URLhaus Database

You are currently viewing the URLhaus database entry for http://masque.es/stat/payment/qru9xmffmw9ouwrao3m8avsq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:731156
URL: http://masque.es/stat/payment/qru9xmffmw9ouwrao3m8avsq/
URL Status:Offline
Host: masque.es
Date added:2020-10-21 21:18:04 UTC
Last online:2020-10-22 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 21:20:25 UTC to abuse{at}arsys[dot]es)
Takedown time:9 hours, 59 minutes Good (down since 2020-10-22 07:19:37 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22BAL_ERW_100120_WKY_102220.docdoc 41206210b4b572edaab337c11752cdae50e5356ad52b67f276f1a0d53988d707n/aHeodo
2020-10-22PO_10222020EX.docdoc 933160e989dc335e391fdfba72751039c4c1c68f1648aa634af269e0e0600ab6Virustotal results 49.06%Heodo
2020-10-22BAL_206873793196229695.docdoc 56126f16e90d28b3bc7e4a1460c71bd6ffb7763f79d17ecc274e8c6988c8531an/aHeodo
2020-10-2293756873.docdoc fe8d90884de697451ea446a5dfd254041d252229a8a17175f11f77486dcdc4d4n/aHeodo
2020-10-2230114980.docdoc 69a856aef533deaa255988eed151b27d0c60edf7e9e3187fe9b5537feede3197n/aHeodo
2020-10-2280565054876368112553.docdoc ef3eda0a0ce827c44632df7b430f082bf54965ce02293734e942776bbfd2b1fcVirustotal results 49.06%Heodo
2020-10-22REP_S8M7E6VRW08QH.docdoc c343246a8b6df26e48dedc87a71762563be3e241ea28994ad1e2d0700b823f8dVirustotal results 46.77%Heodo
2020-10-22REP_99250357.docdoc 775be0a86b7a5d27adf04eb982cbd8f223f06ae88dc5f6a33a26774d707f7bcbVirustotal results 48.21%Heodo
2020-10-224335406895875.docdoc ff7bc571e097d09b02234d6bef98da4468da5c7dfc197e2cb20f1a00eb85f61eVirustotal results 45.90%Heodo
2020-10-22REP_69992867.docdoc 00be3474f86c64b8ed871822ccfe02e7bdcbb4b5132682ee36915e8553952648Virustotal results 45.00%Heodo
2020-10-22DOC_FYM_100120_DRI_102220.docdoc 26675160f52f90a778a8e6489be6b67a6982742a192595c69b9d87e49e11cbf9n/aHeodo
2020-10-22INV_XLI_100120_EKK_102220.docdoc 29747a11e9ffbd0668f9b880137f1051a27677c4f3bf0a17ead5299fb5857946n/aHeodo
2020-10-22BAL_LUR_100120_HHM_102220.docdoc 8cf9bf37fe3de456cee48cd50ac6487278290ce4038eee214389512625297016Virustotal results 47.17%Heodo
2020-10-22BAL_PO_10222020EX.docdoc 9c0aa6a67f05f22e0bf2889fef6bb38dbbc89fa9da70a8b6ac6cfe0b45f3b704n/aHeodo
2020-10-22REP_75546261.docdoc ac34efa35d04bc35c3bc9eb52c130c25c9841995ed37b75e3f9e04d7c2599bb4n/aHeodo
2020-10-22D_PO_10222020EX.docdoc 2da1ed7b630f4a606c6c65a41dc9c852015d64174113023eff5a63c64f5eac0dn/aHeodo
2020-10-21E_77805576.docdoc 3af63f662ad3afb788f4f65538788a97811e2a45d869bf83d5ac6dfa9a2251e7n/aHeodo
2020-10-21FILE_11810730.docdoc 890535144da2084ee8e9431e6521be9719100cc5bec7679a4d7bdce3763a692cVirustotal results 41.51%Heodo