URLhaus Database

You are currently viewing the URLhaus database entry for https://leads.afrus.app/sys-cache/Document/8ozykvzu/3nrvisj8b4bs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:693329
URL: https://leads.afrus.app/sys-cache/Document/8ozykvzu/3nrvisj8b4bs/
URL Status:Offline
Host: leads.afrus.app
Date added:2020-10-14 16:28:04 UTC
Last online:2020-10-14 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 16:30:05 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 hours, 40 minutes Good (down since 2020-10-14 21:10:57 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-14BAL_IJN_100120_SYO_101420.docdoc b356139efe926c881eff89255d16d5e8a0364aed9b05d34c491d8515710b3e72Virustotal results 33.87%Heodo
2020-10-14DOC_MF1342429482VH.docdoc 826727003b2127dc81f56b340d152f0cf35bb9f85f96bc3c0505406af9724a55Virustotal results 27.87%Heodo
2020-10-14REP_JNILDCFR9.docdoc e7f5e90df9b0934c38d4d8953f7f209d8c4cf6baa312d7da7d9ff5280f3ce14aVirustotal results 30.65%Heodo
2020-10-14REP_61792717062493156536.docdoc aa08af368a5160b9286b65057e96e42aba63933c677ed3bc930d3357d7b40176Virustotal results 26.23%Heodo
2020-10-14BAL_N2HW7LJXL3.docdoc f031bdd1371fa17dff0a41ba682450de725ba3dc5cdf539c55d5049667b5d4a8Virustotal results 27.42%Heodo
2020-10-14DOC_PO_10142020EX.docdoc 11b6433cc50996eaa60f48be87ac8627f7ef22e82111415e743daee3d32b613aVirustotal results 29.03%Heodo
2020-10-14UC_PO_10142020EX.docdoc 7f12ac5050b001bf7409ea74f6b6dad0f8bd7d4fc74773887b8ed8e571d12ceaVirustotal results 27.87%Heodo
2020-10-14R_XLU_100120_UIS_101420.docdoc 846d77d538cd9695250cf045c49a916d429f3cda26c50d0d76aa91783ff96344Virustotal results 27.42%Heodo
2020-10-14FILE_69721878.docdoc 266b94aef7020a8f128002d83bca80c054900d06c066a2e4223fddbcdbc9e7feVirustotal results 26.98%Heodo
2020-10-14REP_PO_10142020EX.docdoc 13c25bb5b4e70dbbec90e1195bfe0e1b60b9c6ef0ebad49cceb11f9fe23d9f15n/aHeodo
2020-10-14REP_SQH_100120_XIG_101420.docdoc a0bf7cbc3aac6467993b5bc74487158da7247f41270aaa1ca617b69419089e6eVirustotal results 27.87%Heodo
2020-10-14Y_23095752.docdoc 64c0ea99d2684c1ff62d288fb69c1be09120aaf465edbe15b87f595450e5c012Virustotal results 27.42%Heodo