URLhaus Database

You are currently viewing the URLhaus database entry for http://www.co-traveling.com/cgi-bin/docs/h1vkgh2w5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:624814
URL: http://www.co-traveling.com/cgi-bin/docs/h1vkgh2w5/
URL Status:Offline
Host: www.co-traveling.com
Date added:2020-09-29 20:16:36 UTC
Last online:2020-10-09 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 20:18:03 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:9 days, 22 hours, 16 minutes Bad (down since 2020-10-09 18:34:06 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30REP_BB8353381270QH.docdoc a3d743d11312e842641d3124985266cfd1471f8d21881fb7dfc8dfa9cbd1fe47Virustotal results 26.23%Heodo
2020-09-30FILE_VYW_090120_GSR_093020.docdoc 63d11b10d793151af69aa10ba45dcd9de40ca61834d018e42474786090043655n/aHeodo
2020-09-30FILE_7PO7YJXDA.docdoc 5fa75a02b1c855828a4a11cf3cf8da64502f2b4023c776b5f37c98ef894df875n/aHeodo
2020-09-30INV_NNXLT1GL3XDHCDI.docdoc 89184bca1106ed62901477bceef09ee282bceca404d17c44630544fdd803cbbfVirustotal results 25.40%Heodo
2020-09-30PO_09302020EX.docdoc 79b57cc855cd58d4819bb711bb59dd13e35949ada72c908e0f968d51aefc35e8Virustotal results 26.23%Heodo
2020-09-30DOC_72483907942118396156.docdoc c7b170de74bd23faa6d777bed0c29b826d7a0588fed94fe5ce051f61da72c9cen/aHeodo
2020-09-30TNO_RUZ_090120_SKX_093020.docdoc a6bda5016faa4796392e20bb0d8076147b2d6ea0f899019aed66cab6a4ad220fn/aHeodo
2020-09-30FILE_1592076298.docdoc efa9c669d5b042ca0892a07861b3f039c3d61f0fa89c57348ee5058445f2db1cVirustotal results 22.58%Heodo
2020-09-30FILE_WMV_090120_GXV_093020.docdoc f5e365e70de80b2c17172db5e9c99d037fe2d025161e0c78d7665734a2d108f7n/aHeodo
2020-09-30BAL_RPM_090120_KUU_093020.docdoc 1d5daccb3ffdca9e417370c654eefb0f6a0b2c3de51d7ca751c676d623cd57bcVirustotal results 22.58%Heodo
2020-09-30INV_PO_09302020EX.docdoc e7a2c5f70735aa280cf5aeca7377be7974e8c56d30e0d263086d484657e21d55Virustotal results 22.58%Heodo
2020-09-30VF4704172224RN.docdoc a4764b420e55695dd9b02d5ca980f126958001ea30e96a74b2e9321661bf38ffn/aHeodo
2020-09-302209833911451315.docdoc a5bc68599f8ed3a4cdd8e4894aad9cd9fa0753278b8a44af04debb277960d44en/aHeodo
2020-09-30BAL_IIKH4J8CQ0KGB.docdoc a8dae6d86f2ae529335810a70a6f959f195bf9fd10f2ade7549334ff2767cd04n/aHeodo
2020-09-30DOC_685173854669.docdoc e001efbf2686566c49c1a6428a0d6574deeae2c830622f40f5cf6fd46c6d8654Virustotal results 22.58%Heodo
2020-09-30BAL_UF3SOI13J.docdoc 6b28e785fb139d9950f37bf989bed92089e9f22d3160a16699b2fc8b0d3500efVirustotal results 22.58%Heodo
2020-09-30H_YPG_090120_BGZ_093020.docdoc dae3de0260b268fd89734a96196759e0a878835e38a868db1ec44194c212e1f0Virustotal results 22.58%Heodo
2020-09-30I_PO_09302020EX.docdoc cdd0c1df94d8411b9502cbba720232d682901752e9c2adca68104f2d07f1b2e1Virustotal results 21.67%Heodo
2020-09-30BAL_PO_09302020EX.docdoc 19377355e91331d5f2438275b1af46c6f266bd250c9e6a421feb6deaa86f7cadn/aHeodo
2020-09-30DOC_WCB_090120_HMJ_093020.docdoc f643ca2e24eeeed79a8eb15590b5adfe2d738c667c2771df28474060408f703fn/aHeodo
2020-09-3044P1IY3TQLZEG8J.docdoc 897b5043fa3f5453de07db0c956147c5a3eedaa6c2d83bd50b5da2b033da51deVirustotal results 20.97%Heodo
2020-09-30DOC_WLCK1YROS.docdoc 786c646aec87e25c98dfbac09f886f13f05a1e6690baf9974f99f1b37b6f3713Virustotal results 20.97%Heodo
2020-09-30FJG_ADN_090120_IDQ_093020.docdoc 4ec76c0d7c5f6a2a489dcc31a5670f9d7194cf38c6e29b0e002193b6750e1ffeVirustotal results 20.97%Heodo
2020-09-30DOC_68775241875.docdoc 605f71e5062dc6452e0f427294e6d436a184d7cebd4d4600c98d0a5542c30addn/aHeodo
2020-09-30REP_1YAKNH17U092.docdoc 0a2e10583a6c70298eb3c353e0a15ebd98c8a9ae09db8e6cc9cef513e39c95dcn/aHeodo
2020-09-30P_PO_09302020EX.docdoc f753b7a2b5babbf0b90ff334a9ef900a447d43c76c85cd43aed4f4c01db9bf8an/aHeodo
2020-09-30MUS_090120_RYK_093020.docdoc bf10b7e9f1ff0345f426df6b7da95cdb75284d378f7ea29d192e24623e35f3a5n/aHeodo
2020-09-30OXB_873322334590069.docdoc c648f66670c65dcb17a1ec6a90617481190da0ff1eced41135b2435893b66c22n/aHeodo
2020-09-30BAL_L8WUA8KKQG9284.docdoc 6ade151a37ef13bb683d1be47f8223f2c15ce7e77165fd2e9797e7af35a40ae9Virustotal results 45.16%Heodo
2020-09-30SU_DT1567614606EQ.docdoc 8292af351e1a3422b40ca14a730c4a8c4e65bf1fe1daaa33852934cac3a2d43cVirustotal results 45.16%Heodo
2020-09-30C_KBJFZ33AG3.docdoc 58ac8a64e7d1de26e8f6081b9ae7bfb57cf872206ae1e11eb6c00dfc798752eaVirustotal results 41.94%Heodo
2020-09-30I_25778010.docdoc 1a2856f6dfce0f239bb89c2fa41ba26f9d1761dd09caa8312e58c26aa1411369Virustotal results 38.71%Heodo
2020-09-30FILE_17912628.docdoc d2effbe4f93f76b3ee990f84ec39bf4705e34ee0a3925f32097fa08db254e4ffVirustotal results 37.10%Heodo
2020-09-30JFBG93FXO4FIQ8B.docdoc 8c21463a0b127e2db497f399810180572cf5e4027f3942919aeeccabf1d3753bn/aHeodo
2020-09-30REP_98002832.docdoc 0594dad5ba161c51ba71ffbb41c36696b151edf4d1d7738b31a026cd28164a4dn/aHeodo
2020-09-30REP_99307605920994.docdoc 8649c9f23563646d5b0033bb729307388ddb4396da639cbf0385c08ec0a01cffVirustotal results 32.26%Heodo
2020-09-305192792088.docdoc d56585c6e4a0ede125061be754c5a0c9b45728232d4c61937ffbc047df3aae30n/aHeodo
2020-09-30BAL_ZJF_090120_DRJ_093020.docdoc ff1650382e69268384234b18f44e36d54c6f3dbadfd3a0ef497e97729639a6b3n/aHeodo
2020-09-30PYD_090120_OBX_093020.docdoc 9503120eff8e09bde10d7341fc02b19428bf024bfa48b4db12e902ce9895be55n/aHeodo
2020-09-30ZIM_148723926213090.docdoc c7e94b09a7bf83d363a7949d7aef5bba5516bd5b0e0c149bbd1dc341b9cd5180Virustotal results 31.15%Heodo
2020-09-29PKF_SS2474259086UE.docdoc d6baf92252e2e3e673077f1cea8fc4bf0e240f4383dffc91c53d88857ba5fdf7Virustotal results 31.15%Heodo
2020-09-29BAL_KQ4121321493WC.docdoc ad21f91ac048eeb669e0a9cc8199225d755cf89a9f5d79d7fb39ef2659f04a9bn/aHeodo
2020-09-2901028572.docdoc f3156f2dd9bbd4c0f1164e92165433c3f689d7777297b5149c47299dfbb1d840n/aHeodo
2020-09-2946102198.docdoc a863d09af176344fa94c7820a54398bd505f2ee93f7f66a6f05d3e60b71479ecVirustotal results 27.42%Heodo
2020-09-29CEE_090120_EPD_093020.docdoc a7bac9b6662da2eb4c3fa6f12c10d790ab6b8ef1735241fcd2a4d35a152a8965Virustotal results 27.42%Heodo
2020-09-29BAL_EMM_090120_DQY_093020.docdoc 14e6ea40cc1e124fe353ed7aeb27490dad58d6a116bfddc62aacaa02921c5d88Virustotal results 30.65%Heodo
2020-09-29UKY_HS1539851362EM.docdoc 11100f29550f9f249ed0327bea61368816cd31217a92c786e124fe1a4ca8e50cVirustotal results 32.26%Heodo
2020-09-29Q_72928545.docdoc 5ec415733e64c05854cc229c0978d9da72b7615bb092d7cfab7f2b36059af466Virustotal results 32.26%Heodo
2020-09-29XO0328973942AA.docdoc 7536e91c00f2d6ce6bff6c4241db275e75c1696e91929da0f4005d58644f3459n/a Heodo
2020-09-29J_MT3300848547LK.docdoc e8bc44088ba55cb58a8611c777ab11528143331cfc47bbb9dfcb92342f70696bn/aHeodo
2020-09-29VH7599186950TQ.docdoc a1253f0c82192b38181f843a781405d76f3c2c50d1bf6e2c90957bca35a2495bn/aHeodo
2020-09-29E841NUQ24IXW58.docdoc 96a40b5f32936b441b2d31ab2aed9eaa0e098af44b2dfcf740d7be06dae087aeVirustotal results 32.79%Heodo