URLhaus Database

You are currently viewing the URLhaus database entry for http://qualityhairbundles.com/of/docs/kljnu017/ie944840324547177796j43ag21yiojmuvt4hg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:606773
URL: http://qualityhairbundles.com/of/docs/kljnu017/ie944840324547177796j43ag21yiojmuvt4hg/
URL Status:Offline
Host: qualityhairbundles.com
Date added:2020-09-23 19:11:34 UTC
Last online:2020-09-24 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-23 19:12:06 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:16 hours, 42 minutes Good (down since 2020-09-24 11:54:52 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24DOC_952S5JCGP5T.docdoc d9e5e99a04e37db7783f369c532e2e6d5171b90a286f2c397fcd6356a1abcce9Virustotal results 25.81%Heodo
2020-09-24V_79840206.docdoc 35fdf71d1156a709edbfc6250568a61a62afb183218e5fc5ffc1249ab07bb4b3Virustotal results 25.81%Heodo
2020-09-24CY83TNV1.docdoc 740ea2b635d60e6415d33b3efebb49934d260bae03b4e879ca4b78855680b019Virustotal results 22.58%Heodo
2020-09-24INV_PO_09242020EX.docdoc 21e3f5e7a57c3e1871bec153b6876e793eea367a4c1cb2876681f858454ee52cVirustotal results 20.97%Heodo
2020-09-24FILE_52787312.docdoc 573cf8b0e537a825c17e7f74be98dc2516d0b509eb22cc7a259717e53d50ec53Virustotal results 20.97%Heodo
2020-09-24336062477053928400.docdoc 6e5bcd9db826f2b855f63e8a591e02ebb0bbd141387d2922e3e251fc8ddbcbb8Virustotal results 19.67%Heodo
2020-09-24X_87936157122985951676.docdoc 9002b2aadfaa8b371cdf11d233531ba292b5dd90cc161bd7e132c3d49ce79fd2Virustotal results 20.97%Heodo
2020-09-24YK7584105259QY.docdoc 2cb8e1446721719846acffe071530942784ff1af5081ba4740e713f33ef02571n/aHeodo
2020-09-24UN0188687698RP.docdoc e2dffd7e2a3663a738dac21fd590dec2cce14df9ccf7aebcc5944258a827bc04n/aHeodo
2020-09-24FILE_LCP_090120_OJQ_092420.docdoc f2621313b9111b762e3fdf55bb9e64523d3a6ee50a09b193cc339ab22a42cecfVirustotal results 41.94%Heodo
2020-09-24BAL_YT4204065052KT.docdoc 4d6a492ccf58a9712b96c0ce4443b1881fa7405bbda94ce7cc0a92ef06a2daafVirustotal results 40.98%Heodo
2020-09-2443233112.docdoc 581091d124784af196ac242540f360f1ef2ab6e5e346ec9125a467b47e5e1f4fVirustotal results 37.10%Heodo
2020-09-24EW2619161318BV.docdoc b86aa2863a808be4474b2ee7285bb8642b67c9706f68b81925ae69c824defd8eVirustotal results 37.10%Heodo
2020-09-24PO_09242020EX.docdoc a48a197539aed2368c68f377ee4e1a8886412cabd39050e98b3fab282c089d39Virustotal results 37.10%Heodo
2020-09-24FILE_OW4042290432IJ.docdoc 7aed739ebb48064d94fa17f51816a7d3f4414ec8d578a6bde0830e844055e971n/aHeodo
2020-09-24G_BB6962516186KJ.docdoc 8f054924ac0e3a72b2725a18206bf1e2faaa327460d2e7199b1152126241d054Virustotal results 35.48%Heodo
2020-09-24FILE_83093414.docdoc 79a7d433152a96d54a0687fd65dae6aab97a6af26dd206692bf88636977729a1Virustotal results 34.92%Heodo
2020-09-24BAL_AT834ZRJ1RP.docdoc fba080b64f42891f1ddec30a5a83c9881e8b8dc2e577226eb1575654caddc56fVirustotal results 35.48%Heodo
2020-09-24BAL_PO_09242020EX.docdoc 55d2d07c2dcaff03658304df8b3b1b80946d30f441ff14743dd2ea7130333746Virustotal results 35.48%Heodo
2020-09-24REP_QC5NSWDTD.docdoc eb45dca6aca88223d8145576132a86f7f21770508a20b6335021ea03cc040d8cVirustotal results 35.48%Heodo
2020-09-24MSGYZ0P45.docdoc 0185c23ef468c062bc446ffc87e7af495c49e991d0a24c67634d8f0cd3d8bf8bVirustotal results 32.08%Heodo
2020-09-24PO_09242020EX.docdoc 870ba595f65af8d1f314816bf60f9dc98864d389bb9f8c78d934b32fdbff7bb4Virustotal results 31.15%Heodo
2020-09-24INV_GL8304254113XU.docdoc a6bdea3758ccb519e3736628a467290a74b47562f8a489e89346642276c9f177n/aHeodo
2020-09-24INV_PO_09242020EX.docdoc 3caf40ca5ad83988dcc46183de98c772464dd0447db89cb8ad5cbae02587039fVirustotal results 30.00%Heodo
2020-09-23INV_50067019.docdoc 16d16ae909ca22dc9c0dbac471cd299964065913894d10f00e91a967f2eac359Virustotal results 29.03%Heodo
2020-09-23AT5426288727PL.docdoc d74a0a2af76d37b9621074bc15dee942c972ea0fe761110f8767c1b836dec555Virustotal results 29.03%Heodo
2020-09-23REP_26827266.docdoc 13b44fe04aec7fdc7dce67de3a987317ad25ab9301110382847ca08bd645f2beVirustotal results 28.33%Heodo
2020-09-23FILE_00937988.docdoc 76435bca763f869f80daabd795435e20bd52e2cff25a5594ccc20c8be946a2e8n/aHeodo
2020-09-23CF6302319430HT.docdoc 5d7354671a544c392039f3b512158f3505f576f34e4942109e8a7adf19bd07b0n/aHeodo
2020-09-23REP_PO_09242020EX.docdoc 042dc54cf3a44dd90279a0057a99dbfd68e9b60897d814d0d37a6f28da370859Virustotal results 34.43%Heodo
2020-09-23DOC_PO_09232020EX.docdoc 4d6009c18bae92b1e904d67ab192ace86b9375c14eeb4eb84401e3a363b403c1Virustotal results 36.07%Heodo
2020-09-23REP_TH5778843521UR.docdoc 5d5e964840d2d7f401bae3568724b259b02c4485c211ccc7ec23c0273d11edd1n/a Heodo
2020-09-23GB2995745467DA.docdoc b2f9a597db846fff8f8fed8d950d0b3be1f06ba1dfe8add6aef001f6d469acfan/aHeodo
2020-09-23K_RNR_090120_YYJ_092320.docdoc 275e74c921d4676893e049215cd0a40ade4ca28564af84272af361f86f62283aVirustotal results 33.87%Heodo