URLhaus Database

You are currently viewing the URLhaus database entry for http://spektramaxima.com/7409590BPFFLQXV/com/Business which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:61104
URL: http://spektramaxima.com/7409590BPFFLQXV/com/Business
URL Status:Offline
Host: spektramaxima.com
Date added:2018-09-26 22:51:24 UTC
Last online:2018-10-01 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-26 22:52:08 UTC to abuse{at}ip[dot]ro)
Takedown time:4 days, 11 hours, 4 minutes Bad (down since 2018-10-01 09:56:50 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-27BIZ #3400649NSBIHDPD.docdoc 231b78a40b7cc41b5ddd3cc63f9e1f45249bec580b4b8203704eba8ef8971818Virustotal results 27.87% Heodo
2018-09-27BIZ #83UFLBSZR.docdoc 996747aff1d8095f1851fece7ce4668f989cb242300c618a30d721cfb346fb83Virustotal results 26.67% Heodo
2018-09-27SEP #70UQBATVT.docdoc ff436aaa5d3fbe8f22be24ddf7a329e63835ef4b8e8a8fd93b018f9f785ed4f5Virustotal results 27.87% Heodo
2018-09-27PAYROLL #8XYFQ.docdoc 534d51a44c1dfaa71dff42c8cef884d0c888660ba6793512073cbd10b701880bn/a Heodo
2018-09-27SEP #8722ITEYVN.docdoc 5a91c72c3955dc75b80f3da01eb1cef5527002b412e6fb9952f5998eb42eb784n/a Heodo
2018-09-27BIZ #4TOSCCRN.docdoc 0ddbd8ea72ad8ec5c6c6fe5c1b718e7e2c4a8627f9fcc83f9c08b0862968c267n/a Heodo
2018-09-27PAY #2020QUGAIUI.docdoc aef1f6b128a6df92ec467dae551ef2cdec0d6306873fac5c9aeba521d47c16f3n/a Heodo
2018-09-26SWIFT #19071DDMYUVE.docdoc a53e871f7f3757cf3d21a190f88a2296deccb5f0a0ab176ef31cffad99412297n/a Heodo
2018-09-26PAYROLL #388FHTTOG.docdoc 6a9ee408add72e19dc7f57768f36fb17f8da299ddde48b492d1db8561d7b13b5n/a Heodo