URLhaus Database

You are currently viewing the URLhaus database entry for https://hairbyjenniferx.co.uk/test/balance/zxucq5j5es3c/zcq8ddxk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725273
URL: https://hairbyjenniferx.co.uk/test/balance/zxucq5j5es3c/zcq8ddxk/
URL Status:Offline
Host: hairbyjenniferx.co.uk
Date added:2020-10-20 19:53:09 UTC
Last online:2020-10-21 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 19:54:27 UTC to abuse{at}aware-soft[dot]com)
Takedown time:13 hours, 4 minutes Good (down since 2020-10-21 08:58:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2148605620221415141134.docdoc e7863e06fdf3830b0b5b4c8f97dac6420a04c0fae7f728aca4ebe046534b9b0dVirustotal results 50.00%Heodo
2020-10-21X_11064392.docdoc 3f28d23c6650e22fa69d824efc5153fd46fecbbdbd236ae7b4ee15bae4ef556dVirustotal results 49.06%Heodo
2020-10-21REP_F6OKYJ09.docdoc 9d3040374b112258a669d0ed8b5cc9bf7444e7ab0e937ebff0e3cab6286ab626Virustotal results 50.00%Heodo
2020-10-21BPUT_SN1840971808WJ.docdoc 66ff2845aa49250c6a643867ff07164647006a80a5fadaddb5d41c99fd6b9452Virustotal results 48.08%Heodo
2020-10-21O_BLZ_100120_VXK_102120.docdoc 1996ba49c1e42e54c8cd2717756d00e05f3290d1be0d606dc11a3ae0f556ffc9Virustotal results 52.83%Heodo
2020-10-21DA0883406529NK.docdoc 72ee93d05e4bd3913546a0db9808d690f708353470319f19b20235fd0107ec38n/aHeodo
2020-10-21J_MJ5342293961LC.docdoc db6c107a7034688cf9fd3a069d7941ee4b8f606b102e3cb24e1dcab621a87304n/aHeodo
2020-10-21DOC_BJR6U7WX54YGQ.docdoc ff560f270317afc9d31e1eae55c277c99bdd45f9fbd3a2dc44e8929a25ff065cn/aHeodo
2020-10-21BGO_100120_LWZ_102120.docdoc d755c5281821fb9a1af024b9c6bd977a7da4c3aabe8999703525ece1767fdd13Virustotal results 48.39%Heodo
2020-10-21SU8072222069PS.docdoc ef31028a7bfb047b5233493c6b8e14ac6fa49ac6d022b6e016a22276a4be732fVirustotal results 46.67%Heodo
2020-10-2188676753.docdoc 230fc1531e7d113ebf83ea8dad03120965c293da08a2ae82305ac9cb61efe7b8Virustotal results 48.39%Heodo
2020-10-21INV_PB1077920373WL.docdoc a977513362ad46e1cab8cdf98638a7e3edcd11796c732a818660e18e49b74a5aVirustotal results 43.40%Heodo
2020-10-21HL6328275277DN.docdoc 25d12cabe3d39e681a0b8c9ac88206110f66071089e92667ee0fed7bc917e918Virustotal results 36.54%Heodo
2020-10-21BAL_YO2845732990CF.docdoc 614bbd10017422522d46a734ed08de066834e449d5802b036b0231a39b0c043cVirustotal results 34.78%Heodo
2020-10-21FILE_18817534.docdoc afcfe7ff49c2df7f47347c4c49d64ac3f027b1c79f5d090a0daf526fd65d859dVirustotal results 43.55%Heodo
2020-10-21683156755337559.docdoc 2465db836fb8ce33c72ba9c55528a00a290b770a2bb977ecaed539b453c1211bVirustotal results 40.38%Heodo
2020-10-21LKRV1QHUXR6HWY.docdoc 7b59e4314d2b1bbefd045815d54be5bd19315bcd13e3de6816a36bfd0930e032Virustotal results 39.62%Heodo
2020-10-21INV_EJV_100120_ECJ_102120.docdoc fb83f2eec33aadc1229efe5c44276c92fbf59ce6dfab221071a61ca25c694a82n/aHeodo
2020-10-21125067814.docdoc cd0c0ee5979ebfa7ed73a40ee1f879f2b65cc57ed38619fc4f7e186c15e54128Virustotal results 38.89% Heodo
2020-10-20PO_10212020EX.docdoc a65e7b5a4d99582f1ec1c608eea4d21fd29d1c23bed2b8dd8ec8062f23d90e40Virustotal results 39.34%Heodo
2020-10-2088084024.docdoc 8cadf5fc31643a1acc9b991d110e039e7e0520e94783c61d9caf5ccb2481915eVirustotal results 44.64%Heodo
2020-10-2034444347.docdoc 6f38eadeaa66f8291d39404657f414c63a1a29aa2a8368ad16f536242f8acc65n/a Heodo
2020-10-207812474227.docdoc 73b1ecd0729d4a6776f63d5ec7943f5914ff080311e5f670ab38a4991795d29dVirustotal results 42.62%Heodo