URLhaus Database

You are currently viewing the URLhaus database entry for https://www.arthurrazor.com/css/swift/d3py5w4jz3mq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:727408
URL: https://www.arthurrazor.com/css/swift/d3py5w4jz3mq/
URL Status:Offline
Host: www.arthurrazor.com
Date added:2020-10-21 05:59:04 UTC
Last online:2020-11-01 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 06:12:20 UTC to noc{at}krystal[dot]co[dot]uk)
Takedown time:11 days, 12 hours, 31 minutes Bad (down since 2020-11-01 18:44:02 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22BAL_TNE_100120_FTR_102320.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdVirustotal results 42.00%Heodo
2020-10-22YKUN_BPV_100120_CSK_102220.docdoc 03d580e7110bd85d7a360ceb31538a967f59877402892ca04ae4859e4ea20e00Virustotal results 42.31%Heodo
2020-10-22PG3I3ETGNO2Z3ZM.docdoc d6703263ade837f40041f706035c4607c319cd75efa19a8c68a7ab46fc43c1a5Virustotal results 42.62%Heodo
2020-10-22T_FMM_100120_ZBX_102220.docdoc c5e2ca43cfaf08706098c33d599b0b3290e871331e604cc8ca58dc71794c8183Virustotal results 42.62% Heodo
2020-10-2299802556.docdoc 9efd979157de0caaf41c017ec54c0164a339103e2a19255e4e8666024d477fc7Virustotal results 40.98%Heodo
2020-10-22680730617174.docdoc d718bafb38535e5c1ca6fb484a744078d3ff431987ae87ce1682bd38f8aa350cVirustotal results 38.46%Heodo
2020-10-22R_PGO_100120_VJQ_102220.docdoc 937c87496e98fe97075f0ae5ec35a64a75cc04b533f0a1a937d8a50096183519n/aHeodo
2020-10-2255259980.docdoc 55e79ed4dc97111eb94b6830fdada156fc8d7ca76f3dc5a15d737fbd0dba8757Virustotal results 39.66% Heodo
2020-10-22AFVO_04187288.docdoc 6e73ed5041166e3aa6f7ce070efab391259a868771d35fa7f6b8aa64d8a3065fn/aHeodo
2020-10-221235875507159294011991.docdoc 44be59f199c5d2d4d0dcfef847d9e611abcaab3d8223b63fcbfe9a5d3c6745d5n/aHeodo
2020-10-2207176312700195791.docdoc fe5ff5b44dde8df916f46992574027192d8a8bf4ab36091fcb25905c0afa6afbVirustotal results 40.38%Heodo
2020-10-22JS3939859539GB.docdoc 5071f2da34845b41b8e65266293f6756c12aef537eaa3777eeb4f6333f6191d5Virustotal results 36.54%Heodo
2020-10-228YH1W1VYZVOCV9Q.docdoc 1398dfcbea47214d59bb327957bac69b2db7c06a50da13399c63aa797fa5fa9bVirustotal results 40.38%Heodo
2020-10-22DOC_08409007.docdoc 3f0f9c6cc34e60cf9dd9c8479ef08f97d80ffc7bd5135fda5eed8189c7a31f2dn/aHeodo
2020-10-22INV_89112927.docdoc b02d8914188d8c0628510d4008fda2cb9854c383c714ccfec3133edf22263fe0Virustotal results 52.83% Heodo
2020-10-223652267487.docdoc 2e45410e293f870df9a2729fd8d3e0aabac8b6aa79365b502a849f90ccb67b67Virustotal results 45.16%Heodo
2020-10-22REP_75109150.docdoc 1a6ddadc772f06b99c0286b4d3d96639582499d811601fa4b402619a7ffa4c80Virustotal results 50.00%Heodo
2020-10-22FV5401232045LC.docdoc 69246d46d3c893a3ee3740f371c6d72698daa05ba77e3dd8a2c9a4aaaf86aab7Virustotal results 46.67%Heodo
2020-10-22Y4EKU3G3.docdoc 220e3645890122715ff1e995b86a7d014cfce7e53b2576e862d9c686c7fcf553Virustotal results 46.77%Heodo
2020-10-22FILE_GI6620270526VB.docdoc 7ed0141f0a2a5f88f9be5418ff02a2fcc1e18b7a11d58fb68581b21b99b5eba0n/aHeodo
2020-10-22INV_29756124262789802054738.docdoc 7eaf0df9dd2a33ee958384a9472366f58f1c0a204360efea6a7f8b0d298560d0Virustotal results 45.00%Heodo
2020-10-2246SMV1DUG0OM58.docdoc c41bcade49f3e2413b5d95ce09c2ecf30c21b43ab6b306206b9b737f1cd10450Virustotal results 42.62%Heodo
2020-10-22INV_114736774588040.docdoc 6bc2d7d48d9f0085333ac13895043ae58da0bf60848ae38c3733a470ab313643Virustotal results 45.90%Heodo
2020-10-22LIZ_100120_HWJ_102220.docdoc e1ae8430f64735e0c767276e1e57632257e7aa36f38cd6515b43e92bcd95dbd4Virustotal results 44.26%Heodo
2020-10-22PO_10222020EX.docdoc a0ac35ec0ee3a97f79ecb953f29c1dca13fa5661a5df78ba82012b16c5b291d4Virustotal results 47.17%Heodo
2020-10-22FILE_5Y364SNIAI.docdoc 5e6f9a748268113d3da7867313c0be3f5891553c5690a01354fbbee0d530a136Virustotal results 45.16%Heodo
2020-10-22FILE_094727045025323129140.docdoc b39c953e5621fd7b9af004e2d9195a7a37f9070b736007d74635c5d36d6ccd04Virustotal results 42.37%Heodo
2020-10-22080673737288317982.docdoc b6055d889e7ac86545888a5da746c4c231ead0afc40a036c3927188e99d7ae9aVirustotal results 43.33%Heodo
2020-10-22DOC_4BN8EEXIJ3A.docdoc 8d3f3a330ef15519bfb2e3f71de5f5893e321a5e1f09e7f0a7459bb2f27559ccVirustotal results 45.00%Heodo
2020-10-22L_SC1D0BFBYJUWM.docdoc c0936a09ea5471f2231fa2a66fff1dbb1c8f42f2a37d63e01ea45b4d40682d4eVirustotal results 45.16%Heodo
2020-10-22INV_UE8908583585WA.docdoc 39f8421b6ac7a025203dfb27d7b193171c2b08644ff2d4521672875356541571n/aHeodo
2020-10-22O_JOKBLXKZ.docdoc 0183b5d51eda544d62b1cd8c412328d860d3f567131825824900cc45936aa78dn/aHeodo
2020-10-22X_ZOB_100120_CIN_102220.docdoc 0da81935024d0599fd8d9347b3b1cd7d1c3224a851735ee92224a3f2cfe007ddVirustotal results 43.55%Heodo
2020-10-22OK3886047206SN.docdoc d810adecb2a17cc42025465a49799119896605f16af88bb79a6342746b7cd8d8n/aHeodo
2020-10-22DOC_RUM_100120_QSP_102220.docdoc 1d2531f558d817649eb30142108364e3d3716712a0e17d4bf033d4b3013fc7c5Virustotal results 50.00%Heodo
2020-10-22GW4748609946XQ.docdoc 0d59d407c6fca62823b5b9e4eacce7270e5b98640aa37b1852d5c298805319ddVirustotal results 48.33%Heodo
2020-10-22REP_61595193.docdoc f00791295a21f7fea2b5a3fc6f14be08b6182388080f8e0666bc87ef8201a362Virustotal results 48.28%Heodo
2020-10-22DOC_0404416847834356.docdoc ef3eda0a0ce827c44632df7b430f082bf54965ce02293734e942776bbfd2b1fcVirustotal results 49.06%Heodo
2020-10-22JBO_100120_KRI_102220.docdoc 056f25e8944119ad3d9d651d77cc32cef6621c5cb3498b47161738be7aff416eVirustotal results 49.06%Heodo
2020-10-22FILE_167939653453935528211820.docdoc 24ca326ece108e2ec02346c32536bd5cd2a990364f8d8c9fa35b082ba4a68f2fVirustotal results 46.15%Heodo
2020-10-22535611839142.docdoc 884d55db64ae38575a793fcfaf4f07a6b4f67a7ee84374571189cc4bdb485608Virustotal results 44.23%Heodo
2020-10-22BAL_86190529.docdoc 2622c411514e2ebeb404ff72a11abb8b36da194d0f09dcc95869802a01cf4a20Virustotal results 46.67%Heodo
2020-10-22PO_10222020EX.docdoc 26675160f52f90a778a8e6489be6b67a6982742a192595c69b9d87e49e11cbf9Virustotal results 48.08%Heodo
2020-10-22691220888806.docdoc 29747a11e9ffbd0668f9b880137f1051a27677c4f3bf0a17ead5299fb5857946Virustotal results 46.15%Heodo
2020-10-22FM_YJM_100120_OSY_102220.docdoc 7a9d24e23c3cd1701c2de8826db43aa1dc7d2b73c6c4fd50f491276725a2ad4bVirustotal results 46.77%Heodo
2020-10-22I_38870768.docdoc bffe543ff321cb95dc82dc8c8a96c283d019176537290a63c6bc86d7ae98fe57n/aHeodo
2020-10-22INV_4381206415315480085.docdoc a087c45b5ed8a1c9d91f0b920d6f2510bd5d82d3813af9653757607709da9d87Virustotal results 45.00%Heodo
2020-10-2230110525.docdoc 95c62759d32e2a426433130be7fc1c17a3d3787359258f3af33f61760463eeeeVirustotal results 43.40%Heodo
2020-10-22DOC_O1QG5BJX2W2TP73T.docdoc 476b69835ad34811317226c4b0d9c78525fbb9770f4dc6c649da167a65359582Virustotal results 40.38%Heodo
2020-10-216RN329K.docdoc 3af63f662ad3afb788f4f65538788a97811e2a45d869bf83d5ac6dfa9a2251e7n/aHeodo
2020-10-21FILE_ODVXEM10ZI4B9EU.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 41.51%Heodo
2020-10-21BAL_PO_10212020EX.docdoc b730b36a22a6d6da4bf394e59e3bdb0a0bc32a3adc8fea6f568a58b926a7fdc4n/aHeodo
2020-10-21FILE_YYM_100120_LLM_102120.docdoc 3edf85ed613cb1c778b32fa1ff5aea9553de2e9e8224d5cd868eca8863b67ff8n/aHeodo
2020-10-21FILE_4627787081.docdoc 9ccbbb119271b882bcd53559aa7e60487f0a7ce757b9b4fb1b51b691142dd35en/aHeodo
2020-10-21RM9724033888GP.docdoc ee8ef9beac4202e018577996e293215dd2cc1e260bca0ac0a38f9abcdcd4fa2dVirustotal results 33.96%Heodo
2020-10-21INV_ZWB_100120_FCP_102120.docdoc cb128eb8a7e2118942b9dc0b429a21c8aa057dac01473ad072f487d02cc80849Virustotal results 33.33%Heodo
2020-10-21REP_18087551.docdoc a22de608c25a6a0dec4ca2749b1a1048b8351177b5195780f85baaee421ce713Virustotal results 34.62%Heodo
2020-10-21SE7DMCAU.docdoc 2613c4d78a8daef9a9fc119072017d73ea4651234942d2d2c57683baae0e86d3n/aHeodo
2020-10-21DOC_45014983.docdoc 0ef3eb571df8fcaa4ad2f23f3daabf1bcbc17ee41a42913f623eaaf788f5e04cn/aHeodo
2020-10-21OMGC_MQH_100120_YMT_102120.docdoc aad3348c28dbb9e0a038508e8fde9f2771e550228320b8ebc0f6cf1d11c39945n/aHeodo
2020-10-21BAL_W9UZSPJ2D6QJPEND.docdoc f93730c27fbb9a6c6cc64e5f4d9127854a0c11d165e699569dd0828ebee3ec4bn/aHeodo
2020-10-21DOC_79575999.docdoc c9005b11db864adc5c5393451fc9bb77fc67fab38c00ad806790a4ac7245c80aVirustotal results 27.42%Heodo
2020-10-21FZ_30424551.docdoc d6edabb30c96ad35f08d16e274d639b6a5a5208e7b35167d56392a44b3842599Virustotal results 26.23%Heodo
2020-10-21N4XRUAJDC.docdoc eecb224f52b8de54b58ba589efb3044d6c88f70246ec6dd1c134b186d1d8c388n/aHeodo
2020-10-21Q_28761543.docdoc 71e55ad14abd213d5627b65f8f045b2c9337c629a556868c692376c331d9fa58n/aHeodo
2020-10-21FILE_NN8301791522BE.docdoc 345865d30681e3e80a301984ee82920018dba62cbbade4673c33cc2a0aa9555fn/aHeodo
2020-10-21INV_XUF_100120_EGE_102120.docdoc b7269623a45db722954c9aa554be08c14fb9b6cad622331bb2d5c35e17ca9be9Virustotal results 50.00%Heodo
2020-10-21JK8332992984BU.docdoc 71c25e3712abdd3d405b0a43f2819fb51d16dd9bf3c5fd5c9ecd04b028240533Virustotal results 47.54%Heodo
2020-10-21BAL_029202347501738272.docdoc 988037ab30e7fefdcaff766f160658d982522969787c02fddfd09ce912573dc1n/aHeodo
2020-10-21REP_BL0877229699DS.docdoc 5b78a4ef32efd6eba54e53df8b14092631d475f672d60774c26f20dbe0ed5f7fVirustotal results 50.00%Heodo
2020-10-2136887412.docdoc 7bb0c64469d6f91a86db62a275cfbfa0b6bbf04e10bde77f507649c0adbd844an/aHeodo
2020-10-21H_90640279.docdoc b886042bae6dcbb3ff1e2343630f7c873d2fedbc6b59147c40346b16f69c8603n/aHeodo
2020-10-2140IMBDH8.docdoc 1c69c8db95ce9e60d2cd1b61601b96a3a5bca68602f2da10fb5cbcfd2e354401Virustotal results 54.72%Heodo
2020-10-21REP_WLJ_100120_JPF_102120.docdoc 85a0100950655dd48b3789ac075bbca0e9b4d1ba0e1a4fbc29ee363cc23da4f9Virustotal results 50.00%Heodo