URLhaus Database

You are currently viewing the URLhaus database entry for http://hkq.cfc.myftpupload.com/macos-catalina/esp/xEF2YuN5JSYtUnM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:756464
URL: http://hkq.cfc.myftpupload.com/macos-catalina/esp/xEF2YuN5JSYtUnM/
URL Status:Offline
Host: hkq.cfc.myftpupload.com
Date added:2020-10-27 13:33:05 UTC
Last online:2021-04-20 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003037240 created on 2020-10-27 13:34:05 UTC)
Takedown time:5 months, 25 days, 6 hours, 10 minutes Bad (down since 2021-04-20 19:44:47 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Attachment 2020_10_29 CB262064.docdoc 741375b07ac32d524e8c607b3eeade5bf05677b047fed42c812d758f46b10238Virustotal results 17.46%Heodo
2020-10-297739_20201029_TQS503.docdoc dfaa310d7bc496dfbf4e407c13620aee429e24721f9c6c41ee196236b1e6c2a4Virustotal results 15.87%Heodo
2020-10-29FILE_O6267.docdoc c7b60462b094969cc54492ec3824b410137c8b1bddd14d17c4ef64c0dce0c732Virustotal results 16.39%Heodo
2020-10-29Untitled-2020_10_29-M19173.docdoc a81de1a517280ac81b774eb0c3d3d66417d07545cb7f2ef11fafbce7157ddc8aVirustotal results 16.39%Heodo
2020-10-29Arc_2020_10_29_4075.docdoc fe2ba175ef90b019459e5cb17088fa708dea90a40fbe39c65a9d2660cf620611Virustotal results 16.13%Heodo
2020-10-29rep.docdoc b0b000035a31dee6844e0f9a9cdb5406980772a554e4a525da220a492fb1c493n/aHeodo
2020-10-29file-20201029-3448.docdoc 91a490e604cc0d21d413e2703d55b707c09c9c8df43f2bfca033ac6bbe1a4672Virustotal results 15.87%Heodo
2020-10-29Inf-2020_10_29-O5263.docdoc 94e08e3932fdbf68dce59492d22219b9afc8c0effe79517e9d9ea943a40b369aVirustotal results 38.71%Heodo
2020-10-29Attachment_O978.docdoc 2bf0cc9160a59f450f45c68f45679d8333b8149e30c04c74d20be56db019f884Virustotal results 38.71%Heodo
2020-10-29inf.docdoc d06c24a09106daa1032a15c8cff9c4eb399881b463ccefee9a51744197fed53cVirustotal results 38.10%Heodo
2020-10-29Inf-UZ2741.docdoc cb164bd1cfa7c79b3d8040057da0737477aebfc35236cb707bcfa845e3f30c88Virustotal results 38.10%Heodo
2020-10-29Inf.docdoc bb9b42355cd9c3b2448099c344e24ceab8f54de4c5e7f3e68ee997dc8e1bc678Virustotal results 38.10%Heodo
2020-10-29FILE-2020_10_29-68184.docdoc 41ad376a9521ae341bd5a60e9084150f0745b92fb26a5b44001e11579d180316n/aHeodo
2020-10-29Untitled-20201029-SFN17196.docdoc 29069c8ef4147aa42ee5cc01d2dcc4f0a5dd6d8116c4122852845a08f2e5fea2Virustotal results 35.48%Heodo
2020-10-294215UWC-IJX992908.docdoc f63abb92cdab9a6112967307f4ceafcdb39955c0ef4d4097054083b579f9e5ccVirustotal results 36.51%Heodo
2020-10-29Untitled 2020_10_29 I86829.docdoc 43ac0bbd19c8d0a845fa3ca8b23e7f2fe7c7acb071a288271ad08b3cbc9ed06en/aHeodo
2020-10-29356_20201029_X146.docdoc abe172e01e4ff35ab6b4a16222119b738b325ef9ad809f4ea9bb1c7c4e7b41cdn/aHeodo
2020-10-29inf-2020_10_29-V780044.docdoc b13effbff490d9ec0a85c36b8c02f2bfb17aacf39691fbf4d98839b32fabf044n/aHeodo
2020-10-29Doc 2020_10_29 F266748.docdoc 230145518bd1bee6679f4ebc0546c94c0e1b45c47e78117a0e523ada0cf39ac5Virustotal results 33.87%Heodo
2020-10-29mes.docdoc 01832091bf1c1ecee3623274c0a9d173d305fb1b0f1059cafa86eab41961f498Virustotal results 33.33%Heodo
2020-10-29Arc 2020_10_29.docdoc 337de8e0e40177373bdf5f53078961535f04a362d6d512a15bd5c33ef6fa9572Virustotal results 33.87%Heodo
2020-10-29rep.docdoc d14723eb50af0341b72c28a3c747940042ecd0795e40dd42a5a85ab0ac49ba7fVirustotal results 27.42%Heodo
2020-10-29arc-015145.docdoc 947359baeda91df2475d551cd36248ccbc371bfab378fba634176d4fe1bc46c6Virustotal results 27.87%Heodo
2020-10-29Mes_2020_10_29_5344071.docdoc 5cbb14d1979b0259be5131e9d92da0ea63751d263e0db5d2e3ddde47a74771c8Virustotal results 25.40%Heodo
2020-10-29FILE 20201029 73773.docdoc 697d945ff47046f421017a4ececab19494f8ec8b9d59abc54fd159fdaf1bfcafVirustotal results 25.40%Heodo
2020-10-29ARC-20201029-DBC547.docdoc 215045feff7312ea56f5ce12972479d6fa0800225844ecaac492114804cea962Virustotal results 25.40%Heodo
2020-10-29dat_20201029_PJZ735.docdoc f49637e7159ed3b8f29519c003193985c2d5de0638a9386d637a2e62a8910160Virustotal results 25.40%Heodo
2020-10-28NKT39563-2020_10_29-N7128.docdoc 72c9c4d03ba8a5fc0ac23ada5fd271b8277b95f3ff49f0bd8b7977ecc23fbc2bVirustotal results 26.98%Heodo
2020-10-28Rep 2020_10_29 D07767.docdoc 5c91b9dff81808ba1ba3d21fa9c6ec57d09922af1cfd7ae5d06aef031eee5f11Virustotal results 25.81%Heodo
2020-10-28file-20201029-A191347.docdoc 48a76d85d2eb93ee3fa58f3b1ef6a80e17e824cef265353c9cb804874809063aVirustotal results 25.40%Heodo
2020-10-28inf_20201029.docdoc a5371e1aeb4a9cd992cb7701ead18e8443fbb575c273b54e83507e7c1ac5d9aan/aHeodo
2020-10-28W58216_2020_10_29_321.docdoc 7b186e0ad6e521be2f711bf336ff752300505614522e0cd7b2865e6c3cffc611Virustotal results 23.81%Heodo
2020-10-28Attachment_20201029_IDW7748.docdoc 6f0669385903d245dbc1e82d3a1789986d819bd5a754c3bcec91c29e9ad561d0n/a Heodo
2020-10-28List OKN57588.docdoc 45b34d3ea4ae8a23f30f20ae157a3860942a0185a3f8132ce4b474da2f862997Virustotal results 23.81%Heodo
2020-10-28list_NI2494.docdoc 63e7ee325c79ea137e6cf1af5f7b56ef6767d20edf1d67283a46f0ec1dac902dVirustotal results 23.81%Heodo
2020-10-286912A X8042.docdoc 85679073310e9e6b9f5e274084e661d4947f4c5ab7042d40b9a204ba09447799Virustotal results 23.81%Heodo
2020-10-28Rep_TVB740883.docdoc 694b0629f5e0d7e62b4b5c15c4e49ff1be51d9f8e6a8657dca67e6d1df1e0f85n/aHeodo
2020-10-28dat-20201028-G1273.docdoc 8ec484a33a9d6faa812349834788233eb6831589c4190ec8431302da9c9e0757Virustotal results 20.63%Heodo
2020-10-28Attachment-20201028-6966004.docdoc 85ad457a5bd19613875e65795b24342005a7b91bf3d1a5e56d20b20de7488882Virustotal results 16.67%Heodo
2020-10-28rep_2020_10_28_MK9575.docdoc c79e3e3eb444ac8d43384bf99c4cbd5b8ab94eb831bec3bb2eddef59dbe7b9can/aHeodo
2020-10-2827515-2020_10_28-HUH72845.docdoc 48a6948505d42f70d05ebe07c311c91dd6ade0cd6ff091c0fae441e82ae57126n/aHeodo
2020-10-28LIST HQ237068.docdoc 3fb10a7eeb13516354cf1e4f1aad7f811ab0eccc9bbf89a06d81f2ee11d1c7d2Virustotal results 15.87%Heodo
2020-10-28inf-2020_10_28-T9726.docdoc c52d7a70e6ae1edec10a02951f1668f6442e8837619245733d206aa4f669bb2fVirustotal results 15.87%Heodo
2020-10-28List_2020_10_28_QXQ239270.docdoc a79f95cacb9da773665d3ec11e7d3b4f578df040ed73e5f5d7df33dab159554bVirustotal results 16.39%Heodo
2020-10-28820X-2020_10_28.docdoc 996ee4dd4b97188a5f14ce28fc3f8752d151af3647abd9e2fe7363e36ee79501Virustotal results 15.00%Heodo
2020-10-28List-675001.docdoc f98113f3bb223fabcb8f2c799d49abbef50eee542d323aae513a4fd656da82b0Virustotal results 15.00% Heodo
2020-10-28list 2020_10_28 573718.docdoc 1982b6c4036286ba47a27de309abefb7b8e542dafc43448ef6437f504191143cVirustotal results 15.25%Heodo
2020-10-28MES ZR337673.docdoc 5889f2806952698235cfc4c29fcaec44f4f9bf6aab0dac87de568fc928e6665cn/aHeodo
2020-10-28INF_0658.docdoc 0df95b70e69d52ea4e8a54b239aa9f4cebad05bb3536cca32668c7a6bc7c0e26Virustotal results 16.13%Heodo
2020-10-28Attachment_20201028_8025.docdoc e7685f0f198129a74f92f5da4d49f1dfbc7d8e726c2ad293428a757a0c2dda86n/aHeodo
2020-10-28Attachments_ET1223.docdoc 2ce0b1b64893c2e1bc8708ef881ff4d10eecb5ca1599b25d67e7f20f9cf64eb8n/aHeodo
2020-10-28696 91393.docdoc 0a2dc11d95176b9aaf5668ba60308fb823187e808fb7955b9483459e7dcb7dacVirustotal results 16.13%Heodo
2020-10-28rep-P78176.docdoc 6e65227ec6f8979158ed3addae68568e01a0bfcd2bb560b92f218e8088a7c673n/aHeodo
2020-10-288969636-2020_10_28-SU8597.docdoc d67bac7dbe75fbb08f68108c847dd12d7061acf4ffb725a8bb61e0fe86f9432bn/aHeodo
2020-10-28list-2020_10_28-C887.docdoc 4084fc01c1a72055687aaf0bebff502ef0bb4d432e65078fa5c4b512d7e9c4adn/aHeodo
2020-10-28Mes_20201028_B960.docdoc 20e74d670b10c22727bc37f9737fef25a0acfaff19fe44e4c0f59870f26be78dn/aHeodo
2020-10-28Attachment-DTS871588.docdoc adfcee369d6a4cff14f1f2a6ca1752f5f16fe83441efb74cc04b1fb667e64466n/aHeodo
2020-10-28rep 20201028 44564.docdoc ae3d650ba24dd80404c0a514f6455bb2a56e61df533ef1704cab33e46f41b1cbn/aHeodo
2020-10-28File_2020_10_28_FZD611.docdoc 549b6cebe4a821e1019fba53aa24e7cb51005f71242739907087af25f66a6862n/aHeodo
2020-10-28UNTITLED-1073.docdoc ae14a8bfd6863ef8c39e36774089e581aaed45e5e6cf5af493f18e676c4e6bd4Virustotal results 34.92%Heodo
2020-10-28rep 4708.docdoc 64d7efdecef43694730a5897dabc0766eaa60bee01d0757a4299184973476978n/aHeodo
2020-10-28DAT_20201028_46951.docdoc cce46e9e2d57327823f9114470df8550c4685dd3c3a5c39c6e637f67e108ef47n/aHeodo
2020-10-28Doc-LCN607514.docdoc 09ab13ed5cc26d51e726e1121895e9887d1d2b3ac02edc6e7d86c73ada3ecf40n/aHeodo
2020-10-28FILE_20201028_R562.docdoc 7d34fa4b3159340dc6f389fd81167fb0340e0ff28f65e1e4fbe7ab9da3b7b257n/aHeodo
2020-10-28DAT-2020_10_28-RE483875.docdoc d3d10de392c0d61043b5786332ff0e306072886898429cd0f8285e76ec019daen/a Heodo
2020-10-28Mes_B720059.docdoc fbb671ae1f53d8726d9bf7afbec7fce69952163f4ffbe17de732c67b2cc2a527n/aHeodo
2020-10-28LIST-2020_10_28.docdoc 19f448d50c5d4bfed24bcf4dd99c326f1225218e444a97b16594a179bcfd5156n/aHeodo
2020-10-28Dat 20201028 AZ418.docdoc 0a5c124b976df79f06f8502dd41b406d6a78ea861e4c31c4a390af5910c334ecn/aHeodo
2020-10-28INF-BHO631.docdoc 2cf3d4913e94c3a564e5c9e16a395ed68e8d693a91818fbe5f2fed1a86ce6b0fn/aHeodo
2020-10-28List-2020_10_28-OO43874.docdoc 04909a18166b609c0d5997946e9b397d0528ce9625f78c578d8d704a0606bba8n/aHeodo
2020-10-28Attachment 45869.docdoc 5ba6a0db5fe221f32f4a9cd85cf69ab066cc4f6186d6e93b5669571a32a35d7an/aHeodo
2020-10-28Rep.docdoc 8f50a7d1ae60fe1c94ec624726fee868a40beca07e5ac1c34fe710a78f5edbbdn/aHeodo
2020-10-28Mes 2020_10_28 7774796.docdoc 10c403fa94671432962dcf60d4e7facf2e4a9cd2c44964a9b16e6e79cc2625c5n/aHeodo
2020-10-28LIST-20201028-GZ39819.docdoc e549afaef9205d532d55d91cec38651852e85a6cb0bfbfc07904a59f1a6b211cn/aHeodo
2020-10-28XV245-20201028.docdoc 6bf49682da7e06dc378e14693f4dcb29147a7f29c73fe4b3206b979058af6b2bn/aHeodo
2020-10-28List_20201028_OO52765.docdoc e0149996d56095e6d280019c91eed5f60a27662ccbe25de1397e115c0cca4c65n/aHeodo
2020-10-28Mes_NOM6914.docdoc 24ebcf996471396b752396e9fca71feaab4a6f384f7691b5932cf939f570beb1n/aHeodo
2020-10-28MES 20201028 AAC759.docdoc bdfdd232b2595883bee70d5bc1310e4eda72350e0c92f7ad4ec6c7bd9a1e5761n/aHeodo
2020-10-28Doc_20201028.docdoc 0b56d0c16488f468ecee2ca5cd49ad5641fc26dab54e1e9103e23d8602c51d90n/aHeodo
2020-10-28Rep_20201028_061.docdoc 8c04391d0a311e35b7ab76044cd603cb29ce05a6c9f47f45a377b2fc6b057d25n/aHeodo
2020-10-28Mes-20201028.docdoc f3f544d1ebc8663d6d4d375f2fd7e749d0b34bfb3aeca33e3ce7c598f5748f3an/aHeodo
2020-10-28arc-054.docdoc 8480e663d0a058194b6a6eb9701872e426d2039988a82de35c226dd13cf012fcn/aHeodo
2020-10-28UNTITLED-6346.docdoc 64cca5b412d07f17478431d16e387f38db07bed63b22f8e625c7168872cb9f78n/aHeodo
2020-10-28Arc 2020_10_28 60779.docdoc 82b14aaf54efd2412c88df5b304fd6653cb8be0233060953772fe068c64e25aan/aHeodo
2020-10-28Attachment.docdoc c09da99f44d060cc07412d7cd8f81d184f0530fe7a5b2e0e4e32e5e1be74fb5dn/aHeodo
2020-10-28doc 2020_10_28 OV0396.docdoc b47dae8872a527763b24b949b05d357135e54543476daab85347b85e021ce6d9n/aHeodo
2020-10-28Inf-2020_10_28-UDW392.docdoc 52d21414a206f853f6469fd112297a132aa6ff3dcca6b0a710e9cf642ecc1ad7n/aHeodo
2020-10-28rep-2020_10_28-MT322645.docdoc e319da870bd1d43344153ca31e8af91a4dbb0044cc3cbd2638189c655daa3e3aVirustotal results 30.77%Heodo
2020-10-28FILE_2020_10_28_87509.docdoc 49a9e653ecfad6200a5b9bfc90ca6a9c749b95aeb2fbe0ec38d2842b1de797a5Virustotal results 31.15%Heodo
2020-10-28INF_20201028_KCW0266.docdoc df9332b5df7d249baa672ecc8ba2c26f5bcd43c25319c9ad09028aa389b5c31an/aHeodo
2020-10-28doc_20201028_6947.docdoc f1ae5f1b0254e4e6517e7e89de3a1a57b7666e9f931daa590b757fb3fb105727n/aHeodo
2020-10-28INF_J4756.docdoc 7862369f401d84f41b94003a00d8fe6b36e51c435f35a8e996138a0f52fa1893Virustotal results 27.42%Heodo
2020-10-28Attachments-20201028.docdoc c430d5a21c9bd894ee7f7adad674ea7a0ec0520df916938568284c655ecb2c8an/aHeodo
2020-10-28file 20201028 UWK918663.docdoc a1e19706a93e53e657ae474f58a7e0e0d452d2f95a832d25464a5e7509624aa8n/aHeodo
2020-10-28DAT-X953640.docdoc 487e0a9b22ce11dec5c86491870bc84438e44e35382527d1b52f657b5695d3bcn/aHeodo
2020-10-28265546 59198.docdoc f30c2007e54b4b981f00a16777f3bd4fcf535414cac34748a3b2916f4dd19efan/aHeodo
2020-10-28Doc 2020_10_28 973574.docdoc 7e04c986b4db0e23baaf1d60b136a6c899833dc934d309596ea62bc4e460eb46n/aHeodo
2020-10-27List 4475.docdoc 13dc41a09ac500a00ec0a4a9843017260672fdaaed428508c6307ff3341c3e95n/aHeodo
2020-10-27List-G55383.docdoc 26eead61c6edbde1e06d00ecf89571be284ba247df2081239f5bcb0632b4c1dfVirustotal results 29.63%Heodo
2020-10-27REP_PEV947946.docdoc 0de43abd8d4f8877ff865f52486cf10fdc2c9c8c627562969e32f6b00ebb36f5n/aHeodo
2020-10-278024492_9485285.docdoc a7b5befccf3dd1276a60f1cea3f930219e35aa634b378b23b57772f480d9fe2cn/aHeodo
2020-10-27REP-JVM93076.docdoc dc195bb810b63c35c74cc0cdd8690cff533be0b29da2a5e568c8a03d6b3bc05en/aHeodo
2020-10-27File-2020_10_28-19716.docdoc 3fa27d7f4524a8efda23661cbe385cc37dd53fffd927b87e29934aec025d9e35n/aHeodo
2020-10-27Dat-XDO163.docdoc 414730c09b8914aad74e763d7ccacbfe96361572d2f1c53fd6210f913dc96549n/aHeodo
2020-10-27Inf_20201028_F05175.docdoc 2c0e571af9551f882e0f962c19799154fd0e9d82e9c8876d726a11f50cbc9676n/aHeodo
2020-10-27dat-20201027-193019.docdoc fdc02372ac6d7b4a8701285360493b05002f7036df6d3fec2cde93f7e8a5de75n/aHeodo
2020-10-27Dat_2020_10_27_1637108.docdoc 885bd0f67afc277e86935a0d40269d5acda103ce69562edb2a8992ec925aee8bn/aHeodo
2020-10-27inf-20201027.docdoc 184d6bd17c2c32f50ae4f311c26b22cb61fc712a10c74c8e57a3063afcc8a7c5n/a Heodo
2020-10-2735928-20201027-4148.docdoc 65ca688afc9a4a3542b3f24aec0d15a23d4ff309adc0aec528c289ed1630fee2n/aHeodo
2020-10-27Dat_20201027_AGT815.docdoc e8b19723225167f1b831cdfd075a80a02537306d5d73af68da53d7dd4fd27229Virustotal results 19.05%Heodo
2020-10-27UNTITLED 20201027 L62848.docdoc 7361bce55fc9bf2abccce87123c812bf499278023d0b206d6ea656a87bf3d592n/aHeodo
2020-10-27arc-JCF366.docdoc 3828bfd5ab72ffa3e34833003ec5565eb8b92cc72b5212e997c13a693de018a8n/aHeodo
2020-10-27Doc_2020_10_27_91531.docdoc c760fe45f26d328ded7cc3fac92ee701e551cfc11a4c2b0cbde98423f6097dafn/aHeodo
2020-10-27Doc_2020_10_27_2018.docdoc 95d6502baed7604d8057c1835f59629605748e13e17f51a8bb9a35dd55655feen/aHeodo
2020-10-27list_2020_10_27_264486.docdoc 930b2c650c02155d23102b7f5af7341f24dfc1f37c40d1eb601a7472af87d28en/aHeodo
2020-10-27Inf 2020_10_27 0763.docdoc 789c0d57de38535643ee38b0e4fd94e4ff94baae07225e2d2f1e1ca9fc967ecbVirustotal results 33.33%Heodo
2020-10-27MES_20201027.docdoc 9addd2e4077d5a7c24bccc8a9108404f079a61f851615ab2e65deeeece42e424Virustotal results 34.43%Heodo
2020-10-27doc-20201027-246.docdoc de9ed45fc90ae166716a1703044069bea57d72376086f43b0711dd7b35ffa18aVirustotal results 34.43%Heodo
2020-10-27List-2020_10_27-FM200251.docdoc c7e578b275cae29568c0c3a7f31f1d7a6c9b1ef5b9e089876954d5df9dc492d5n/aHeodo
2020-10-27Arc-20201027.docdoc 56ea3d5db4eb0c842f6ffd51d225f3b420ba1187a6b8f7bc15bf333953b750e0n/aHeodo
2020-10-27mes_SZB457526.docdoc 541f859ac32cad287b78d2c974c701bfdc423e364b1887d596e0a65b33de30a5n/aHeodo
2020-10-27Arc 20201027 IU988.docdoc 2ad662e1db9cd5ee82d67c7da8cc2de482e5908653e148702fb4e3b02bab42edn/aHeodo
2020-10-27Rep 2020_10_27 501.docdoc 221bc9397ea64f78461c384b024f93f9361e624c505a870341d0befcabfb614dn/aHeodo
2020-10-27010351_2020_10_27.docdoc d49b0e90fc3a7c0ab23a13938ec39f57656395a2311421dbf72093ef4f790c04n/aHeodo
2020-10-27UNTITLED 20201027 A976377.docdoc 0d4606b5760bfc879d2a19d4015d5bea06657aaeb4c571fcab5de758141b64d5n/a Heodo
2020-10-27ARC 20201027 9375127.docdoc bfed81c8498333359a72fd9e2f2b1caf7b4e83c2088131ff84b67dca661e11b0n/aHeodo
2020-10-27INF-20201027-5376.docdoc 622b70a9335e95bd716b8d4e6cf68bbed4e395c0acdc8a7ff73a9458e77d6c66n/aHeodo
2020-10-27list.docdoc 4c73278d883614e282844bb68b15c9677976ece1bc3f3c2e7e8a7dc909b50705n/a Heodo
2020-10-27Untitled.docdoc 3491d15a4889470e8356f7fa3a7047e89f667488fd1ea5abbff01b401b848338n/aHeodo