URLhaus Database

You are currently viewing the URLhaus database entry for https://profbuh.org/content/Scan/a9qa18tk0rge/8oraffr73/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698221
URL: https://profbuh.org/content/Scan/a9qa18tk0rge/8oraffr73/
URL Status:Offline
Host: profbuh.org
Date added:2020-10-15 17:43:07 UTC
Last online:2020-11-12 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 17:44:11 UTC to abuse{at}reg[dot]ru)
Takedown time:27 days, 18 hours, 54 minutes Bad (down since 2020-11-12 12:39:08 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17FILE_12335738963023.docdoc 360a5cb7eed923017b4ef07460e7652362cdf1fc0a902516addbb8e244e30134Virustotal results 53.23%Heodo
2020-10-17FILE_13108084.docdoc bd5e318573106192eca830985c93ad07583928c7ba9b1f752ee5ce3e38eea593Virustotal results 53.23%Heodo
2020-10-17FILE_PO_10172020EX.docdoc b0f945ed6afda303421f9501b2b2d1d2996a132eb27486911019cb9996538460Virustotal results 54.10%Heodo
2020-10-17INV_ATX_100120_VYD_101720.docdoc c5b951c65f67f1136dedc670dfa0cf0fe59abb9172a0fe5a6011e2882e129e8aVirustotal results 54.10%Heodo
2020-10-17INV_BHL_100120_NPO_101720.docdoc 169fa4037e8c45a38a3b2e862d860e955fc810c63682c78155bbbd45820b83bfVirustotal results 54.84%Heodo
2020-10-17REP_PO_10172020EX.docdoc ab13f6f95154d0396465d9bb9d42e49708e2efdd49c259b7189ae2c7c7c2d389Virustotal results 53.23%Heodo
2020-10-17DOC_93860482418075224.docdoc 8eed16b7e0a64351cb06ea437eeae8f69b227cac04237187ed17cff470a3cb0dVirustotal results 52.46%Heodo
2020-10-17INV_RAB_100120_XMG_101720.docdoc fdcbcd4f6d22900775055fa03ab8643f72041e73d6af1c271a672ce65268e0ddVirustotal results 53.23%Heodo
2020-10-17FILE_57972269144412553400096.docdoc ff9996026d66c80170010bab3d84d0ba1ecac3a6b87f8e694008feb0bc0b3d4fVirustotal results 53.23%Heodo
2020-10-17INV_77603715.docdoc ea065a0dbc3ca645237d0c98e82887ca636451f3fa822c6c0a087a2fe98c230fn/aHeodo
2020-10-17RD6969447953WJ.docdoc c0f957552ea0bfa9ec43b903ee17f870d19d10026a6e967b5ba434e26758232fVirustotal results 53.23%Heodo
2020-10-17PO_10172020EX.docdoc 7f7aaae8116f26c7d91c5c3d87ab7c7a752e628195c25563cc7c3074669e6c7aVirustotal results 54.84%Heodo
2020-10-17BAL_PO_10172020EX.docdoc 6d5ed047cba0f40a2bd108fdb285520a5590c29ac64b7a9d32a20719905f1e7cVirustotal results 53.23%Heodo
2020-10-174847956623651351297383269.docdoc ca5d768289c225dea34f82176591548fc03963cf653f0a8ea0b6e0f9f71ca3aaVirustotal results 54.84%Heodo
2020-10-17INV_50599139288.docdoc 4f1b55b5cbbaa28b0d87b93dd256cebd16df18a51e081378940ad152fd24da8eVirustotal results 54.84%Heodo
2020-10-17SGSWJRX7N2DEKZ4H.docdoc 7563b098e425087d70e59bc0ad1d712d39ec6286fc63eaa9a9eea68f9a7ede26Virustotal results 51.61%Heodo
2020-10-17FILE_PO_10172020EX.docdoc 905c7ae4c62237c4d5783b52652b9eef6be72076862c6f6aaa440f8e7ce23a8cVirustotal results 53.33%Heodo
2020-10-17MAY_08034602096806.docdoc 3cf860a4fc48852cfc15307168a655fe09d970de805123a370c888f18b949aaaVirustotal results 51.61%Heodo
2020-10-17BAL_PO_10172020EX.docdoc 61cf4ff84de3e35dd24e8df00464aa832912b8c378cbffc5da91abc576c809fdVirustotal results 51.61%Heodo
2020-10-17BAL_PZC_100120_ZKZ_101720.docdoc bb96b8f7ca8418e8d16ada7ed78c33abe3bd24d7ca843033cc73e73e4c606fdaVirustotal results 51.61%Heodo
2020-10-17PO_10172020EX.docdoc cad389f338446345616f9a4f005b47f186be55fdd914d1b88f42bc4f26220685Virustotal results 50.82%Heodo
2020-10-17WN5691039788UO.docdoc a106e1da9cf3b1b5b2f7211307b55422cf772fb176003bd02070def6d3b1c13en/aHeodo
2020-10-17XGG_100120_NGT_101720.docdoc af4011781c0a2add45a6f72b8d52e5bd7d7381ff28c93e478dede0ff100ff237Virustotal results 50.82%Heodo
2020-10-17WZ2016650138XW.docdoc 99acccb026919eac0d3249c8a9207a71d032fbe59c7540c12aee398ae86e6780Virustotal results 50.00%Heodo
2020-10-17FILE_QDG_100120_LZI_101720.docdoc 1f9fcb8ad3585c6cbf7250308fc58ebd7fd913baf350cbd3d7fd8934c9e33e43Virustotal results 50.00%Heodo
2020-10-16Y_5E1KG0H.docdoc c25321d27755dd74dfcb51c16c96a607d16b09b59b1cbe7f025dc89763d9d630Virustotal results 50.00%Heodo
2020-10-16DOC_88882835.docdoc 2d4a3ae690cd64017a114de08ffb095c8208ca65f5647809600f6caf8ff7cd97Virustotal results 50.00%Heodo
2020-10-16INV_43339013.docdoc 34470931a684a070f70a0ed741a36c388fb0c082426aebf15aeedbc28a4d778bVirustotal results 51.61%Heodo
2020-10-16GY_DRF_100120_IWX_101720.docdoc 6539d2ac4a847b3444866e22b642a335e3d8b92d40031a090fa315aef1af2930Virustotal results 51.61%Heodo
2020-10-16INV_SOS_100120_RLS_101720.docdoc dae05fe983f37d53c614de68c40f3da714bccb7dd377adecaf6a7592c31cdc4bVirustotal results 51.61%Heodo
2020-10-16FILE_ZXXDPF3TV8LX0.docdoc c3cd8ffeaef0490d7d34177eb5e08082a1bd326f49c324248578a4b45f3fd0f2Virustotal results 51.61%Heodo
2020-10-16DOC_84531902.docdoc 8e4239eda8a4993212d0de12a0e6fb748c995f1a89e8fab3417a0140b9f650d8Virustotal results 51.67%Heodo
2020-10-16PO_10172020EX.docdoc 9c44a164c70d7fdbd796c9805e3ce506cf8fd1d8df4d84e27384d794e3c075b1n/aHeodo
2020-10-16BAL_079921973357680364581709.docdoc 21f2a9296db63e8671bce4862c485e7ebf0a1a4bfac598720516c4e81d951f97n/aHeodo
2020-10-1608349GCES4AIM.docdoc ba25bd51dddd6e6b5f359d2e79ac6cafab5ec98ac623f412764253be9e449833Virustotal results 50.00%Heodo
2020-10-16INV_RWX_100120_EHI_101620.docdoc f516029eb5a63ec663aa57bcf41d0ba93e98574976381c581b952aa1631de8dcVirustotal results 50.82%Heodo
2020-10-16290694387203659945354325.docdoc c35986ebc1fadec0bc076c81466e8e87dd82058ca783e03545036dcf9a5d7a46Virustotal results 50.82%Heodo
2020-10-16JH9023433692EV.docdoc b790075cf1b5ae9592d7b61d5513b6b4ae15e0df4e08226b9152f878e0ef49b3Virustotal results 45.90%Heodo
2020-10-16BAL_PO_10162020EX.docdoc 69723a53775c6a9e152a508cdfa347a0e07201d2efca1c2c0ac1112748a9fcd6Virustotal results 48.39%Heodo
2020-10-16REP_TGZ_100120_ZWP_101620.docdoc 89157919f283aad6306a78ae43e54b55c2431a0a64dbfcef22df553bf09ae681Virustotal results 49.18%Heodo
2020-10-16REP_8839411348.docdoc ee640ad9d020dedce3c3a18efe2a6a9a14ed4cf50ffa64ba27090765dfb3cc6bVirustotal results 47.54%Heodo
2020-10-16INV_66142598746081010.docdoc 055c0768feaa5f21bc4c430d586190b390dfcb0f18a8c908bf9dc4fa01bc99d0Virustotal results 45.00%Heodo
2020-10-16DOC_YW1179516869GA.docdoc ef0e715e1da6a1717d119a57d6ec4f961a3a700f9a807b1072fae419151807d8Virustotal results 43.55%Heodo
2020-10-16J_45650557.docdoc e33080e4baec5f692b6a9902fbf0661cef6fd33fdc1ace3cd95e64fe9c70118eVirustotal results 45.16%Heodo
2020-10-16INV_JYI_100120_SUN_101620.docdoc 4d92f4549c627c844dc6c2212d8028b73f0c3d07b19296f0a297ed9577b979aan/aHeodo
2020-10-16XMX_SQJ_100120_NYJ_101620.docdoc b285a4eb97b84d68240929ecbe902577a607c7e7b0abe299ef3ff2a6fa3e9eb7Virustotal results 33.87%Heodo
2020-10-16V_CNO_100120_IHS_101620.docdoc fd965285c7763ba89396757d0d3a21d013c1f0ec33856514ca688534587f0726Virustotal results 33.33%Heodo
2020-10-16GV_27597184.docdoc 5f94a90f54d5c04a4ba33f0d4884392c5411775d63d2293793f9e0d348bfc88dVirustotal results 41.67%Heodo
2020-10-16BAL_PO_10162020EX.docdoc 416c28eeaa4f2ecdcea4ff0f31cb81a99f7a9f6ff65c9e96afec641dd8a84a12n/aHeodo
2020-10-16INV_0OY6QRNBLSO31D.docdoc 35eec9fbd979405c3055add3801985dc21b0762af182d38297ad8f87db7874e4Virustotal results 38.98%Heodo
2020-10-16DOC_95944339.docdoc ebd9a7a7b9549c9d6181a8972c532d559d5495d9a7decad112cb1d13c8a6e664Virustotal results 30.65%Heodo
2020-10-16REP_2SPOWWOCD80PY.docdoc b9238cf8ae3c30c1b4bc0cbdd43c8309daa334d456a5dfca04b233b03a8a0221Virustotal results 33.90%Heodo
2020-10-16BAL_PO_10162020EX.docdoc 01f98b1a31eaf93128b65347f3fc0e25b853d2535e9d828263002b80f0e445a0Virustotal results 31.15%Heodo
2020-10-16YMC_YDFZSZ8.docdoc 331449b7cf090472612be3eaaf098869cd351983a12f809e5b6dc3860d35c556Virustotal results 30.65%Heodo
2020-10-16J_SKPX1VIKSLOOGM7R.docdoc c9146e559eeaafb38494a657eb583b6833b2c35dd60eafe2140ee8bc22150c96Virustotal results 31.03%Heodo
2020-10-1607152821.docdoc 1b2652ca4216be8936873953880078a3db413557d80496831b1891f5947f4eebVirustotal results 33.33%Heodo
2020-10-16BAL_QHN_100120_DCZ_101620.docdoc aa3af1b21af839268143b000b0e8f4a431079b94f69c8025f31315e8ceac2b47n/aHeodo
2020-10-1676772833304485424320475.docdoc a74b230d5a83dd721b98493e0a752cd0f9d6739bc4ff6f0046b798fa98513fbaVirustotal results 32.79%Heodo
2020-10-16WZB_100120_YLM_101620.docdoc 44b5ac3a1688e978f2ab497cb9a2b77b9a4a27edb617212e27b63035becfb148Virustotal results 50.00%Heodo
2020-10-1633368557.docdoc 92d36d8404107035e4524734547170d1517c9ffff23480556c718f4c7c89d3d1Virustotal results 50.00%Heodo
2020-10-16BAL_PO_10162020EX.docdoc 147b9616588be0def766828cbdc415348543d772fbf13e9a7fbe0b37b0ebf3fdVirustotal results 50.00%Heodo
2020-10-16FILE_40065999.docdoc 095fe16690d338ae33d6608dbe94adf60f398907737417666034e7a5b64eded8Virustotal results 50.00%Heodo
2020-10-16INV_9XRFWUB.docdoc 862a3557cbd080c1e4b737d044d2a849ffc1fda3cd46e474ff947ff583357464Virustotal results 50.00%Heodo
2020-10-16REP_PO_10162020EX.docdoc 7e1333c6529018473221519532ee51d04523ad9354f66d62ea599d4bcb9b4a8an/aHeodo
2020-10-16REP_PO_10162020EX.docdoc 6bd70c37738737b137dddf5e137cff39eb5baeca80217787c95d5ce885c5854aVirustotal results 47.54%Heodo
2020-10-16BAL_18032858.docdoc 2955467d39aee8efaa08f284298b86e105ff6b8855c674bb41e38ca21d2c6bfeVirustotal results 46.77%Heodo
2020-10-16REP_PO_10162020EX.docdoc 598b4cf3fc5b97854ae8b54625407b4e6b7f05d8ad96b446baaf0855b754074cVirustotal results 46.77%Heodo
2020-10-1648718036.docdoc 2ea42eea9abe81ee4415154eabd2fc00bb951b3a234e1b3ef9e824d77ee97732Virustotal results 51.61%Heodo
2020-10-16Z4GEZBCPUZ3T59A3.docdoc 29d8f14d9aad7f7303bfffcff57109e4a24983050638c356af826bf4febc04a2Virustotal results 46.77%Heodo
2020-10-16REP_3LI8VPE1E4XZSW4Q.docdoc 28a6bdd824538dcbdc61dc5ffe9d61ccf016e4a4bb027becec2d522503ec8b0aVirustotal results 46.77%Heodo
2020-10-16REP_PO_10162020EX.docdoc 3a3dd7687c72a79fe44ec05be24ef77e62e6b1cdcf3f202251d6c12e94475dcdVirustotal results 48.39%Heodo
2020-10-16INV_PO_10162020EX.docdoc a44bec73fa5d84c99c152a133907faff21cecbabd17faba199a628c8259be229Virustotal results 48.39%Heodo
2020-10-15INV_17809238.docdoc f3aecd021c57be4a051eb58488f96cd6183ea34153cf79876db7f699d5ce1032Virustotal results 48.21%Heodo
2020-10-15REP_IDJ_100120_BKS_101620.docdoc 5781607bc4d3aa2d65dc523aab5dfea022ffae444327c4463969d7e461822367Virustotal results 50.00%Heodo
2020-10-156781188250.docdoc d9dee0ffa4b0f9f8ae5c312de758420aef5fa12d4489a8c5f3e5ee627ea966dan/aHeodo
2020-10-15REP_PC4957051108MP.docdoc 197ff18c407c279e436240984c946009e24dc90b17cb986b9bf9554278a8a699Virustotal results 46.67%Heodo
2020-10-15DY6787180115ZX.docdoc 9e6ccb86ca25351f22a9960687787487cd93476f21e943368886f63c03167222Virustotal results 47.54%Heodo
2020-10-15XC_YB1853460233TO.docdoc 966af50d9ffd82cdc2a4fa693620dfe90172ef15047cc10d3b35fcd47ae47c4fVirustotal results 46.77%Heodo
2020-10-15069896448990284838.docdoc b9bb517022d0b2c98532d6239bd55d7a33911467a4ca1d6c8d69736530a6157aVirustotal results 46.77%Heodo
2020-10-15REP_7461036733462896205.docdoc 52cc4044252ebba622acceb8374c67dac01416c08fc26a5a1e366be2d6a475aen/aHeodo
2020-10-15FILE_DLL_100120_LIK_101520.docdoc 63409e6742b521d02cfb6f833ee7484c6db70237e48675a06c28cc7c9920bfe5Virustotal results 46.77%Heodo
2020-10-15I_85626608.docdoc 70652370e67cef224785a44a3bb57d19f00a8b000714cf7117ed9dec27b3c920Virustotal results 45.16%Heodo
2020-10-15WNG_FGL_100120_NHS_101520.docdoc df301a07bada1a07adbe33c638f8c00159a565bafec1b7fc1ff5ff69b6a7946cVirustotal results 44.26%Heodo
2020-10-15PO_10152020EX.docdoc 39c25de18abaccdff5bdbe5fb490b60e00e8b38d1c30556115d11f468d4b6a76Virustotal results 45.16%Heodo
2020-10-15VE_PO_10152020EX.docdoc dd30e8495694397703816d63ba5a77f3eac6a41216b2d2d536d627d85f015c87Virustotal results 44.26%Heodo
2020-10-15DOC_LO5VBIDPPGMUB5.docdoc 876665583f24289019346c75249cb2a878ee97166a2994f3be6dd27b7c0f3155n/aHeodo