URLhaus Database

You are currently viewing the URLhaus database entry for http://teesvalleywashrooms.co.uk/ALFA_DATA/report/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:693665
URL: http://teesvalleywashrooms.co.uk/ALFA_DATA/report/
URL Status:Offline
Host: teesvalleywashrooms.co.uk
Date added:2020-10-14 17:56:04 UTC
Last online:2020-10-15 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 17:58:10 UTC to abuse{at}123-reg[dot]co[dot]uk)
Takedown time:14 hours, 53 minutes Good (down since 2020-10-15 08:51:26 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15FILE_VYN_100120_XDH_101520.docdoc e09558c501eba43c6277ae9a4437c35bde70855092d6ce522e882f2658be75d9Virustotal results 31.15%Heodo
2020-10-15UPZZ_PO_10152020EX.docdoc ddabc8380b111a6ab0351fdf1e43024580cf19bf58f90bb43c51755ca4058ca1Virustotal results 32.79%Heodo
2020-10-151V71XUI19M1V7KDV.docdoc 6dd48bb5636ef582e56dda06c2c3bf04defa7e64b1369dec7de673098b94efa4n/aHeodo
2020-10-15FILE_3883646142753002499.docdoc 0ff9d4c3cfd5a15918d7ed0e685e6b35da8c3c4fb272761910e8f3599bfb3647Virustotal results 38.33%Heodo
2020-10-15XRWZ_IQA_100120_KZP_101520.docdoc 8877bd46df4f972056ba63398a055c5fe92b53cf944fec3f5b7f58904c39ceffVirustotal results 30.65%Heodo
2020-10-152361318941802254180327195.docdoc 48caa70a3b31ff976df78f2b4525b27307a53e88d1ce4f1846dd5801dd2c9b76Virustotal results 33.87%Heodo
2020-10-15C_67194746.docdoc b36b1ab739c6689f92c3da6e9a8c93a009756069b982b64e74e4075e98badc70n/aHeodo
2020-10-15QB5FMTZNZK5.docdoc 599c5a96c48cab303ee9a8fedda331cf66f2db8f076733cf715d00c5c4278e20Virustotal results 29.03%Heodo
2020-10-15DOC_PO_10152020EX.docdoc 09b2a0a619eef827aca5df812a125f278c915c56afa75e6bcbd55e47265034bbVirustotal results 34.43%Heodo
2020-10-15REP_PKY_100120_BHV_101520.docdoc eb0efcd4366f3c4e3f529ff2b1e108a1fcb1e3ef0e7485cef709d9351d64b55fVirustotal results 40.32%Heodo
2020-10-159ZI6YIQO9CU9JM.docdoc 5fefd7066e7cb6344aa6f4ceb150de371e98cc1de2af7bfa2fa46cb4949ff0aeVirustotal results 31.15%Heodo
2020-10-1524637886.docdoc b716ead26e4edc1ca7925f26ba16cdbe932e9cff3fbb636630f3d7bad4ad487dVirustotal results 32.26%Heodo
2020-10-15FILE_NHJ_100120_ZYO_101520.docdoc 2cac6b6f1ed831e31b804e46839fb6e8e196a14ba3d75ba6c945d4b87dd18f04n/aHeodo
2020-10-15INV_QV8FJN1O.docdoc 97facc45c64f326ed17ae9ea249dab0f4d6bb4a237092a7996d8e4eaf43226c0Virustotal results 33.87%Heodo
2020-10-15FILE_PO_10152020EX.docdoc 100b400505d67803dd47e7093247e44637dade8df24255e8fd14b80a78f77533Virustotal results 34.43%Heodo
2020-10-153720922184445.docdoc 9b215a17a892b453c3f564442181f449693efbb1777c15f53e2238544500a92fVirustotal results 29.03%Heodo
2020-10-15TV_FI6436766475YV.docdoc 5e0d9e19ad9079d0325f377113e1975450b7c90b66051ea99f268153814d5687Virustotal results 32.26%Heodo
2020-10-15INV_5BZ6TBLJYPR.docdoc 2d22c090ca32c456c3d88c382392a124bf484fb67ef5737c1e9c6ed81b87e4fdVirustotal results 29.03%Heodo
2020-10-15UVZ_100120_XBI_101520.docdoc 1790c5fab1f40df300b33f400baa6f3981447142c4368a43e01a5b76b1beed3an/aHeodo
2020-10-15DOC_QJE_100120_XSG_101520.docdoc 0ce691ae2caab090785a0378e42e72fb8c1b6e129c8b3f50e32462295cf128e3Virustotal results 32.26%Heodo
2020-10-15S_80499073.docdoc f2749bfcb47ccd5ca2d9a1a0707ed06064ceb9ad0549c3bbff8475d01668d9b5Virustotal results 29.51%Heodo
2020-10-15REP_PO_10152020EX.docdoc fc6514ef333a9a7df16243a938d3a6e2c9fcf1410d492381598062d92b267346Virustotal results 33.87%Heodo
2020-10-15EOG_100120_TIS_101520.docdoc b1380f1fdf3f7636d79043feef8f62d1f57ec8694f3abddce522899895cf4dddVirustotal results 30.65%Heodo
2020-10-142ZETUAT.docdoc 285bac1c67ccd0ea184f852a4f063955511ea533a444fd1115733221099bb823Virustotal results 27.87%Heodo
2020-10-14Q96HW4C6SPV.docdoc 90e36d2990e1c86b71a77c96196d4fbe57e9e5d274d37bd085edf57d4058a55bVirustotal results 27.87%Heodo
2020-10-14BAL_12355532.docdoc 9bc913ba9ebf09d1b8c420ec7d5e7398f06e5ad3740000f0caaedbf73999bf9aVirustotal results 27.42%Heodo
2020-10-1437290703764210789.docdoc 89a7221256e253cd0904a91ca49c1c82118be9cdac76b21a6735eae4871ab400Virustotal results 27.42%Heodo
2020-10-14AS_92467297.docdoc 17de7a6f4665896c233d8dc13318c316bff4f9ee492c0d33e8e64a5d38a1b0f9n/aHeodo
2020-10-14BAL_CWT_100120_SKG_101520.docdoc 8b93392f1157f46ab9025aff15937ecc6c0d74ec1881502a048d919c9b203543Virustotal results 31.67%Heodo
2020-10-14UH8905810893IP.docdoc 89805057d1a481cf26a6efd0f74ed731cefd3ee7547ac6f529a6cce3223f6d07Virustotal results 27.42%Heodo
2020-10-14FILE_PO_10152020EX.docdoc 9140235214871fd0aa4167f88aafd261126784ecf7c266b1f5678c46dc9be18dVirustotal results 31.15%Heodo
2020-10-14ITG_100120_IEF_101420.docdoc 3f22f924db8066982fcf6f6b72ce5e37a76a15db8a9fd7e10e0123529da3c28fn/aHeodo
2020-10-141R7AXC73M.docdoc b356139efe926c881eff89255d16d5e8a0364aed9b05d34c491d8515710b3e72Virustotal results 33.87%Heodo
2020-10-14DOC_IBF3LVZI20JOJM.docdoc 1d53bace9c10c587db8501b65ec6a3216bda9cf2367d43b25949d9f4158ff9e7Virustotal results 30.65%Heodo
2020-10-142801275038259116089433601.docdoc dff04a292f708be6dc651f4164c2f711a836eeab00529793693a3f25518a0341Virustotal results 27.42%Heodo
2020-10-14N_612892253327752423581.docdoc 9cdefce35cdb78bfad530dc47d20a2497159cfaff4df8e163843ece18a16396cVirustotal results 29.03%Heodo
2020-10-14BAL_BBO0G7C3TE6JJBM.docdoc 11b6433cc50996eaa60f48be87ac8627f7ef22e82111415e743daee3d32b613aVirustotal results 29.03%Heodo
2020-10-14P_NYJ_100120_RHZ_101420.docdoc 1df6aef022d1cbf3066209efa10f084a0089988d6d488006d43ef433edf1cac3Virustotal results 29.03%Heodo
2020-10-14DOC_9Y65KMH68US5NS.docdoc 08544b0583237aefdb829f4bc623028d9242db49511ac36f7eac946b47533c6cVirustotal results 27.42%Heodo
2020-10-14LJ8403509774WH.docdoc 846d77d538cd9695250cf045c49a916d429f3cda26c50d0d76aa91783ff96344Virustotal results 27.42%Heodo