URLhaus Database

You are currently viewing the URLhaus database entry for https://www.crystalteck.com/06-comming-soon/eTrac/0733942782693797/oyfmoYoC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725039
URL: https://www.crystalteck.com/06-comming-soon/eTrac/0733942782693797/oyfmoYoC/
URL Status:Offline
Host: www.crystalteck.com
Date added:2020-10-20 19:03:05 UTC
Last online:2020-10-28 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 19:04:04 UTC to hostsoch{at}gmail[dot]com)
Takedown time:8 days, 2 hours, 33 minutes Bad (down since 2020-10-28 21:37:27 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Inv. 00205922754.docdoc 7a56b5b48ac48e157ed7a853c891fe72ec3df342d02414d2aca77a1b62772ad8Virustotal results 34.69% Heodo
2020-10-22Invoice 4231757.docdoc 5825492e4acb3a6e36349f5fafef4745159e86616e9d38b4db2e2b4c212e3119Virustotal results 35.48% Heodo
2020-10-22Invoice 86559.docdoc d8bbe49377ebac547c2afa2ab29a64b774b4ddb3501f62becbaedf4d24c33a0fVirustotal results 38.89% Heodo
2020-10-22INV_825860.docdoc 749e0e405f25ff952f9ac9f879f50fcaac51258237b698562dc85c891bf323a8Virustotal results 33.33% Heodo
2020-10-22Inv. 070779109.docdoc 54e4fc3613affad5354fc1058f7879031c1191f2e8e79b72df4673bae4603695Virustotal results 50.00% Heodo
2020-10-22October invoice.docdoc 01b228cd4f024acce23be7b762797915e8ece1d47c301e20f9596a98aed2acb5Virustotal results 49.06% Heodo
2020-10-22October Invoice.docdoc ba76faaf67244b22ede91ccbdb43e3988b58539eeac446392d0c61afbb5ef437Virustotal results 49.06% Heodo
2020-10-22IY-100120 VRSJ-102220.docdoc 3d931f3056e01ac585facd9cd6b2295bd63dbc6e340ccc4d94549533f42558e4Virustotal results 46.30% Heodo
2020-10-22363894.docdoc 711fafda2f160ff5d89246ee698c4ba0738663a2a0a61469c401fc03f59b4550Virustotal results 49.09% Heodo
2020-10-22form.docdoc b25f82dbf33bc9cc154be6c8bef79aa2b570c84eba334f3fc27ae55681f6c154Virustotal results 52.63% Heodo
2020-10-22form.docdoc 638b48f5106a07180e10d72cb0c0fdd9c3568b08e463ee480d66fae4ab87f029Virustotal results 49.06% Heodo
2020-10-22invoice #19281.docdoc df51e418e047ba848de075954ab841887fafe6e47c6b7b6d529222e3795ecb23Virustotal results 47.54% Heodo
2020-10-22invoices 4881 & 4483.docdoc 098b7a1d812c209b85974e1f187e3a670e02821164c1dba212da04d78e86ff33Virustotal results 47.17% Heodo
2020-10-22Electronic form.docdoc 4c0eefb631af43ca75f18562817c8ac29361fdf7b5a528341efa855a8d1c6a6aVirustotal results 40.35% Heodo
2020-10-220767875.docdoc c0cccadc44aaa5274573830ea82eef9cda6607a02db099ce12c138cf50bb267fVirustotal results 46.43% Heodo
2020-10-22October Invoice.docdoc 3abe5cdbb82a1a48fb89ecf043e24351ffb466cb6112ea7316f6fb518244a289n/a Heodo
2020-10-22INV_7738.docdoc 077db39d1c6f7785aa6191761f4033eeaf24c81e2c0ed0f104e798e63a6a1c4aVirustotal results 44.64% Heodo
2020-10-22LK5967114181TV.docdoc caa64b3ac297b61892889a9f4a29cb2bd5719a809c2b610c07fdd30c5c9f7129Virustotal results 45.16% Heodo
2020-10-22INV_4143.docdoc 49e99a2c9064c24011dc0c71ff29d661e2b447f8213bc858b7feaa28d5d22576Virustotal results 44.26%Heodo
2020-10-21Inv. 0014602.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo
2020-10-21form.docdoc edceeb0a4307b08df79e506dd7c07185337cd4a6b3f7a979d55b168f768d94ean/aHeodo
2020-10-21October invoice.docdoc 846e5913124d7032c01dffc200b7250ef349a517df8653d0e92ba024b61de295n/aHeodo
2020-10-21October Invoice.docdoc 68650e65451380320a268775d59b1d777dbfeda748e2b73807177871d912e240Virustotal results 27.87% Heodo
2020-10-21INV #3129 FOR PO #41790596.docdoc e45c71c909dafaee0830088e9068e0cb0f2f99e5ab1ff7da592240e46ba6fa58Virustotal results 29.03% Heodo
2020-10-210617840751.docdoc 793296b35ebc61fce4acf584fba910b876bafb60877bdd657f2bf7839bc5d84dn/a Heodo
2020-10-21Invoice #377521.docdoc 887c3473aab94ff54bed0af87135fad58dcb435bcb5dd630ca49ebfc6d1b9a55n/a Heodo
2020-10-21form.docdoc 4edbef59b575a4095b13edab1b9c640b1cecc8f25a2b61f93e988285c079b488Virustotal results 25.81%Heodo
2020-10-21NW34 invoicing.docdoc cf275b27c9d9ff1afbbf89c46cd4546584c4a173ddc75405c48b7ead240f7b0bVirustotal results 30.43% Heodo
2020-10-21PO# 10212020.docdoc 20822d454fc7b4ccc00e84d41fcfebef444b6d243921dd0e7db0c7252f1e319bn/aHeodo
2020-10-210333432.docdoc 4b091f47077d168f83c5f39f3ca6837c70c9fef749880418389cf07514420dc3Virustotal results 26.23% Heodo
2020-10-2106952837.docdoc c197a6840f019226e39e14128490f861eb67b738ccfee85a256e97847047b769Virustotal results 28.57%Heodo
2020-10-21IY9286581900KC.docdoc e1443833e96642ff26e74d8b999dcf5aeea285a95e9ad1e70ad696f035a66518Virustotal results 26.23%Heodo
2020-10-21INV_9360.docdoc 2dccaaa7764ebb4f4e309902834f8ebfe5049decf0cc573e4e68befa3f84e69fVirustotal results 26.23%Heodo
2020-10-21Invoice.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21Form.docdoc a32b8fc89045749411368894b5eb70012518a8d9d1703b940bcbc966c0e40bdfVirustotal results 50.94%Heodo
2020-10-21Form.docdoc a9b5951976e5aebe82b1a18ef33e379ec5f3a36a04b89103649e54d7dc746aecVirustotal results 49.06%Heodo
2020-10-21October invoice.docdoc 33931df25bbfed2013a987a32738c165a5799d274381e76cbf534ba189be293eVirustotal results 46.15%Heodo
2020-10-21INV #06347060 FOR PO #08896945.docdoc df0901fe828ab8ff739461f32f011dd20e5cf34df476de9821c56d8bc6e9528dVirustotal results 44.26%Heodo
2020-10-21invoice.docdoc a3bd9261b5a8844a6a6a77e06f0eabf6a21d998001e99718a42f8bfc8147762dVirustotal results 45.00%Heodo
2020-10-21October Invoice.docdoc 29cdc20b4b547e832ab1e9c0eeff5b71201efe4262d8d542a8b359131f26ed1aVirustotal results 41.67%Heodo
2020-10-21October invoice.docdoc df9211fe12de3974165e9b876ac971eb94c70c83d54a06ccc3028a91eb92c7f4Virustotal results 41.51%Heodo
2020-10-21Y9350473195OK.docdoc 663930eb12ff6afb8cd3d0410fcef8fa32edf4964504e10f0cd56af546b0ecb2n/aHeodo
2020-10-21Payment.docdoc f75dfd9100b7fb7c93a95812e11a04f911e4ed1f61fafa8b73c747df9898a212Virustotal results 40.98%Heodo
2020-10-20October invoice.docdoc f98b21e5ba36d3d933fdd95c54037c9a3412c52fd05700222580a7e4267608bdVirustotal results 41.51%Heodo
2020-10-20INV #577847 FOR PO #0080410774.docdoc 368608fc48be7d6239425f9a9e23b2aa19d22aaa001796c8c0e391858bd2932eVirustotal results 39.62%Heodo
2020-10-20Invoice.docdoc cf4ee7df0ffd61e8ffcd0559aad63ff1c60cfbe2b0f7bf5e3cb4d771218f8657Virustotal results 39.62%Heodo
2020-10-2008111643.docdoc a85c57fa12d0087eb6da3bbeff4a027b351978d8b8073086c43d522366e5fe9eVirustotal results 39.34%Heodo
2020-10-2004009088.docdoc d6755b63b325a0da010a33d5a3e1698866b58b7628b6c3b47a5beb12663604e2Virustotal results 37.70%Heodo
2020-10-20Invoice.docdoc 864eeb47c83f4648f5c3a22de6c34559c24f871adfe7490af5c932ee7fbd52f4Virustotal results 32.26%Heodo
2020-10-20October Invoice.docdoc 80112c9d5f76aa1687aa0df70c0d7f1d96f1b7524da942b87480ff37231091e8Virustotal results 32.79%Heodo
2020-10-20Payment.docdoc 9c7f9441f61d7c2798707bc28069012911e4547e38374095bb23506fb1bbee2eVirustotal results 31.58%Heodo
2020-10-20Form.docdoc 1949d127f8cad19649adb5f4534e1b6eff752a31d5ea73e427d0ef8c90511ceen/aHeodo
2020-10-20Invoice #142.docdoc c9804b898a9d2326b05f4037b2eace298777d1a387273033692c9f6deede6cabn/aHeodo
2020-10-20QW-100120 OXFZ-102020.docdoc 3bc3a1ea24bd194a23d6c8493b9754de9a41127025a14052754eba04dd1dda70n/a Heodo