URLhaus Database

You are currently viewing the URLhaus database entry for http://baatzconsulting.com/EN_US/Attachments/092018 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:61089
URL: http://baatzconsulting.com/EN_US/Attachments/092018
URL Status:Offline
Host: baatzconsulting.com
Date added:2018-09-26 22:50:31 UTC
Last online:2018-09-28 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-26 22:52:21 UTC to jeff{at}sudjam[dot]com)
Takedown time:1 day, 15 hours, 42 minutes Poor (down since 2018-09-28 14:34:49 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-28form-56708278779328.docdoc 2be2af5135aff09c03a9676a1832ec019493dd6efb776c221bb83ab64876b390n/a Heodo
2018-09-28FILE-4803301865319.docdoc 6cc91d59850a8f08a69ec32ca8c10e44a3ce7e5ce2ee4fae84b01f7c9ffa9ff6n/a Heodo
2018-09-28form-5399691954.docdoc 6c7dd9c5f28bd50f55b95c7edfd6aac33ec177ce240deeb95dc197861e4f4e7an/a Heodo
2018-09-28FILE-7725815623684.docdoc 2a2c4c88937ba9df57f575150921f3d2263d1f33398d684b20a6b12bd836d577n/a Heodo
2018-09-28FILE-795895186328355.docdoc f8b789c9db49c8d5f8de129be7941f7047483e3076b5af2dd9f938fd41dbf854Virustotal results 23.33% Heodo
2018-09-28Untitled-09276816496.docdoc f8648621b583a6dece712e222b613117a21431a462f0782cfbb5e6e8c8a7982aVirustotal results 29.09% Heodo
2018-09-28Untitled-1637558741.docdoc ddaf4bd998a507399f04865a80cba516cccc56590895849486ecc4da509a0174Virustotal results 29.51% Heodo
2018-09-28form-55346489050.docdoc 45429290ab6028c8e2046ef40c91fa1032586372caa33a9b565c34278805bf3dVirustotal results 29.51% Heodo
2018-09-28form-55346489050.docdoc 45429290ab6028c8e2046ef40c91fa1032586372caa33a9b565c34278805bf3dVirustotal results 29.51% Heodo
2018-09-28form-6095370527270052.docdoc 25d8545230ddfe4589b7e5b9603570e6f100d490ee8f4f2d4ffdf5917c3f4514n/a Heodo
2018-09-28FORM-11634282122.docdoc 228f574e588b380dd855870733c6af18ad879b9cebfba1fbfc309acc4be7f6dfVirustotal results 24.59% Heodo
2018-09-28DOC-52948896620112.docdoc 56b08ebdd03ce6a5209d1c0d9ba40908056f011417fcaeafa77bbdd673c63736Virustotal results 24.59% Heodo
2018-09-28DOC-6856567718.docdoc 0b971ad29d2a20b99a6ba4e7701225c40fb7d8377173ce32b925ca1cada9d4ddn/a Heodo
2018-09-28FORM-919729780964.docdoc 0e2d2330890d4f6a132f5e2bb979e8a27e13ed32d17cb33d123c82a95754802an/a Heodo
2018-09-28form-9471985265663.docdoc bbe71e8f10793aa4cc2277937115a6da91cfed65a2e6aa34747bad4d1d7e6288Virustotal results 24.59% Heodo
2018-09-28DOC-6350021723121.docdoc 45c1cb8c0491a55a034b421929b3369d2d5157a5a1568961d9437a9fe5605eb3Virustotal results 24.59% 
2018-09-27doc-980594228113194.docdoc 5f1769ebbff68ec327d77f4dffa86e62d4a4ad6ada10829bb0857fa2eac2674aVirustotal results 29.51% Heodo
2018-09-27DOC-722691684473.docdoc 9b6a4842959889f21b43a620609175c2bd3d8824681d7d0d1e277fe32d663826n/a Heodo
2018-09-27FILE-3597035775977652.docdoc e9fa4207821c28bacb47b1fc9c75596cbe5cf4bb241ad990b62871b7d7338ca0Virustotal results 26.67% Heodo
2018-09-27FORM-3703323508400.docdoc b455c6753c3cfb3f13aec64c616437986964745e799eaa9a1ce8ce891fffd230Virustotal results 25.00% Heodo
2018-09-27Untitled-52360163128.docdoc 05ec0258ee7e240ea34b5998150071a0a42587394af2c018e66a1cdfb5826f19Virustotal results 24.56% Heodo
2018-09-27file-46882089948.docdoc bdc8907c19b321df8a53d24339287ecda858fb09c10c4f6fd04d818a72553e34Virustotal results 26.23% Heodo
2018-09-27FILE-0786126057594.docdoc fc25b79dcef35b140e44bf2d25ee2fca89798626c283f80c4e811f5bf0f0754bVirustotal results 25.00% Heodo
2018-09-27file-2354141064.docdoc f33911d1291def94112aa473bf61dc33ec594c07b7a8099103e77564f1650e80Virustotal results 26.67% Heodo
2018-09-27file-2066587660.docdoc ba5142dd6d662c6bf0352bc4eabd70e29d72c8f48dadb607ba47d73ce7ecbe8bVirustotal results 34.43% Heodo
2018-09-27FORM-611532445074.docdoc 5211095e6fe4a852b3bddacce0d63b7c5da2ecc2f0202632dc0006c22fec438bn/a Heodo
2018-09-27FILE-6071442959939.docdoc 057ee5a6b0654fc4dc2d28faaa2af8ae6300fe0e60121670d213d76d9389bb53n/a Heodo
2018-09-27file-94503755507536.docdoc 77f7b34815d5acfec2577e436676753340383c39982c9d14cf781b9d75028dccVirustotal results 26.67% Heodo
2018-09-26FILE-5291425512.docdoc c4c8989ef731fc53d4906a1173d42506c52762b183e82829f5ff6fba47b88928n/a Heodo