URLhaus Database

You are currently viewing the URLhaus database entry for http://blindshade.com/brochures/balance/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:605876
URL: http://blindshade.com/brochures/balance/
URL Status:Offline
Host: blindshade.com
Date added:2020-09-23 15:08:10 UTC
Last online:2020-09-25 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002958468 created on 2020-09-23 15:10:07 UTC)
Takedown time:2 days, 4 hours, 18 minutes Poor (down since 2020-09-25 19:28:48 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24C_V3DKISEKM1.docdoc ab91db60823e2094091fd21a60eda971c965e334da7b12f08b02334d781397e4Virustotal results 24.19%Heodo
2020-09-24262200837.docdoc 1c66ec5827934e0744220674a8ae91d47bfa027376d756dd4722ecc165f09878Virustotal results 22.03%Heodo
2020-09-24GOFI904B75.docdoc 21e3f5e7a57c3e1871bec153b6876e793eea367a4c1cb2876681f858454ee52cVirustotal results 20.97%Heodo
2020-09-24D_GX4089880818DL.docdoc e4a782671d6a001f226fd064f2f6204cb368f6e4e82aad502a4d5cd56b65a78bVirustotal results 19.67%Heodo
2020-09-24FILE_4052696133686733025201706.docdoc b1ba77be7809b33fe1f34d2a388f0d8397bac88ac18ebf4fab88748d6fe2edf2Virustotal results 21.31%Heodo
2020-09-2487038250.docdoc 6cbd2115091ed6aac27b36f75ef0aa1328e9cd43fc463b039ff9cefed0d8b1f8Virustotal results 20.97%Heodo
2020-09-24INV_35914652.docdoc 04c40043a6f85ced583227c163faec46ab1ea268357293dea65e35744895955cVirustotal results 21.31%Heodo
2020-09-24FILE_PO_09242020EX.docdoc 77a72a7f45a2e516a520ecb15d79adaa7213cb9778309de61bc9dd2a8a2e5891Virustotal results 21.31%Heodo
2020-09-24INV_43861890611.docdoc a92504d33c04f21f1e8bfc2322f66cf3d45f486ed7ebbf78f3ee270fb0d3e3a2Virustotal results 39.34%Heodo
2020-09-24BAL_EMJGRJJP7HNA.docdoc 4d6a492ccf58a9712b96c0ce4443b1881fa7405bbda94ce7cc0a92ef06a2daafVirustotal results 40.98%Heodo
2020-09-24HX_BWH_090120_WHV_092420.docdoc 21d6462af9e28cac11c5b8bc20c9f07e953c7af99c15966175e8b8cfc8ee9363Virustotal results 38.71%Heodo
2020-09-24DOC_OUC_090120_VPY_092420.docdoc 3b2da1783943899a3e23e20477670990adbde1f6edb9bb2e2ec1aa640c601f3dVirustotal results 35.48%Heodo
2020-09-24DOC_JG4698571774CD.docdoc 813c3689cf9fecd602a950034dcd90f060f360f68193e239a02e13ed8587c220Virustotal results 37.10%Heodo
2020-09-24GFX_090120_JQC_092420.docdoc 9d3a4dbf3d2bb53bc85aa8598f2eb220e74dd85928693e3fd6bca9c88e0571c2Virustotal results 36.67%Heodo
2020-09-24E_76186603936214727952.docdoc 505eba500eb177462772c3c20029c6a8da6ebae013e23593e8647b31eca13dedVirustotal results 37.70%Heodo
2020-09-24DOC_KZ0525766522MG.docdoc 3e64351afeaa45724ba4e119f792781b8f1e311623e056e6c7f2f27f2ee9cc5aVirustotal results 35.48%Heodo
2020-09-24BAL_FE6043790715LN.docdoc fba080b64f42891f1ddec30a5a83c9881e8b8dc2e577226eb1575654caddc56fVirustotal results 35.48%Heodo
2020-09-24BAL_BH5009731779VL.docdoc 7f480dae416960104d9733a280be27c1a6381c1a310cb1f7b7b4acb7aa83fcdbVirustotal results 36.07%Heodo
2020-09-24VB9541484755YJ.docdoc a5be49695d9d336e787b37a7a4955307a263c426f7cae3cecdd69d2bfe026585Virustotal results 32.26%Heodo
2020-09-24REP_PO_09242020EX.docdoc 3482064d619a9c734533009937366a4864fecea1851ae5ebeb2998b8b40b0bf1Virustotal results 29.51%Heodo
2020-09-24DOC_PO_09242020EX.docdoc 098e0c52d47feef3ad6ad20535919541c76799f4bddd67233049509a0ae8656dn/aHeodo
2020-09-24669869150.docdoc 0e30a7bc2d19a489b6c26b22e411e9f691cfb0b9d693a5888ae064519809470cVirustotal results 29.51%Heodo
2020-09-24U_Q9VLX2F3AL6V.docdoc 1cc5edeae07046d2a02914d85adea7d129c619124b76e405e99f63acb512503cVirustotal results 29.03%Heodo
2020-09-24DOC_6710484274100984112395.docdoc b3d57ca8076070443526c2cb24b0a0ec82bdde3df2573290b884425536b600b6Virustotal results 29.03%Heodo
2020-09-23REP_WOV_090120_HOY_092420.docdoc bad24e6bdf40e58be83bdeb717bcb1a09ae986e50f8c51fdc11ff8de777a4482n/aHeodo
2020-09-23XFZS_PO_09242020EX.docdoc 8c5a7c3909eb8fa754ea6c689f2063f553e1400cc12b30266c8f59479453ef0eVirustotal results 29.03%Heodo
2020-09-23498977586476821150983161.docdoc 76435bca763f869f80daabd795435e20bd52e2cff25a5594ccc20c8be946a2e8Virustotal results 37.10%Heodo
2020-09-23INV_46294747.docdoc f62ef7f415a25bbe326cecb39a15134327c963de9253795427a71974f8845b6fVirustotal results 34.43%Heodo
2020-09-23FILE_PO_09242020EX.docdoc eabfce0e3ace401756754cf86b0f1b5f1057f2a9466eb1b74c4bb1cc0c134d71n/aHeodo
2020-09-23AA4296052873GP.docdoc 042dc54cf3a44dd90279a0057a99dbfd68e9b60897d814d0d37a6f28da370859Virustotal results 34.43%Heodo
2020-09-23FILE_656058659533593326521.docdoc 17f28ba9ec3406178924435252e81db9e219bc21ccc0520d3c699ce0878dd738Virustotal results 33.87%Heodo
2020-09-23PO_09232020EX.docdoc 56cbf96af906adc2960627f7308bbccef3283458499dad9a032ec264a6e46644Virustotal results 33.33%Heodo
2020-09-23VF6W4TVI6.docdoc 843b2da06ecf481cd70c1107d6a3ef2e8cf393019f8c6019d1105e0456fc3313Virustotal results 35.48%Heodo
2020-09-23DOC_CPMT7MGOK9.docdoc b9b92fd2db926541ffe87cdb4d652394ddd2b33559d51db96c862ffe2e6c2e1dn/aHeodo
2020-09-23W_LFC_090120_PLX_092320.docdoc 15c9d94e300b7177907171c24a7cf8cbdf3ae42a1bace42390eaeceff66d89b6Virustotal results 33.87%Heodo
2020-09-23PO_09232020EX.docdoc 26614fe04700998a42fbb7c3d84cbce63bd4a32aa9de3efe130ee1366827c094Virustotal results 34.43%Heodo
2020-09-23BAL_TB6612149433VN.docdoc 60c842c5f189f507fc85b61c2c4f51f02082609590c8b3e38580179f6d6c6657Virustotal results 36.07%Heodo
2020-09-23BAL_HHU_090120_RLX_092320.docdoc 914b8769a89b16d3231958e8a03e2af289e32de76df9839de1c4ab3c2679f9f4Virustotal results 36.07%Heodo
2020-09-23S_51536451.docdoc 93376fc8dbfe2e11658564d1aa1e9088e6f7ad6a61d1ff146651df3d275c839dVirustotal results 37.10%Heodo
2020-09-23INV_17415732775355666161148.docdoc 236f77c28643d0ad263544a59652f3a3392c2de3e57ef1644b7d3716e5b87a96Virustotal results 36.67%Heodo
2020-09-23INV_813003708.docdoc a115966eb8c424bdd009722a91a269d04b1f2f646c0f048ee8d08a2d1e3746a7n/aHeodo
2020-09-23JMZ_090120_UGY_092320.docdoc 48fb9960d4880303b9ac71ab8d6d52f5853ad6b0520aa8a6ebc470ddcbd3085fn/aHeodo
2020-09-23BAL_DD4139552026QZ.docdoc d3cf2b43d2a246e276c8ca88790a65e01e230e8c8c39127d094f43247e2f0175Virustotal results 33.87%Heodo
2020-09-23WI_PO_09232020EX.docdoc abac1b85fef1b60626e2d74a8f0888a7b908c222303b742556a2226994ddcd39Virustotal results 33.87%Heodo