9b28b5fbacc5c185Virustotal results 27.42%Heodo
2020-09-23PO_09232020EX.docdoc 04648ce7223361494ad5620c674be88a869710007f672d05721b77af59be70fdVirustotal results 30.65% Heodo
2020-09-22T_LK7MB2H4IQDS3.docdoc af31068680a432b4d1d2164488f6353795fbb745479373bbafc6a60e9cf25169Virustotal results 30.65%Heodo
2020-09-22LIOM_HCU_090120_RRT_092320.docdoc 158dba6d537edd9c1fb56cc2c1307f00634cf5188667321946c2247e02eb6c40Virustotal results 29.03%Heodo
2020-09-22I_8S6QUQPRDB9.docdoc c4ed4d279282ab289d7a00ba9d05f1f31af4a3dafbe02ae91aba6585d55506cen/aHeodo
2020-09-22REP_PO_09232020EX.docdoc 096e7d0d8016a7efe13a6bcfe45e2b78d115eb681a6f855b639a9ca3c8db22c4Virustotal results 30.65%Heodo
2020-09-22DOC_PO_09232020EX.docdoc f81dc1dd571c29424756de4b14efa593fdea619f32694846535c4820c9acf375n/aHeodo
2020-09-22FILE_55383359.docdoc 10fe3df8f6540696c8eaf649bc752e30d5533b0203869ec0839cf045227620ban/aHeodo
2020-09-22XDPY_SNE_090120_HGW_092320.docdoc c6e601d3f1268441a2518c331465ffd7acd22aae6e1526662ffcac834946f259Virustotal results 27.42%Heodo
2020-09-22PO_09222020EX.docdoc f929a641d61afcc3da16efb268321fa3a98a19ed3cacd0d1b6b2a98c5de37d35n/aHeodo
2020-09-22OS_27301168.docdoc 1c64de03ffee1b612358e9f45424fa90efb35ee3f384839c5d48f8932bdb23a9Virustotal results 27.42%Heodo
2020-09-22PO_09222020EX.docdoc 526a3a875236eb66c2fa9894594c30025d794c8ecbe0dde1fd873dedfab79497Virustotal results 21.74%Heodo
2020-09-22CGQJ_7287320110476924.docdoc 698748ed65c5d697095b866208160f8b4142e8d3e66a8cf826de1601fb3b080bn/aHeodo
2020-09-22PO_09222020EX.docdoc 8b086b781acec12715982f30c39eb5d20950325e39a5d84b33a6df96d9edcf8cVirustotal results 27.42%Heodo
2020-09-22P_WPT3MN9RWAUDJR.docdoc 02503f6546f32015f98eb839efb8b3d86d56b8ab5de5a30b5d6e99b4bd41802dVirustotal results 32.26%Heodo