URLhaus Database

You are currently viewing the URLhaus database entry for http://helixtap.com/wp-content/balance/bnfHOJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:756491
URL: http://helixtap.com/wp-content/balance/bnfHOJ/
URL Status:Offline
Host: helixtap.com
Date added:2020-10-27 13:34:11 UTC
Last online:2020-10-28 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 13:34:41 UTC to abuse{at}digitalocean[dot]com)
Takedown time:22 hours, 9 minutes Good (down since 2020-10-28 11:44:02 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28October Invoice.docdoc 753c4521e07dab9a1de57a156021942b8e1019f48da5659b28dedbc848c3d013Virustotal results 17.74% Heodo
2020-10-28INV_235813.docdoc 0b9d0864e1af339c8924de338519f8773111be2d5d0aa9956e910d2bc1b4e1bcn/a Heodo
2020-10-28form.docdoc c156c19120c201216fa1ed0db10ae8afd1c2d5b162e885dc69af1f7024a53cb8n/a Heodo
2020-10-28Form.docdoc dae86e5f6950b75013fc995cadb73abc26cced79c643080cbf10815728971718Virustotal results 15.00% Heodo
2020-10-280327437939.docdoc 32feb7edd391361d09ff5f8c6515c3fd05df572933a78dc033c9fd97a496fc9fn/a Heodo
2020-10-28Payment.docdoc 8825d7209f3d3941021c374a3af3a9e996a6fe548bb4a13782a09ddd75ba5ff1Virustotal results 18.52% Heodo
2020-10-28October Invoice.docdoc 91bebfd44fc5f09905c3f3e2f4bbd772dcd181b4b7983e5ad87db305ba5d7965Virustotal results 16.98% Heodo
2020-10-28invoice.docdoc 69cc19e7c63413a30084ef7dc1158a0ce219c8221e5012d84a3fd56c796fca5eVirustotal results 15.87% Heodo
2020-10-28invoices 25253 & 58803.docdoc f2fd2a7b312555a475a14cbc6a5300a2d7d16bbcb3f8f5409e6d4d9dd4cd0aecn/a Heodo
2020-10-28INV #0033868 FOR PO #00733564273380.docdoc 80c6de9caa8fb29457e799ff74947cf9a28aa5bae84ca015cfbe75b1edb3c93dVirustotal results 15.87% Heodo
2020-10-28Payment status.docdoc 9efe62711778d762d08370193467de5fd1c62cccaf5759890df537fb153a079fVirustotal results 15.87% Heodo
2020-10-28Form.docdoc f08f15cb2246230432ca89a7e2fabc9d2a148a38c67ab6974447a4b3879e8425Virustotal results 18.87% Heodo
2020-10-28M03 invoicing.docdoc d35d4920596ae47da5cad70a58d82cd7857289e6a2721b469dfef372aa439957Virustotal results 41.51% Heodo
2020-10-28Invoice.docdoc 48efe9c614307e94938ac34fe8ef20189a347f4501260415e8365bb2b1149d4bVirustotal results 41.27% Heodo
2020-10-28Copy invoice #73790.docdoc e4a4e6c278d0a2cf660e0d6e8cc8359851c32772b4c9fccf98e2b28c9aab7f44Virustotal results 41.27% Heodo
2020-10-28form.docdoc 138f68878f0c09a4d5a982087da5f57943a8f84e87f9ff80bf9b66949d9bcb02Virustotal results 42.62% Heodo
2020-10-2804211442.docdoc 27a3188058fed1166803e44662278cf2a6215057f984d81925a1586dfadf58b5n/a Heodo
2020-10-28INV #00422136 FOR PO #025117603.docdoc 639f3d1d1a494dcf20b64daa8f46a98affe8b7e708fac26f08a732bf4a03c06aVirustotal results 26.98% Heodo
2020-10-280657478.docdoc 7cdf46cacb08878324d471fc7cec17b333e38c7d76479a164d1115811dccceb8Virustotal results 28.30% Heodo
2020-10-28Inv_3081.docdoc ab8a246400a024e5490c031fe13b4c892da8e1db9687fd937766669b28467255Virustotal results 26.23% Heodo
2020-10-28OT-100120 VETL-102820.docdoc 5fd6570201a29865b41f8da78021803a4db2b28a392a583170a80c5f24d76e8dVirustotal results 29.63% Heodo
2020-10-28Inv. 005507671.docdoc 99c91035c6a269a23e022673bb84e4cb8e8b40909281707212bd9dc4a074c3cfVirustotal results 28.30% Heodo
2020-10-28Inv. 025200528.docdoc 7178e85af3d05ab325a721c502191735ab4bf50b6df622a6a8395d43c887e073Virustotal results 25.00% Heodo
2020-10-28XX-100120 PYMO-102820.docdoc 269ebb02c0552abc38ea7b9e4e0a464ebabbc80035e259af2fa94f1544a3b351Virustotal results 24.59% Heodo
2020-10-28SIF-100120 NPPL-102820.docdoc a1546bd45c31f3d8028e9ed32b37a0394e615efc5a71ea3f36e4696a6a913c56Virustotal results 23.81% Heodo
2020-10-28Invoice #61863.docdoc cefdece809bb4ea44a6ed18923e403e409190c61aebfadc97e7eddc70da59285Virustotal results 28.85% Heodo
2020-10-28005642954534.docdoc a6d4e2b08b8440d239b850df7a27ee5b2269f64f6c898b0b4d04ad6d596d432bVirustotal results 22.58% Heodo
2020-10-28form.docdoc 129235f3355a262045edfd381d264ee669cd0eee9eaca1601a8509dad50ac10aVirustotal results 24.19% Heodo
2020-10-28Inv_34256.docdoc ae7d3ba8461109f291913ce09ca8033736c9fd52d9a2d7b2eab34d844f7dcde2Virustotal results 25.86% Heodo
2020-10-28INV_27455.docdoc 22ff098ed7106067b60086383ec7d4ac8211fec5b7298cb2c7d22bdc05e75b8eVirustotal results 24.19% Heodo
2020-10-27INV_9519.docdoc b35d615da70e3502114b5ba61a1979d6f463f7eb8b0fd6bb17d4da8bd1561646n/a Heodo
2020-10-27INV_12572.docdoc 6695d93e57264079a79dd7fc5155df3df40f82d2a6a78063c99d8617362850c2Virustotal results 27.78% Heodo
2020-10-27INV #027169 FOR PO #108334734.docdoc e2bbf218b2f6bfdef878d35313c3ecc99c6608aa8c7c8f261b59be4a20673f22Virustotal results 26.98% Heodo
2020-10-27Inv_417035.docdoc dae0cc43be550a6d83464a1f5b2ba4ab8dafdaac48c3441bfc941279afd56de1Virustotal results 24.59% Heodo
2020-10-27invoice.docdoc 4955a66e9711e8207f53c9204d68f89903e7aec37f30cbd298ff102bf68f937bVirustotal results 28.85% Heodo
2020-10-27Payment status.docdoc 57dede1f54d1939e59316810f3dbd48bce103d37bc58ce856404ae327b165e67Virustotal results 25.86% Heodo
2020-10-27INV_42556.docdoc 3c0b0961efde86a2b9c1a239fbefeaa8c6cf896bfd8e930f972af471efc540c3Virustotal results 23.81% Heodo
2020-10-27Invoice.docdoc ccd9a6efeec7e3257f7e01534eae6701580d56c7792ee2a8661a1ad396a6320bn/a Heodo
2020-10-27October Invoice.docdoc c0c5965a405e155ed20444895767665de59ec49602fa279c7c94014265ae4561Virustotal results 28.30% Heodo
2020-10-27Form - Oct 27, 2020.docdoc 18e31e5b8ad5d3194d4fad561b4c5bf1bece67a65dc3454ef30e5019479afc42n/a Heodo
2020-10-27Form.docdoc 26b6c08bbd6f91a2bed79c26264bdeecd3f1c92733a9870924e53eda84d5ccdfn/a Heodo
2020-10-27Electronic form.docdoc cc0df9cb7c27958c95b031a5c41d0b6064f94c8c61317aedec48eb64d43aac7aVirustotal results 24.19% Heodo
2020-10-27invoice.docdoc 4a10c49813723560898495290eedafdf0dd7dc2ca1e0df6a54cae088c48b9b3fn/a Heodo
2020-10-27X0072 invoicing.docdoc c08f488ccd844154239cbddae4e7581df811648b6fa2ac1dc70194f194138742Virustotal results 23.33% Heodo
2020-10-27October Invoice.docdoc b2c300696fc8ad9ff5f0aa4ae76a7ae337d9cf8427bef59aa3baba261b9b048dn/a Heodo
2020-10-27Invoice 09132411.docdoc 5a07cc5df83be11d085d9a031f8c188b40fc8133ffa322777aed9a7c9a239c5cn/a Heodo
2020-10-270210952.docdoc 799de3c0b3c57093a424c4e80e471b26b7f7d121e6e4b75a250304ed59ab9d6fVirustotal results 34.92%Heodo
2020-10-27763007.docdoc 509de817ca426db6b61aed12a1a401fe05b91bd2a01c6203277c80e0b14f03can/a Heodo