URLhaus Database

You are currently viewing the URLhaus database entry for https://arthurrazor.com/css/swift/d3py5w4jz3mq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:734385
URL: https://arthurrazor.com/css/swift/d3py5w4jz3mq/
URL Status:Offline
Host: arthurrazor.com
Date added:2020-10-22 11:53:03 UTC
Last online:2020-11-01 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 11:54:37 UTC to noc{at}krystal[dot]co[dot]uk)
Takedown time:10 days, 6 hours, 46 minutes Bad (down since 2020-11-01 18:41:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22DOC_DRELM4J69JW2IBT.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdn/aHeodo
2020-10-22REP_RWZ_100120_TXL_102220.docdoc 40b52434db8fa8dea7ba146d6436e1cbdc7f4222cb63923387f11b941912e31fVirustotal results 40.74% Heodo
2020-10-22QJU_100120_VOF_102220.docdoc a479d5df4923cf3d9c170aa218de43da798baeda6247d5f044fe539826c58cdeVirustotal results 39.62%Heodo
2020-10-22INV_BN1271397506VT.docdoc 1fe29e28174521c55bb6e73db876f3e783ba9eb0905a51be0d2ee6254bb903e4n/a Heodo
2020-10-22L_3236912024443225990.docdoc b1dd253ade315392024f0586eb829a5317cbaff4c8428276b58a1566ed9db173Virustotal results 40.74%Heodo
2020-10-22DOC_QAG_100120_YUD_102220.docdoc e3cd7451ef720df2cbc18258725e7d4e5b881f0ab970b5d1f9343c1d9754d2acVirustotal results 39.62%Heodo
2020-10-22R_PGO_100120_VJQ_102220.docdoc 937c87496e98fe97075f0ae5ec35a64a75cc04b533f0a1a937d8a50096183519Virustotal results 41.94%Heodo
2020-10-22021810014171284.docdoc c4d6c72ac1f2925c2af592fd65e1bbdfd5327d959321403faf797ec85d658a6fVirustotal results 41.94%Heodo
2020-10-22REP_359976621070401292218.docdoc f363c98ddbab25e6cd5cf325704c8a4fab2dab557a3a263c4416f0b580127b89n/aHeodo
2020-10-22AFVO_04187288.docdoc 6e73ed5041166e3aa6f7ce070efab391259a868771d35fa7f6b8aa64d8a3065fVirustotal results 37.04%Heodo
2020-10-221235875507159294011991.docdoc 44be59f199c5d2d4d0dcfef847d9e611abcaab3d8223b63fcbfe9a5d3c6745d5n/aHeodo
2020-10-22PO_10222020EX.docdoc 6c1a970155c3756aaddd02ef3f1e5f266292a97f661fada4a11011b3eb8795c2Virustotal results 40.98%Heodo
2020-10-22FILE_07295585.docdoc 7a2e6cd2e23620e7dd3ac4811e5b79b7532fb6d910e96109e46bd47b0b4b5c2bn/aHeodo
2020-10-22REP_1L5XMBAG.docdoc 253503dd210f77e068fa385be863442f8c65307dda3743925de307f93d4e7fbaVirustotal results 55.93%Heodo
2020-10-22PO_10222020EX.docdoc aea5323b8ec31304c294e8225cddefa8aa8a5df30873dc0b5af266062972583fn/aHeodo
2020-10-223652267487.docdoc 2e45410e293f870df9a2729fd8d3e0aabac8b6aa79365b502a849f90ccb67b67Virustotal results 45.16%Heodo
2020-10-22BAL_PO_10222020EX.docdoc 864d0a9fffea983ef2c1137ddb09a42b8bb880017d0359af9c5758b250bcca9fn/aHeodo
2020-10-22FV5401232045LC.docdoc 69246d46d3c893a3ee3740f371c6d72698daa05ba77e3dd8a2c9a4aaaf86aab7Virustotal results 46.67%Heodo
2020-10-22VX9734147605ET.docdoc ae5168eab14a38621615d44a35ff6af0052fabf8af421ef2c66f783169b808e8Virustotal results 46.77%Heodo
2020-10-22D_87813772.docdoc 7eaf0df9dd2a33ee958384a9472366f58f1c0a204360efea6a7f8b0d298560d0Virustotal results 44.23%Heodo
2020-10-22PO_10222020EX.docdoc 20b2c39a7931947aa8713534876868f8dd24851c50b934069b2b151661bb2f72Virustotal results 39.29%Heodo