URLhaus Database

You are currently viewing the URLhaus database entry for https://edwardscontracting.co.uk/test/eTrac/lzacd749jvdo/yhw8w2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725306
URL: https://edwardscontracting.co.uk/test/eTrac/lzacd749jvdo/yhw8w2/
URL Status:Offline
Host: edwardscontracting.co.uk
Date added:2020-10-20 19:56:03 UTC
Last online:2020-10-21 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 19:58:02 UTC to abuse{at}aware-soft[dot]com)
Takedown time:12 hours, 49 minutes Good (down since 2020-10-21 08:47:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2175Y8AALT.docdoc 6a71e77723470c71b7481201af67c2a3fccef877d132370bdb2a3d8a705ce95dn/aHeodo
2020-10-21UNG_PO_10212020EX.docdoc 3f28d23c6650e22fa69d824efc5153fd46fecbbdbd236ae7b4ee15bae4ef556dVirustotal results 49.06%Heodo
2020-10-21WG7741489338UF.docdoc c8b17ac2998849beb6bb8ea8fbb40c2457402574ec8c6768a54a0db63c8ecb8cn/aHeodo
2020-10-21DOC_Y5FUY4QP96Q745.docdoc f63551b5b6a12a9fe329cae332d0d952a9e56640ed81da22996a4ee0efd379c1Virustotal results 41.94%Heodo
2020-10-21BAL_596164595082564.docdoc c75ff84fe40e2bd56dd64dd2a51d43de4ae2eac42c9efb6df985ff4244f7f974n/aHeodo
2020-10-21REP_PO_10212020EX.docdoc fdf5102af9db589345a5c7d4e747c98489a7341147058b2a42e337a03fa62baan/aHeodo
2020-10-21LHNO_1168273613171677918775.docdoc 2b5fc5004d582d3716cad376c6d98b0c2da17ce59eb4b3d0ceaddfce0128a73an/aHeodo
2020-10-21FILE_YY8YFVJMR.docdoc ff560f270317afc9d31e1eae55c277c99bdd45f9fbd3a2dc44e8929a25ff065cn/aHeodo
2020-10-2138334670.docdoc d755c5281821fb9a1af024b9c6bd977a7da4c3aabe8999703525ece1767fdd13Virustotal results 50.00%Heodo
2020-10-21REP_BD9297141552ZK.docdoc d0337f9e3f826764678ff11fd7e2b49a84db21bd33615cd0cc63e6654c502d9an/aHeodo
2020-10-21IDE_100120_RTX_102120.docdoc a977513362ad46e1cab8cdf98638a7e3edcd11796c732a818660e18e49b74a5aVirustotal results 43.40%Heodo
2020-10-21J_PAK_100120_CTX_102120.docdoc 730dc7281140bb144e159ad27638ff4f4d3a021999727a26b7731250343a3f76n/aHeodo
2020-10-21W_EHK_100120_EFO_102120.docdoc 84feca377993d253e4d214e7c044ddd45eb3ef0f47796ef2970e9a5bd1f2f535n/aHeodo
2020-10-21DOC_UJ4044704992LQ.docdoc 6b85363b3e529eb9580f5c273816ad4cefba491ec3927872ee7570a550df965aVirustotal results 46.30%Heodo
2020-10-21TJF_100120_IZM_102120.docdoc b5f8485da1270855c2866456988ce8010f5c32c69fb19f324859d685e719fa3eVirustotal results 40.38%Heodo
2020-10-21DOC_24688607.docdoc 92e4476fe9673fe19a33b4c306402a172f3b2124ad380f0782517a9e15fec347Virustotal results 39.62%Heodo
2020-10-21E_MAD_100120_MOH_102120.docdoc 1393994f35a8a5910cbc519d9a9d9baa91d4dbc85080bea49d95c152892a2aabn/aHeodo
2020-10-21SGZB_0346968214127925276298433.docdoc 0d80b679c7accc183439a7f6d72dfa61e4fb2e260706398692fdb1f2c1255343Virustotal results 40.32%Heodo
2020-10-20DOC_33036207.docdoc a65e7b5a4d99582f1ec1c608eea4d21fd29d1c23bed2b8dd8ec8062f23d90e40Virustotal results 39.34%Heodo
2020-10-20PO_10212020EX.docdoc 8cadf5fc31643a1acc9b991d110e039e7e0520e94783c61d9caf5ccb2481915eVirustotal results 44.64%Heodo
2020-10-2052480394.docdoc 549072b3e94570b866d20997383d99b1b2a7b9a014cd41ab974cb0853307058fn/aHeodo
2020-10-20DOC_SUJ_100120_WWN_102020.docdoc 07bdea9c73c53c4d65c9cf2061b9a303e8f05180736729fe54c17c6953e66184n/aHeodo
2020-10-20REP_HS1640264821XN.docdoc 73b1ecd0729d4a6776f63d5ec7943f5914ff080311e5f670ab38a4991795d29dVirustotal results 42.62%Heodo