URLhaus Database

You are currently viewing the URLhaus database entry for https://librosporfavor.com/wp-content/swift/uid5bmt/547jbnw6kkyl6m2f/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:695231
URL: https://librosporfavor.com/wp-content/swift/uid5bmt/547jbnw6kkyl6m2f/
URL Status:Offline
Host: librosporfavor.com
Date added:2020-10-15 01:14:03 UTC
Last online:2020-10-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 01:16:16 UTC to abuse{at}amazonaws[dot]com)
Takedown time:4 days, 8 hours, 58 minutes Bad (down since 2020-10-19 10:14:54 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16DOC_965413502.docdoc 5c6f2d9a882fc281752198cd5c713aab468bafe4a0ed461ed70556a8dd12b900Virustotal results 44.26%Heodo
2020-10-16BAL_AN3455027471IR.docdoc a2864ec0d73578ac81e51cec11d7ebaf531bd59f579c05e796110a99e0d20e88Virustotal results 43.55%Heodo
2020-10-16FILE_Q12R67WXG5XNIJJ.docdoc 9c709e26cab4a752ef535629ca0789fa9454436ac24b8d5577c2cb420c60b20bVirustotal results 41.94%Heodo
2020-10-16REP_65338332.docdoc b285a4eb97b84d68240929ecbe902577a607c7e7b0abe299ef3ff2a6fa3e9eb7Virustotal results 33.87%Heodo
2020-10-16BAL_PSY_100120_TDZ_101620.docdoc 603619e4d81dda77197d6ff40406a6f101a494901653c22f181ecb7be55111d6Virustotal results 42.62%Heodo
2020-10-16FILE_PO_10162020EX.docdoc 50582c9e06f7726c40ab166de684e95a6f0de3f3fe6a0d8a749e6b18a5047f23Virustotal results 42.62%Heodo
2020-10-16PO_10162020EX.docdoc de1e044b0692b4790189c84a6a3bff006ea424fc6ab7a94f3063c76dcf38b463Virustotal results 37.10%Heodo
2020-10-16BAL_PO_10162020EX.docdoc dcdafcf9ad3d06aef3a381823d42a40d517e4151a657d52a07b7f64f2cec9dddVirustotal results 37.70%Heodo
2020-10-16BAL_VXB6X8C.docdoc ebd9a7a7b9549c9d6181a8972c532d559d5495d9a7decad112cb1d13c8a6e664Virustotal results 30.65%Heodo
2020-10-16REP_ZIP_100120_VFQ_101620.docdoc cd26ab187d5f4f2fb4fcb48799e6fa9d43fbe49c83a2e0b719ca6547134ad108Virustotal results 35.85%Heodo
2020-10-16INV_OG6777949805KB.docdoc 331449b7cf090472612be3eaaf098869cd351983a12f809e5b6dc3860d35c556Virustotal results 30.65%Heodo
2020-10-16REP_63862367.docdoc 650e5649d3b4dd927f8b6390e3ef98587b4c2e6769d5d2f5e459cb7f4872f363Virustotal results 31.15%Heodo
2020-10-16Y_NI8098507476RV.docdoc e1657e2b9da4fc39004ca0c0c681b59985f94ca16d04c3f363122de4bb444099Virustotal results 32.79%Heodo
2020-10-16FILE_SEC_100120_WDW_101620.docdoc 8e9462c9a3766b0a41a21d609caf5c36fd65d502b5e17bde7bb2a99628d16bd6Virustotal results 32.26%Heodo
2020-10-1622559827.docdoc c4e5490b2508ceaa3f196549d3c7d2865225ebbd56af97bc4a753542204c6641Virustotal results 32.26%Heodo
2020-10-16DOC_PO_10162020EX.docdoc 59353c49c62f983f096262d073e811f1b5b3f843352fc3cc78ff2a20e7aee458Virustotal results 55.74%Heodo
2020-10-16W_909379362519154.docdoc d22ae8bce1c58f49acf052afd9fc15bcb9f31f7849b5cc3812ac610c97b3d984Virustotal results 50.00%Heodo
2020-10-16J_91653486002275.docdoc 92d36d8404107035e4524734547170d1517c9ffff23480556c718f4c7c89d3d1Virustotal results 50.00%Heodo
2020-10-16FILE_587413445.docdoc 72b44b8e255ace9d74a54f19671fdcfa1b296bb221e038ab578044b55b309afcVirustotal results 51.61%Heodo
2020-10-16BAL_PO_10162020EX.docdoc 095fe16690d338ae33d6608dbe94adf60f398907737417666034e7a5b64eded8Virustotal results 50.00%Heodo
2020-10-16INV_8BP28I7CDX5VU.docdoc e50a486c4f791974fd105266ca6b3a7105238ef18dc5e96fb44a1d1e6d2bbc6bVirustotal results 50.00%Heodo
2020-10-16PO_10162020EX.docdoc 7e1333c6529018473221519532ee51d04523ad9354f66d62ea599d4bcb9b4a8an/aHeodo
2020-10-16BAL_59768376.docdoc 6bd70c37738737b137dddf5e137cff39eb5baeca80217787c95d5ce885c5854aVirustotal results 47.54%Heodo
2020-10-16Q_OEF_100120_RVR_101620.docdoc 98d7c4d63fcd23e0417a08c9645e5bb0729a1fe136941495b001db7126726608Virustotal results 46.77%Heodo
2020-10-16638595476796.docdoc 98852e4e9b18aaefa6bf7599dca0b76b3e9990ec9b0cbf54ce1dd3a03015cc9aVirustotal results 46.77%Heodo
2020-10-16DOC_PO_10162020EX.docdoc 9ff3fa5bcfc5a9b21abf19a4f8f3c406f0874fd93f8508c58e42529f672a6d23Virustotal results 48.39%Heodo
2020-10-16DOC_OBZ_100120_LQX_101620.docdoc 2ea42eea9abe81ee4415154eabd2fc00bb951b3a234e1b3ef9e824d77ee97732Virustotal results 46.77%Heodo
2020-10-16DOC_87508295.docdoc a0af2c0d46bfa10fc4589560d7055a18babee6615726fb2893b817e111f9ecbfVirustotal results 46.77%Heodo
2020-10-16147562890473456380220.docdoc 28a6bdd824538dcbdc61dc5ffe9d61ccf016e4a4bb027becec2d522503ec8b0aVirustotal results 46.77%Heodo
2020-10-16REP_RZJDZWC3YZSW.docdoc 63409e6742b521d02cfb6f833ee7484c6db70237e48675a06c28cc7c9920bfe5Virustotal results 50.00%Heodo
2020-10-15FILE_13573466.docdoc 70652370e67cef224785a44a3bb57d19f00a8b000714cf7117ed9dec27b3c920Virustotal results 50.00%Heodo
2020-10-150XZ3O9UBB36ZLMA3.docdoc 00534d43b370927552e8c71deae866472d34d67e1af2d02b93067c8b2fbc279fVirustotal results 50.82%Heodo
2020-10-15REP_50112260.docdoc dd30e8495694397703816d63ba5a77f3eac6a41216b2d2d536d627d85f015c87Virustotal results 48.39%Heodo
2020-10-152764035026013394289.docdoc c1a5fabe5d3cfa0cfe41476eed0e59b226db234ae57ea097b50adac70d5d9f98Virustotal results 46.77%Heodo
2020-10-159022688297637220869.docdoc d9dee0ffa4b0f9f8ae5c312de758420aef5fa12d4489a8c5f3e5ee627ea966daVirustotal results 46.77%Heodo
2020-10-158361230351830254072130.docdoc 197ff18c407c279e436240984c946009e24dc90b17cb986b9bf9554278a8a699Virustotal results 46.67%Heodo
2020-10-150092690774123409465831.docdoc c9570917c32ecb1c6b6e8ffa9a486d3aebc0d0dca67ae6021b1c5a39f22e69baVirustotal results 46.77%Heodo
2020-10-15REP_CDT_100120_JPG_101520.docdoc 966af50d9ffd82cdc2a4fa693620dfe90172ef15047cc10d3b35fcd47ae47c4fVirustotal results 46.77%Heodo
2020-10-15CCZ_100120_KUI_101520.docdoc b9bb517022d0b2c98532d6239bd55d7a33911467a4ca1d6c8d69736530a6157aVirustotal results 46.77%Heodo
2020-10-1527369473.docdoc f0abef25579afd4a06a70b4a55ce9b492df87c17b66b1949f541f679f6376b84Virustotal results 46.77%Heodo
2020-10-15OT7056373160IW.docdoc 3a3dd7687c72a79fe44ec05be24ef77e62e6b1cdcf3f202251d6c12e94475dcdVirustotal results 46.77%Heodo
2020-10-15LIEG69CS3U839I.docdoc 35063a36e2a9b2ea2f0a17e4f4c22a81de62a240888fbb22195984501125bc34Virustotal results 46.77%Heodo
2020-10-15ZYQ_100120_GCG_101520.docdoc 4175a2dd2295146108a2fb6d370f0d24239715d3709a82c0c6ec420a962efe90Virustotal results 47.54%Heodo
2020-10-15YQ2099844065YZ.docdoc df301a07bada1a07adbe33c638f8c00159a565bafec1b7fc1ff5ff69b6a7946cVirustotal results 44.26%Heodo
2020-10-1598035710.docdoc ab321ed0f56034ac636d328802440c291af5a379fee4ff6b31fbc859ab2d9004Virustotal results 43.33%Heodo
2020-10-15FILE_GBH_100120_IUK_101520.docdoc 0ab272f979fa9aed2035beb2f578c7dd1b689f64452457def9e7aca2d1c91a3an/aHeodo
2020-10-15WPFDV3WD3XNLJZ.docdoc 029477ff072e2c86a782ab3de0f2b82813f14cdea1173cbbcee131b9de7d5852Virustotal results 41.94%Heodo
2020-10-15FILE_UPZ_100120_JSM_101520.docdoc 30b3400f4a69274881ac358ceaed2b0e632dfe513ad2c374e97bc00fc214ad10n/aHeodo
2020-10-15XFI_100120_NFE_101520.docdoc 3f6955a4c8030234f81c5371a9fe055356a777586aec5021a269eb74083d6ce6Virustotal results 40.98%Heodo
2020-10-15K_2049971340435147.docdoc 5054c0740abc74c3d953105c380fd564a4a6ed4ee869aea2d48102b7f9feb1a1Virustotal results 41.94%Heodo
2020-10-1508385237.docdoc dbd52eeae1181eeddab6c7e1fc6a63564fdf6c6ab43a2ce880a8f1af89531022Virustotal results 41.94%Heodo
2020-10-15BAL_PO_10152020EX.docdoc e43f64b313b4f2b70ddbc78e0a0f8d03dc8104b0b4bf9129264587e767c5801cVirustotal results 40.32%Heodo
2020-10-15REP_KRUL5A7U6URK479.docdoc 08851f66b1ce9b451ab8c733fac74cc0211779a930b66f34242e2cbd6350db9eVirustotal results 38.71% Heodo
2020-10-15INV_LE5442221488AL.docdoc 108c2c7c6598b9ff017de74522cabbaee096e3a62cc018573c6ce7c759a7dceaVirustotal results 40.32%Heodo
2020-10-15INV_95780679.docdoc 4a2bf492143ee9960aef01fd04d9ebdfef630921079f5511167e5684f65fba5dVirustotal results 38.78%Heodo
2020-10-15Z_GLT_100120_BSP_101520.docdoc 44ee7d7e1ae4f8f1c2fa934e570db9d654c85b5534d842e0c2f0f509bd890eb3n/aHeodo
2020-10-15INV_PO_10152020EX.docdoc 7697faf6a3ac06e7f465152759a63f92d67946fef445bd4c26c487b579ff857dVirustotal results 39.34%Heodo
2020-10-15D_PO_10152020EX.docdoc d78facd499d94ec13b381733eee00bd566ddd24ee98d4a1a7316fcaaa126e043Virustotal results 38.71%Heodo
2020-10-155606431737.docdoc 832d456b57cda198dd3a21201f33c236a82d272d4780ba484a97e544f7ef998an/aHeodo
2020-10-15PO_10152020EX.docdoc 63a12d5fc1be102cc43155a0bddbaa57e075b647224c268cde1d288d6db2a4ccVirustotal results 39.34%Heodo
2020-10-15INV_QDP_100120_WSZ_101520.docdoc 8a18bd4ad8eba8310bcd422c1ba2612b6ad2adbcbdf5fb76408f85fbf496b5ben/aHeodo
2020-10-15INV_PO_10152020EX.docdoc d30ec2dde96e92164e6be1b42ad79b2b25464da4be6140e0965cb115a5d9e8ddVirustotal results 32.26%Heodo
2020-10-15DOC_GNC_100120_FCW_101520.docdoc 19374cad4526845510b04c4f99d32873a3ca0e5da21abd1bc6aeafdda7473529Virustotal results 32.26%Heodo
2020-10-15KOZ_100120_HVC_101520.docdoc 36214ebd8002b76ea05ec1f314ba5d01bd52986535be9a5a91395a0460389791Virustotal results 32.79% Heodo
2020-10-15REP_30680227546525.docdoc 149107eec47eec15d6160353b5102a17c8b552474e89828511de257fd78d3a52n/aHeodo
2020-10-15BAL_WYC_100120_NSP_101520.docdoc a8a34a6c37f7c220879f3022dee62f83c2f21e3285d534f65111131d363ac379n/aHeodo
2020-10-15INV_PO_10152020EX.docdoc 74162fa1b634bfdde5cbbc8882362c3d5083368cbea1e88ab8c413863cab2ac3Virustotal results 32.26%Heodo
2020-10-15INV_QYF_100120_TXX_101520.docdoc 6dd48bb5636ef582e56dda06c2c3bf04defa7e64b1369dec7de673098b94efa4Virustotal results 32.26%Heodo
2020-10-15MDZ_100120_ZTU_101520.docdoc 2a3d73d8e391636548a28421a0cceeaa7fab08cb60380bf090a57a1af35b96fbVirustotal results 37.70%Heodo
2020-10-15MHI_100120_NKD_101520.docdoc 1cc454d75dc586cd5025eab16ed2a8097e3d412f9efb96ddd568041631aa0ebcVirustotal results 45.00% Heodo
2020-10-15F_FK2724894326MC.docdoc 48caa70a3b31ff976df78f2b4525b27307a53e88d1ce4f1846dd5801dd2c9b76n/aHeodo
2020-10-15FILE_1401352761.docdoc 63d8b2866cf26b1f4411b45557b36780023b3768efe30a63d1e00400158856dfn/aHeodo
2020-10-15BAL_PO_10152020EX.docdoc 09b2a0a619eef827aca5df812a125f278c915c56afa75e6bcbd55e47265034bbn/aHeodo
2020-10-15INV_478671890671.docdoc d2d28ce9e628712a8478ea1439e111036497efe3d10a12bba622baf2952ded06Virustotal results 35.48%Heodo
2020-10-15QFBP_HO5845426358KC.docdoc 7527e19a60407075d5ecb0a0f304aa0608f6deb102d4f9dbc42f65e03e985426Virustotal results 31.15%Heodo
2020-10-15NBHTMWZCD5Y4F8ON.docdoc b716ead26e4edc1ca7925f26ba16cdbe932e9cff3fbb636630f3d7bad4ad487dVirustotal results 32.26%Heodo
2020-10-15G_5SVBEQ2BIRBRQE3.docdoc 03afbf9b046ee6d340253662dfb45f59e4fb6e75b28dd8bf52bb8becb58145b0Virustotal results 33.87%Heodo
2020-10-15DOC_GUV_100120_NVQ_101520.docdoc 0acbd96443e33ed3c7bb5928e381f4440eb99308be50ab1a869a7bc118e57076Virustotal results 32.79%Heodo
2020-10-15DOC_PO_10152020EX.docdoc a62460b5048b49481c6096c23dc3b6f0f0fa84b37b632c80b6395400314ebc7dVirustotal results 30.65%Heodo
2020-10-15FILE_9828579008.docdoc a81218fa6f93ea8937a48dd0a2f9e44226d1cc1d0c14f973d4c4b2d8199aaa8dn/aHeodo
2020-10-15A_41483683.docdoc fd12780ca0e4c591da35bf3d215c22a47050b1a68e524ce4d0434ee2414cbf3aVirustotal results 31.15%Heodo
2020-10-15FILE_AZ7207672917RF.docdoc 14cc0eaf88072cd7dc29c10554024abceb5d548710ad957dcece3133a3a37dc7Virustotal results 33.87%Heodo