URLhaus Database

You are currently viewing the URLhaus database entry for https://caucasusmountaintours.com/wp-content/OCT/sh4yjba/abwa7l/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698525
URL: https://caucasusmountaintours.com/wp-content/OCT/sh4yjba/abwa7l/
URL Status:Offline
Host: caucasusmountaintours.com
Date added:2020-10-15 20:45:05 UTC
Last online:2020-10-16 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 20:46:05 UTC to abuse{at}hostnet[dot]nl)
Takedown time:9 hours, 40 minutes Good (down since 2020-10-16 06:26:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16BAL_NJECF5WT1Y.docdoc 8c5946d83496491e60468ec85aa90964c00945bcbd8e72e8b05b9f230d85f7f4n/aHeodo
2020-10-16DYU_100120_ONU_101620.docdoc 147b9616588be0def766828cbdc415348543d772fbf13e9a7fbe0b37b0ebf3fdn/aHeodo
2020-10-16INV_PO_10162020EX.docdoc 551880e02b296af7914d070f4040b2ff350b298b8c64b1f7abb096514add304an/aHeodo
2020-10-16YE1125139529LH.docdoc e7c9e9fc1b9ce622bde709c5498c23114ea5f1716b9c3acf0091fd7a01960777n/aHeodo
2020-10-16REP_39786199.docdoc 18a1cbac953dff9b006371606aa8ba5ebd1794c14f128e5f46d46629e60383c9Virustotal results 50.00%Heodo
2020-10-16INV_AYO_100120_FUF_101620.docdoc dba29a78e7fca48b133d315c553587d7ba8ed5185ea92e7630d507c84e74ea41Virustotal results 47.54%Heodo
2020-10-16HTN_100120_NBZ_101620.docdoc 2ea42eea9abe81ee4415154eabd2fc00bb951b3a234e1b3ef9e824d77ee97732Virustotal results 46.77%Heodo
2020-10-16INV_GM2793634262AK.docdoc 2fc8f20d9cf100c7de1244d5ccb17f14230e534ff24921e0cb537ebce7668908Virustotal results 48.33%Heodo
2020-10-16OYCOGF5MW1LWIX8W.docdoc 52cc4044252ebba622acceb8374c67dac01416c08fc26a5a1e366be2d6a475aeVirustotal results 46.77%Heodo
2020-10-16Q08C76ET4AAUUCY.docdoc d3c37e88878ac9801e592c464b9f3e15b30ef3096684d4efb9ca6cc6dd042734Virustotal results 48.39%Heodo
2020-10-1614991100.docdoc a44bec73fa5d84c99c152a133907faff21cecbabd17faba199a628c8259be229Virustotal results 48.39%Heodo
2020-10-15JLMQ8KDFQ.docdoc 928793e8f0d35a4a78f1935358fffc9f25ccf0b8f0d4cf8ad4a9e7a1508f22b2Virustotal results 50.00%Heodo
2020-10-15HY5107711960CC.docdoc 2889aa2818bb6b697ece0258b29a039f5f46f85444792ecad4d3667806bb5610Virustotal results 50.00%Heodo
2020-10-15FILE_47586318.docdoc 590e91cfd2bc7164b8528b3e845e9d45e8328e9148b90c0836936e9d870ca895Virustotal results 50.00%Heodo
2020-10-15BAL_03905936550927675614804.docdoc 0ab272f979fa9aed2035beb2f578c7dd1b689f64452457def9e7aca2d1c91a3aVirustotal results 48.39%Heodo
2020-10-15REP_YJDJ33L9GAQFSR.docdoc d9dee0ffa4b0f9f8ae5c312de758420aef5fa12d4489a8c5f3e5ee627ea966dan/aHeodo
2020-10-15FILE_PO_10162020EX.docdoc 766e921c13edd4367d95fd44b3070b9d4bbee1886ba2e298fc91f030e5e034acn/aHeodo
2020-10-15PO_10162020EX.docdoc c9570917c32ecb1c6b6e8ffa9a486d3aebc0d0dca67ae6021b1c5a39f22e69baVirustotal results 46.77%Heodo
2020-10-15FILE_WW8646936479XE.docdoc 966af50d9ffd82cdc2a4fa693620dfe90172ef15047cc10d3b35fcd47ae47c4fVirustotal results 46.77%Heodo