URLhaus Database

You are currently viewing the URLhaus database entry for http://gricoatdecolombia.eiserpublicity.com/d3xfdzq/eTrac/txg2plkaa/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:618159
URL: http://gricoatdecolombia.eiserpublicity.com/d3xfdzq/eTrac/txg2plkaa/
URL Status:Offline
Host: gricoatdecolombia.eiserpublicity.com
Date added:2020-09-28 17:46:07 UTC
Last online:2020-10-07 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 17:46:09 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 days, 21 hours, 25 minutes Bad (down since 2020-10-07 15:11:33 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30FILE_33355799620602.docdoc 7d2c8d827a62c501876d11119d9989eae86dc953f1f0ced0c65a9567cb616fbbVirustotal results 22.58%Heodo
2020-09-30BAL_24553583.docdoc fc6f0ac3e38b970866e30342911b1f72bc2a028a33a093badc8c5694321d5808Virustotal results 20.97%Heodo
2020-09-3053324262.docdoc e9a9d7c87ef767357d0019c6185d27bec8449b2abd340b93b54b6621c426fc14Virustotal results 20.34%Heodo
2020-09-30UPK_090120_ZFD_093020.docdoc 24e3ba16d86892e3c786b97123151b7a2294602a61bafd3c546475d0597a2a37Virustotal results 45.90%Heodo
2020-09-30PO_09302020EX.docdoc 8c898e6465f4f641ea5dc6095375eb50772f4b2d7b0d50f197f74567af847cf8Virustotal results 43.55%Heodo
2020-09-30N_OXL507PDGGHL31.docdoc c648f66670c65dcb17a1ec6a90617481190da0ff1eced41135b2435893b66c22Virustotal results 43.55%Heodo
2020-09-30DOC_17668425958.docdoc f69c957e912e4eb54ca00ba379a5808d47ebcb4667393b4b986d2d50ee35e7b6Virustotal results 43.55%Heodo
2020-09-30E_IBV_090120_GQQ_093020.docdoc 1f7fb407f4aa9c2e8d59826ce97d6fa642f0103b0c140bb54dc65cbe8f8c92f4n/aHeodo
2020-09-30Z_PO_09302020EX.docdoc 3d322e72fd831b7624674c0a9ed650c75bf0cf2d05e5c2dcf7746ee4187260b3Virustotal results 45.16%Heodo
2020-09-30REP_PO_09302020EX.docdoc 896b1086164f16900fa21fd364f85761da882abeb87573d0eac49e7dfaf2524bVirustotal results 43.55%Heodo
2020-09-30INV_YI9689436314AS.docdoc 5989ac83f73cf6a5aec06cf124e7ec4ae2f9704193be74a77f2e72d1fac2aba0Virustotal results 40.32%Heodo
2020-09-30FILE_87J9DQTJYFKE6LK3.docdoc 1854226276e84dabaf5ceaefe8e33cd56360b60752eef6ff1a0e8e1657931e53Virustotal results 37.10%Heodo
2020-09-30REP_PO_09302020EX.docdoc 8d0311de9248f3fc0efd38e822a2d51fb26ec893e9cef6a0f81a2c2b2ea62bd6Virustotal results 36.07%Heodo
2020-09-30ZKV8711WV7IAGN.docdoc aabd54aa244d3a19daa025d685a63495581f02a35c44e11bdb76ea7bbf7360baVirustotal results 32.26%Heodo
2020-09-30BAL_6262446548715100011.docdoc bf8dca92c415f9441d506b7b5aace8b6d6bfbd8d67351b32abc27e2ef1e242efVirustotal results 32.26%Heodo
2020-09-30PO_09302020EX.docdoc b3e10600287dfaee56f53325acb38c44c75d92fdda24bce58c9d231eebc0bd06n/aHeodo
2020-09-30BAL_447PCAD5C0AWI.docdoc ff1650382e69268384234b18f44e36d54c6f3dbadfd3a0ef497e97729639a6b3Virustotal results 32.79%Heodo
2020-09-30QY_BV0924185318CV.docdoc 4a9f3550003b6a5732c04dafb0112c4a68a0e1b9b00f0244bbf65efc7561823eVirustotal results 31.15%Heodo
2020-09-30FILE_14891138.docdoc bbbd4c73bc383a0187533459a3e99105ef733893b116bda7aebf13a371dba532Virustotal results 32.26%Heodo
2020-09-30REP_C7A52E5RB8TR.docdoc b11de73e98459e676a482af2c4e52dbbaf7d6cc9fe43b57ab758f3ffed754223Virustotal results 30.65%Heodo
2020-09-29REP_PO_09302020EX.docdoc d6baf92252e2e3e673077f1cea8fc4bf0e240f4383dffc91c53d88857ba5fdf7Virustotal results 31.15%Heodo
2020-09-29INV_LUL_090120_FFJ_093020.docdoc ad21f91ac048eeb669e0a9cc8199225d755cf89a9f5d79d7fb39ef2659f04a9bVirustotal results 29.51%Heodo
2020-09-29DOC_RUJ83W0P5EYBI.docdoc fbdacf9e30368d59414b52f459d935964b7833d6d8467bf0eb4ccfa97f71e4d6Virustotal results 29.03%Heodo
2020-09-290943159453023.docdoc 16b031e38044afa7252dbfb56c762b3723de1cb4b3535a8c76bd5d4f10a2819bVirustotal results 29.03%Heodo
2020-09-29REP_033803185715.docdoc 76d3bae4ebe683a5d3ff0d90971119c287a3acbab073e28b979ad7eaa60e37bfVirustotal results 27.87%Heodo
2020-09-29INV_DZB_090120_BMF_093020.docdoc ec406f315de493ed38f3fc8e7bdd65664965b74a7215c69123b3e1c08ec28fc8n/aHeodo
2020-09-29INV_W9Z3V4VWZ.docdoc 1af9c4541fd3967f4d9820ee633cde8bee8d73612d046cba0456debdf28313aeVirustotal results 45.16%Heodo
2020-09-28REP_03582513909278.docdoc 582f57c091cdbeb80216ba0b447cb9e9524da65ca308a91662202ff6966d3703Virustotal results 30.65%Heodo
2020-09-28DOC_76568185.docdoc a2d98ee1792c2c1cf3ac1d73267579b9a649b5e9182003f74fda6c5e52f6d4den/aHeodo
2020-09-28PLV4A4400Z.docdoc 10adf11054062023630c6ac237bb5c95d074c3e1cd8f78f79fb38542ee1b824cVirustotal results 29.03%Heodo