URLhaus Database

You are currently viewing the URLhaus database entry for http://citymobile.rs/cgi-bin/LLC/hz1d84w7/f5311gwqp6qp4b9g8n8uq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:723689
URL: http://citymobile.rs/cgi-bin/LLC/hz1d84w7/f5311gwqp6qp4b9g8n8uq/
URL Status:Offline
Host: citymobile.rs
Date added:2020-10-20 13:25:04 UTC
Last online:2020-12-22 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 13:26:03 UTC to abuse{at}ninet[dot]rs)
Takedown time:2 months, 3 days, 1 hours, 58 minutes Bad (down since 2020-12-22 15:25:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22BAL_PO_10222020EX.docdoc 0270a190a68a88ef9a11d8bfb5a6d38256db6f38774772426cb5a578d2f981daVirustotal results 49.06%Heodo
2020-10-22PI6269817383QF.docdoc 9c0cb6e2390b59f199cd4dfbca2d6eb2106969b29ec8df33e4987474b80344eaVirustotal results 43.33%Heodo
2020-10-22FZ5987937318ZZ.docdoc 7eaf0df9dd2a33ee958384a9472366f58f1c0a204360efea6a7f8b0d298560d0Virustotal results 45.00%Heodo
2020-10-22BAL_PO_10222020EX.docdoc c31dadd735bc89eb4e5095f048428ac07fc1dd62c0f8e3913611dec1ec2ebdc1Virustotal results 43.55%Heodo
2020-10-22MJYNN08H705WTOZ.docdoc b86c1f13c4ef248f41ef298808f6597bdda3ad15541943eb545deaee02f4b849Virustotal results 45.16%Heodo
2020-10-22PO_10222020EX.docdoc 9c4152b0286e58648f1b01752c6704efdcc9aeabbb9c46833ad401d48ff81decVirustotal results 45.16%Heodo
2020-10-22INV_PGH_100120_HZQ_102220.docdoc 5547e0e56d071bec65265c21ea88ed4a9d8103d45eadcf69ca86c09f445bdd32Virustotal results 43.33%Heodo
2020-10-22F_PO_10222020EX.docdoc bfb7f5292586b3c2fd3673c21c2d9471162c4924bc2cf06259c5c83f610989cdVirustotal results 43.10%Heodo
2020-10-22A_82938928.docdoc e59123120209e007bb80c178032c84791d47cc6ee629f80a0126521791ad3b41Virustotal results 43.33%Heodo
2020-10-22A_CVE03SD56I.docdoc 0699c1bda793c7aaa9fc01940fe91bbe470ff01abfcbb32ab93d7a6a329e0d13Virustotal results 45.16%Heodo
2020-10-22BAL_6WJTD649RYBRXG.docdoc b6055d889e7ac86545888a5da746c4c231ead0afc40a036c3927188e99d7ae9aVirustotal results 43.33%Heodo
2020-10-22INV_SNG_100120_UVG_102220.docdoc 2ffe544b9a9857e4b910eff4ebf6183e41f7bc8996a68c68f49c4c576745d561Virustotal results 45.16%Heodo
2020-10-22INV_CEC_100120_NCW_102220.docdoc 06b7e31dc559bea806d24d61738a77de70118de926adc81fcbcdac1468c2bc1bVirustotal results 47.17%Heodo
2020-10-22DPIS_HLWHUCUZYJ.docdoc ed5ed9c256dc24f5aeffc1b9b0e7dba316c5c13a1966b7243770318805567ec9Virustotal results 44.26%Heodo
2020-10-22REP_PO_10222020EX.docdoc 2eef34160c2eb32badd3a16ec6ca60426491b8c7d8e986350d5646a66074e640Virustotal results 43.55%Heodo
2020-10-22Q_43618668.docdoc a78a2682db9e96335294df8912a7cd0a843bc011ae898a7fc211f79aea919fa2Virustotal results 51.61%Heodo
2020-10-22REP_3160438995594724.docdoc bad9235b37efab34f7e6cf91e6a80803fdcf8903e2c61d0d6c1f5f9d773da112Virustotal results 48.08%Heodo
2020-10-2273368339520936249801.docdoc da03a9b55b6989c3afc8a859785e254418322eb601e9fcf2ce58da55d9bc7d0bn/aHeodo
2020-10-22REP_93863325.docdoc 056f25e8944119ad3d9d651d77cc32cef6621c5cb3498b47161738be7aff416eVirustotal results 49.06%Heodo
2020-10-22INV_QA8672647554ON.docdoc 486ec0b6be1825886bf09579218543b12ad5ee75da313f4aefe0f9ad0b027f89Virustotal results 48.00%Heodo
2020-10-22YAK_100120_EMU_102220.docdoc bfcf012480833949d47a52c43762fccfd26a1785b134d1da9a84a2f91bca0778Virustotal results 49.02%Heodo
2020-10-22FILE_SYV_100120_YMC_102220.docdoc 9fe7e239b00579f78275ddcdb282bf2b112dad4d3a0bbc7f183e800244486bb9Virustotal results 48.00%Heodo
2020-10-22FJ3159266791FL.docdoc a1430eef6f6acc51cfc4215bd06407ebfc4f5ac126d9f05c27b3cf359dbb816eVirustotal results 46.15%Heodo
2020-10-22JJG1MJIW14R.docdoc bffe543ff321cb95dc82dc8c8a96c283d019176537290a63c6bc86d7ae98fe57Virustotal results 46.15%Heodo
2020-10-22T_38678671.docdoc 2ea760060d8e71ffce91d15fe31085ec999ed299d9d13e35dcd0544f8d361b59Virustotal results 43.55%Heodo
2020-10-22DOC_PO_10222020EX.docdoc dd44fd55293b9113d93ec32356861c6813ad6c23d399625147eb4ad930d71f24Virustotal results 43.33%Heodo
2020-10-22FILE_LV7519695901BR.docdoc 2da1ed7b630f4a606c6c65a41dc9c852015d64174113023eff5a63c64f5eac0dVirustotal results 41.51%Heodo
2020-10-2231574162.docdoc 4665ba876c251ac6ea1e6dcf5ce0a09af31397be348343317144e459901013c0Virustotal results 44.07%Heodo
2020-10-21FILE_526433982.docdoc 3af63f662ad3afb788f4f65538788a97811e2a45d869bf83d5ac6dfa9a2251e7Virustotal results 41.51%Heodo
2020-10-21N_571832487317270253409.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 41.51%Heodo
2020-10-21BAL_F938VJX.docdoc 140f99b8c86ce2cbf27556e78284f685e2cd53ff2e50838f444b115a6a04920bn/aHeodo
2020-10-21INV_232078655160659190.docdoc 2b7d9ef7d6b56a86f2a182683da404a4f463386f1fca26f49d9a930f72d298a6Virustotal results 40.00%Heodo
2020-10-21DOC_PO_10212020EX.docdoc 5603b9a3314a6d1e9220de7c0d42d8fae17921bf022ea4a8be18d5615989848cVirustotal results 40.00%Heodo
2020-10-21X_IN0935624556TS.docdoc c3caf9f914df7b8d90ac3dd35fd1ad24ec34a4d1af94293e9002a9f8f943703eVirustotal results 33.33%Heodo
2020-10-21UG2433898376YW.docdoc cb128eb8a7e2118942b9dc0b429a21c8aa057dac01473ad072f487d02cc80849Virustotal results 33.33%Heodo
2020-10-210192462953240.docdoc 8ce534c1cab5a87f1d3b7962eca1fc801060b44f8e8869701afc0c011604d317Virustotal results 30.19%Heodo
2020-10-2169259807.docdoc c92778df4ae556cc2ad66979e6fafa9256ce4c9c7d0457c6525711429def55feVirustotal results 28.33%Heodo
2020-10-21REP_ALT_100120_JXU_102120.docdoc a25f6b18acb33e6fcd32f81d686d793d38c299f1b42e561612c3ea67679975d4Virustotal results 30.19%Heodo
2020-10-21ZZH_100120_KBP_102120.docdoc f99f175949bd5a0dd1daa81ebbba94b4c80534368ce0192f1886c0babde234d6Virustotal results 26.42%Heodo
2020-10-21PO_10212020EX.docdoc afaa3e615a4cdb709e0914026d5c1d07892391f9e7a2540e8f35da1b810515daVirustotal results 20.97%Heodo
2020-10-21DOC_8971711108103850.docdoc fddd48d21efdc1d86734b611c1183bfe17b584b835bdb85655c3f9b17cf3e8afVirustotal results 39.34%Heodo
2020-10-21REP_8051066227468735.docdoc abd94a7b58ada746b22d9d6a4ef2b3847deda4d5569325459951c0c7f3b2a355n/aHeodo
2020-10-2191630115.docdoc 52caf1a070aa97f41dee32688e691efd22f50efe87a8f77d4a36a28281c19136Virustotal results 30.65%Heodo
2020-10-21INV_38172221.docdoc 0ef3eb571df8fcaa4ad2f23f3daabf1bcbc17ee41a42913f623eaaf788f5e04cVirustotal results 33.96%Heodo
2020-10-21DOC_PO_10212020EX.docdoc 692404c003439a5b699524594e4e229353b541469c40ff25a67e621c94c64c72n/aHeodo
2020-10-21VMU_100120_NFU_102120.docdoc 1ade5184899b623fc4bf9b7caacde819e06dcc9234a962622c056349092327c1Virustotal results 27.42%Heodo
2020-10-21DOC_GI7072085052VD.docdoc d2116981397601f48095f1a584c948e2e623ab4f0c5b2f393479cb20d67bfa90Virustotal results 33.96%Heodo
2020-10-21DOC_SXK_100120_FNB_102120.docdoc d6edabb30c96ad35f08d16e274d639b6a5a5208e7b35167d56392a44b3842599Virustotal results 26.23%Heodo
2020-10-21ML_45607429486292544618.docdoc c01293cbf44eb0891823207d0b98d05d1074414439d414610dfe04250424c5ccVirustotal results 25.00%Heodo
2020-10-21REP_EE1351257701QY.docdoc 1865098fcd518717e48cae856ca1cb02c85a12a37eac4934fe3ec1a7ac2040acVirustotal results 25.81%Heodo
2020-10-2153270118872909933592459.docdoc efc52b61116de71a3b3191b7bf3d79f9152dd3d3fa3d34889a4f11ef178d9e68Virustotal results 50.00%Heodo
2020-10-21FILE_2940014000962987362103.docdoc 91b4636eaefca65ce60c334d8ae4d9c2b01b86dab6e1aa54127de53228272d88Virustotal results 50.00%Heodo
2020-10-21Z8MS61R45D5.docdoc 988037ab30e7fefdcaff766f160658d982522969787c02fddfd09ce912573dc1Virustotal results 50.00%Heodo
2020-10-2194753659.docdoc 99e0cc7017a32fc566d969c88fae5cc8db236858e93bfe804e18a1c4a08e94e8Virustotal results 50.00%Heodo
2020-10-21FILE_YSM_100120_QJS_102120.docdoc 39a7385578321db9d477ff19e7087b03d3c57076ceca16fc2af049c087f72343Virustotal results 38.98%Heodo
2020-10-21S_69166917.docdoc fdf5102af9db589345a5c7d4e747c98489a7341147058b2a42e337a03fa62baan/aHeodo
2020-10-21DOC_YVE_100120_QZM_102120.docdoc 71410da7fd254423681e9a41961a03bac9777fff1882cee09b6ddb785b38b923Virustotal results 49.06%Heodo
2020-10-21FILE_YLJ_100120_PFS_102120.docdoc def1d352d42981058ad1dc582336e6872aa190d9075c65fc3c7d1575d1eb696bVirustotal results 46.67%Heodo
2020-10-21INV_07723176.docdoc ef31028a7bfb047b5233493c6b8e14ac6fa49ac6d022b6e016a22276a4be732fVirustotal results 46.67%Heodo
2020-10-21FILE_LW7AZENGNAGYS.docdoc a6bddd637e4236272a008fab76c75939a56c92161692387612bde0123e8b26e1Virustotal results 47.54%Heodo
2020-10-21REP_ZE0208619832PO.docdoc a977513362ad46e1cab8cdf98638a7e3edcd11796c732a818660e18e49b74a5an/aHeodo
2020-10-21R_SANRFVQB0679.docdoc 730dc7281140bb144e159ad27638ff4f4d3a021999727a26b7731250343a3f76n/aHeodo
2020-10-21BAL_B33DGYUBLTJTBL.docdoc 614bbd10017422522d46a734ed08de066834e449d5802b036b0231a39b0c043cVirustotal results 49.06%Heodo
2020-10-21FILE_6577469674251687971468.docdoc afcfe7ff49c2df7f47347c4c49d64ac3f027b1c79f5d090a0daf526fd65d859dVirustotal results 43.55%Heodo
2020-10-21FILE_PO_10212020EX.docdoc 6eb67022c07e3f32436afc6e89eddb132a4c5d34d733c824ab3dabf51b7c712aVirustotal results 39.62%Heodo
2020-10-21BAL_PO_10212020EX.docdoc 7b59e4314d2b1bbefd045815d54be5bd19315bcd13e3de6816a36bfd0930e032Virustotal results 39.62%Heodo
2020-10-21DYTI_XBJ_100120_ZPB_102120.docdoc 17ac0ed02b6127efefaa0cc936604bc12947c394e902bb8bf88e37b6f0829d9fVirustotal results 40.32%Heodo
2020-10-21MUV_100120_VWU_102120.docdoc cd0c0ee5979ebfa7ed73a40ee1f879f2b65cc57ed38619fc4f7e186c15e54128Virustotal results 38.89% Heodo
2020-10-20INV_82677957.docdoc a65e7b5a4d99582f1ec1c608eea4d21fd29d1c23bed2b8dd8ec8062f23d90e40Virustotal results 39.34%Heodo
2020-10-20REP_WW6W2LFT9I1.docdoc 8cadf5fc31643a1acc9b991d110e039e7e0520e94783c61d9caf5ccb2481915eVirustotal results 44.64%Heodo
2020-10-20JPR_100120_TWV_102020.docdoc 07bdea9c73c53c4d65c9cf2061b9a303e8f05180736729fe54c17c6953e66184Virustotal results 41.67%Heodo
2020-10-20PO_10202020EX.docdoc 9b8e334f4715a421eeea2f1240aa9f3225a0c4f2cf97f8abd3f84c945d39f19cn/aHeodo
2020-10-20T_DA8101180859UX.docdoc 80911a9fc7a1cacae8657c27427e3d2f1a350d3ce6425517da3d1d2fed63e7cen/aHeodo
2020-10-20INV_TY5581486587XB.docdoc 2dcdf03e311cc231854f3971e8e39171b8829e3e72cba54cf82c624519e7e737Virustotal results 39.62%Heodo
2020-10-20293705068835.docdoc 95e5bd8a2660b5b09779472b9f54aac5ccfd4eaa5aab53a448d8ba3baf61fed9Virustotal results 36.21%Heodo
2020-10-20FILE_PO_10202020EX.docdoc 6bac12ad611439d3d004be53bed73d3db7922872af54d05b0c06ef3fd7948aa5Virustotal results 38.60%Heodo
2020-10-20INV_89459095182.docdoc 583d089d846766a56071e1b820a9209dd19ba0db4113c7d65f45171957147297Virustotal results 37.50%Heodo
2020-10-20DOC_QWK_100120_XBS_102020.docdoc 1dd7a8d416a727f166d33634aa4cf35a44111d5e1c51a4d98169157c965a27f2Virustotal results 40.32%Heodo
2020-10-20FILE_40447343.docdoc 621f20067cbf141bfbaa9f852e46d9dd4345b045435364b925741d9f180a2918Virustotal results 38.33%Heodo
2020-10-20FILE_51648817414220092111.docdoc bf264f92b0e3ef3f4d9e2796a07576e3fdb22454e3392625248b65a94d5ce99fVirustotal results 36.67%Heodo
2020-10-207VVDEDQ91RDONKRM.docdoc 3a8287a81d763e34609872325add4dfcccd8609540be210a698596e019647947Virustotal results 38.71%Heodo
2020-10-2049197585.docdoc 7a8b2c156f080eb853a85b4e9beece21fb85945a3c4e0a3ecdd548ba52b88de1Virustotal results 40.00%Heodo
2020-10-205545790589.docdoc 5562a5a261dc5ec8d9d05ae9ecd2b4b15bcecd35d648906f0c1ffc2e85a5d1f9Virustotal results 37.93%Heodo
2020-10-205113963033.docdoc 08057a9df9d17da8a860ee860efc60fef7c46b9cc8bf15ffceeb7ed05480b01aVirustotal results 33.87%Heodo
2020-10-20DOC_KM4980934615AA.docdoc d5f91e755ac8a30effb49d42cec3f28324efed4fa814de5d5ec2464fd1136a62Virustotal results 33.87%Heodo
2020-10-20805711874.docdoc dc2bf19b8783e823415f8820060f32660a8aa7077eac281739eb380f7168886fVirustotal results 34.43%Heodo
2020-10-20PO_10202020EX.docdoc 7bd7deede6dbf2898719a1e37617111154bb0528478f5fa1bea48c21c7ab4145n/aHeodo