URLhaus Database

You are currently viewing the URLhaus database entry for https://support.servu.co.uk/behavior-goals/eTrac/g9beyek/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725303
URL: https://support.servu.co.uk/behavior-goals/eTrac/g9beyek/
URL Status:Offline
Host: support.servu.co.uk
Date added:2020-10-20 19:54:07 UTC
Last online:2020-10-21 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 19:54:27 UTC to abuse{at}aware-soft[dot]com)
Takedown time:13 hours, 31 minutes Good (down since 2020-10-21 09:26:06 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21REP_2623514081.docdoc 6a71e77723470c71b7481201af67c2a3fccef877d132370bdb2a3d8a705ce95dVirustotal results 44.44%Heodo
2020-10-21CZH_100120_EDF_102120.docdoc e6335af6ecbbb9d05de5332fb55088045d8066babe6f9fb4cb05e7097ce44046Virustotal results 49.06%Heodo
2020-10-21REP_PO_10212020EX.docdoc 7c22299823a1e18a0b708214938185faee0fa695ce9e511d56cfe81cb1aaf58fn/aHeodo
2020-10-21INV_NRN_100120_QNE_102120.docdoc ffb659e12aeea991c1bca3702e7d3c01cb589251885cd53c4025994a5e3e1309Virustotal results 48.08%Heodo
2020-10-2178136068.docdoc 05b629955789a13f86e0e00a2b8f9400d48e46df8ce553156c801065adf45872n/aHeodo
2020-10-2180040865.docdoc 39a7385578321db9d477ff19e7087b03d3c57076ceca16fc2af049c087f72343Virustotal results 38.98%Heodo
2020-10-21DOC_QYS_100120_UDY_102120.docdoc 4d674a6143e1a896967213d335f2d95bdcee16aa83b718071ad004c674e458c5Virustotal results 48.33%Heodo
2020-10-21PIB_100120_XUC_102120.docdoc 192d1f4fdc36c10af1e2e207ca659c5b7549c01b189257a12f226c42a6c6b4cfn/aHeodo
2020-10-2189067190628723642.docdoc fe1e5c66a4990cc515e5925db68def9f29f1893d9c6d3fa6b47e05f5c5f618ddVirustotal results 46.55%Heodo
2020-10-21PU_AX7357498449XL.docdoc 8649400e43ae5473b22013585baaa8c2023eb59669aed82a0ca171330b5f6c7cVirustotal results 49.15%Heodo
2020-10-21DOC_ZO8975493977JN.docdoc cd230affe2cef8dd5938e3ea670dbd706c65f93341c35d2eaecf1a5ae6d8203aVirustotal results 48.28%Heodo
2020-10-21BAL_62402198.docdoc 230fc1531e7d113ebf83ea8dad03120965c293da08a2ae82305ac9cb61efe7b8Virustotal results 47.46%Heodo
2020-10-21DOC_MQS_100120_TVX_102120.docdoc 25d12cabe3d39e681a0b8c9ac88206110f66071089e92667ee0fed7bc917e918Virustotal results 46.15%Heodo
2020-10-2133850932541359990.docdoc 8ea38c51f8926ffa9ee61be53fc7ee3e4f968f2c7683bbc3b9320d14a2443067Virustotal results 43.40%Heodo
2020-10-21X_FZQ_100120_VQM_102120.docdoc 614bbd10017422522d46a734ed08de066834e449d5802b036b0231a39b0c043cVirustotal results 34.78%Heodo
2020-10-21INV_RO8937743953VI.docdoc b0e434b1de80d97737347fcf4a28a60aad479593c4dde9c9611296cef08185e8n/aHeodo
2020-10-21REP_PO_10212020EX.docdoc b5f8485da1270855c2866456988ce8010f5c32c69fb19f324859d685e719fa3eVirustotal results 40.38%Heodo
2020-10-2101376019.docdoc 92e4476fe9673fe19a33b4c306402a172f3b2124ad380f0782517a9e15fec347n/aHeodo
2020-10-21BAL_GM8634735978VQ.docdoc a78451771b5a8e66fd912d10f9b621e52239473334785ec68755db5e60594ecbn/aHeodo
2020-10-216724612923315543929241549.docdoc 7bf2ce4dd307b31f8b2eeff8a5ca658f7a680a9bb132d54d6182c711504b0ac3n/aHeodo
2020-10-20Z_10651591.docdoc a65e7b5a4d99582f1ec1c608eea4d21fd29d1c23bed2b8dd8ec8062f23d90e40Virustotal results 39.34%Heodo
2020-10-20PO_10202020EX.docdoc 8cadf5fc31643a1acc9b991d110e039e7e0520e94783c61d9caf5ccb2481915eVirustotal results 44.64%Heodo
2020-10-20Q_48394049.docdoc 8ebe3eb8f2fc91787e217da76d31b3108744220f6cd2a5b74fc6b57c9c681317Virustotal results 42.11%Heodo
2020-10-20DOC_YW2017647895MY.docdoc 73b1ecd0729d4a6776f63d5ec7943f5914ff080311e5f670ab38a4991795d29dVirustotal results 42.62%Heodo