URLhaus Database

You are currently viewing the URLhaus database entry for http://locuz.yumweb.co/profile/Document/pudg2f-000935/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:726329
URL: http://locuz.yumweb.co/profile/Document/pudg2f-000935/
URL Status:Offline
Host: locuz.yumweb.co
Date added:2020-10-21 00:36:06 UTC
Last online:2020-10-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 00:38:04 UTC to abuse{at}digitalocean[dot]com)
Takedown time:17 hours, 23 minutes Good (down since 2020-10-21 18:01:34 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-213109507.docdoc 31658c6055bda692c4a944b0dd23ef5f0ef7d312df172a1eafb6317a110f286bn/aHeodo
2020-10-21Invoice.docdoc a190cc4bd4d39b253f7e560cdf793dd829f74b0f816bbddc666525007a02412fVirustotal results 47.54%Heodo
2020-10-21form.docdoc 33931df25bbfed2013a987a32738c165a5799d274381e76cbf534ba189be293eVirustotal results 45.10%Heodo
2020-10-21INV #0548 FOR PO #9361908694.docdoc e3812e0aa164c68399e61ce76904450c3e6bc028111a3c4df2155e37ad5d01b1Virustotal results 44.44%Heodo
2020-10-21PO# 10212020.docdoc 8d8971cd4eb8a2c26f5263e44299f9f468d43614dcccdcfae564420d264e0d29Virustotal results 43.55%Heodo
2020-10-21RD9786195906PE.docdoc f230273ae9e5eb57e36f98c374578e1a9856504dfbfbdcc7f815d20ba5974f2dVirustotal results 41.94%Heodo
2020-10-21Copy invoice #944460.docdoc 916c5fa5d800ce852e4e0e1c215daf1e813c868e5b1d9b0c7956b16ec6649adfVirustotal results 41.51%Heodo
2020-10-21Inv. 45589458962.docdoc 106359e17594a3265349fbfc1a2fd1e2f19940ca5c4b2262c1d021bb8d74fe11Virustotal results 41.67%Heodo