URLhaus Database

You are currently viewing the URLhaus database entry for http://www.naturalwaterresources.com/wp-content/BaHtb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:760585
URL: http://www.naturalwaterresources.com/wp-content/BaHtb/
URL Status:Offline
Host: www.naturalwaterresources.com
Date added:2020-10-28 11:29:04 UTC
Last online:2020-11-07 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003039346 created on 2020-10-28 11:30:07 UTC)
Takedown time:10 days, 3 hours, 6 minutes Bad (down since 2020-11-07 14:36:07 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Form.docdoc 2efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfVirustotal results 34.38% Heodo
2020-10-29Payment.docdoc 0cd92885567ce8bea98c6744504811e857d0a19a81b78f73d33623d3999efec1Virustotal results 33.87% Heodo
2020-10-29INV_02579.docdoc 55948fa440efdbe28f551bded69dcb747f665518a10876e4ae3ebdcb5e44ea67Virustotal results 34.92% Heodo
2020-10-29invoices 8135 & 6572.docdoc b35e8c1cf63de1025db2d2f786b3252b88272d9bad9576c7e2a223a9b4187663Virustotal results 34.92% Heodo
2020-10-29Form.docdoc 490447ab0221c1d099b57c81080eeddf31c23a6b90f4e753aaa82be8e80aefacVirustotal results 34.38% Heodo
2020-10-29invoice.docdoc 3af30f06e552ad3c513043c06c8cfdf4192cabadd585bbee5ab47c2c0e4ff1d5Virustotal results 34.38% Heodo
2020-10-29Payment status.docdoc 7035a94379b991e446531c0965b4935f1d3be9a10b20dd97e7dd1e34e6571707Virustotal results 34.43% Heodo
2020-10-29Invoice #795.docdoc 0d30a2f25c077dbaa89fd166e0c2e24a2d75900432ab850d5c00dbd826ff759fVirustotal results 34.38% Heodo
2020-10-29invoice.docdoc 092adc3e63864e36764ee209d07e652c3b37b55e0f433d9ae5c69a1619a482a5Virustotal results 34.92% Heodo
2020-10-29Inv. 7884905738.docdoc 6510c1088251e05cfe18fc22279a7312308f08614ba3dee7852e6b1342e21dd6Virustotal results 32.81% Heodo
2020-10-29Invoice 729021.docdoc 015aaecbeea372d2cde18c72ef93ce742b3e8c3ddf7247918403295dfa7357b5Virustotal results 32.76% Heodo
2020-10-29INV_46574.docdoc e30eceea75b291ff394ffb670b46a3b07e8725dc0a146c1df069952d9ed885a9Virustotal results 33.33% Heodo
2020-10-29Inv_5355.docdoc 2a132f8eb55b91975634807a5dab592f5c50ac116fe5914adcf1cdf16f9a6fc6Virustotal results 33.33% Heodo
2020-10-29SCU-100120 SJKL-102920.docdoc 62da1d16914ee7b918b84c1bfd2714584b9f6a979558c8e3c09c779b4b30deeaVirustotal results 31.75% Heodo
2020-10-2920598.docdoc 1c6a68700c5a829d8c421561d670c1f86cb25027af4b54be19724b1b7a979ef5Virustotal results 28.12% Heodo
2020-10-29October Invoice.docdoc b3498e558242db8d11e61b44f5d92839aed7dc9d6535bcb4e2d9e5e870682290Virustotal results 26.67% Heodo
2020-10-29invoices 8715 & 8602.docdoc 1d56ca58b9d83ed2dc74559beabbc4022b781bfee0f365d9997e3ff099bd6d5fVirustotal results 29.03% Heodo
2020-10-29Form - Oct 29, 2020.docdoc 094ec2bccb21b949d59963a6a17be2b816cdb626b5e91622ecc64a01fb16fc92Virustotal results 26.56% Heodo
2020-10-29AR2 invoicing.docdoc b923e2eb612bd13c6a6ee664b62eb77a9ef516772bcbc77f5bdd50dc255337caVirustotal results 29.51%Heodo
2020-10-29Form - Oct 29, 2020.docdoc 9c69f6cf8966a5e6349506b4664919c990dcf411ccd38d0748ea6c60dbf3fd8cn/a Heodo
2020-10-29Invoice 0953462.docdoc 7ae576917499bdb77da8f95dbec37ae4f819b800e62b5f467f0900d1dd716d1dVirustotal results 30.16% Heodo
2020-10-29007487976.docdoc 477abef826205efd3cf971b2c425dff760789b1c15cfcbc182634ba92187e59bn/a Heodo
2020-10-29PO# 10292020.docdoc 02fafe24fe1eab419305d450f7fe2753711cf6b5b8c5013c75c814cfdddb8348Virustotal results 25.00% Heodo
2020-10-29Q044 invoicing.docdoc 69feb49b203345739f8ccbe447369b371c114f0da1bb1ff9f607e5ca6ad6b95dn/a Heodo
2020-10-29N013 invoicing.docdoc 7d41847fb131218d629e6bb8132dc6b2b1ce714b4090c01c3f531fa66ad7274aVirustotal results 21.88% Heodo
2020-10-29Payment.docdoc 2589b11dff1909357910014419942540bed0646531aab526832d700248bbbf0eVirustotal results 22.22% Heodo
2020-10-29invoice.docdoc 26e0dedfbc389de133350f134455565f185e864b79466539b658dacc21fb1bb6Virustotal results 22.58% Heodo
2020-10-29form.docdoc 95b4f0a791e9ffefe35972f8c4e1a90c115fe1c8976f779e44b5190d859b3eb0n/a Heodo
2020-10-2966109.docdoc b04cd0d0b3964558d003f28a5d546be1937e3ed1b34ca455207e9d8757e82dd0Virustotal results 22.58% Heodo
2020-10-29PI2768381854XO.docdoc 3e84e096f2f889c271504b8dcfb1e9fb78a347087b984a219d7749a8a0839c31n/a Heodo
2020-10-29Y00815 invoicing.docdoc 65a1c1b8cbaeaa9098df96d462c765ec20c8d6acad74e0a0ac60e895d9468c06Virustotal results 19.05% Heodo
2020-10-29555432651.docdoc 4d064ffae939066e710a994df38ada3de500bfca3fa58d21f40312450b69b3dfn/a Heodo
2020-10-29B09 invoicing.docdoc 2c9ff8e37385daa5453c52ae127481515435d634effca3453e09a863943386abVirustotal results 19.05% Heodo
2020-10-29Electronic form.docdoc a5df9e6a4b16c603b2f667654c7994ce098bb7baa10e3ac101562e534e5f060aVirustotal results 19.05% Heodo
2020-10-29Inv. 809489.docdoc c8e574a25c67cc59d9e1eab78d4591aa32efdd56dc3a64d5e02928d42fe1e732Virustotal results 19.67% Heodo
2020-10-29PC002 invoicing.docdoc 2dc19d1576e1d7e5d43a3e0cf6ed690d3b66634515389ca782f0af0198069e65Virustotal results 19.05% Heodo
2020-10-28Invoice.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-28INV_364274.docdoc 767adf40099224255f150c5dab97873a98b3aa9a0516b068d3412b1302ab2352Virustotal results 26.98% Heodo
2020-10-28Invoice #093266736.docdoc 77011899c5b86d17bd9c00bf4a80339feebd6adb1135b65512e1dfa8653e6ca7Virustotal results 26.98% Heodo
2020-10-28Payment status.docdoc 09ccc81a0d3dd19981c937faf388f0fe7117243b355255e387dce0dfb43f7769Virustotal results 26.98% Heodo
2020-10-28Payment.docdoc 6c3c1280087fe50fd411676b26ffd9bf41044300aeef5d27ed6322cf365fcd99Virustotal results 26.23% Heodo
2020-10-28Y6004097351AP.docdoc ab327e3be9ef1ce4781f725c995feb6a13f6eaf1d1c31e894048e5be6b4e24aaVirustotal results 23.81% Heodo
2020-10-28Form - Oct 28, 2020.docdoc 19f5c63fa8696a0eaab016bdd4d8d1bcfb5dd7f07d1da25caabaaedf0088dc23Virustotal results 23.81% Heodo
2020-10-28invoice #36965.docdoc 77373248ec2c394eb9cfd85b94e561cdd8ed66646be0298961d65b24a97305e5Virustotal results 22.22% Heodo
2020-10-28form.docdoc 329f623c62c598576abebccee07ddfe04ba97b4c7ae3307e6a9601185941755bVirustotal results 21.67% Heodo
2020-10-28invoice.docdoc e69175f1d0fc57715610220f59992ae3a56ac12d27917162e4626cd0ef2bfc30Virustotal results 19.05% Heodo
2020-10-28L-100120 SRCK-102820.docdoc 72fc52675572a69794899e21825966d31976de8fe26ded5d21f743a903af4d70Virustotal results 14.75% Heodo
2020-10-28Inv_507013.docdoc d1f0145ea0d4e036edd208387b5c7c012b0eec91562b6f210853152462b2ff63Virustotal results 17.74% Heodo
2020-10-280075222.docdoc 3e784298291a432cc1c053b0a50d2245977718a7f16e344559d0952260c96049Virustotal results 17.46% Heodo
2020-10-28invoice.docdoc 7e7bd61af07906f31a4efa5442f7cfda98c0047ef70e15f64e37c5d4882917b2Virustotal results 17.46%Heodo
2020-10-282063731120IU.docdoc cdcc9f999263c672f77e84b1b08028da0a298140b3e9e300baaa8a6b69c84e99Virustotal results 17.46% Heodo
2020-10-28invoice.docdoc 3732182a2ad2854b3f9ae9a1eeaaec7d53eb43bbc485318ae0a2f573a0159b0cn/a Heodo
2020-10-28October invoice.docdoc abc441e8e79d4bbbc2cad82c9c8640e5556dfa439a39b965716dd1cbef7e2ac6Virustotal results 16.39% Heodo
2020-10-28invoices 00385 & 60960.docdoc 268438b641db6d86d82847ad12e55ab098615a5b5328d37db2b6123a4e08a822Virustotal results 17.46% Heodo
2020-10-28INV_370759.docdoc 972373325997756ce08f019f747a89063df5e588ee54bdb8fcbe6aa9d05e70a8Virustotal results 17.74% Heodo
2020-10-28P3 invoicing.docdoc 5a9c040e67efe0446aaaeff9b0dacd2f668516484cf5487449360cd489ce268aVirustotal results 17.46% Heodo
2020-10-28Form.docdoc 9819d665344dae10323a62049a4b5193c88afbdd1792f6d8ad80b7df403b6c73Virustotal results 17.46% Heodo
2020-10-28Payment.docdoc d3b789ffe8bc12eedec50bd95af1d0e1c37ecdbb8e15d61723a63a569c32602eVirustotal results 17.46% Heodo
2020-10-28October Invoice.docdoc 14f85fe5da64996ebcf0d4bc76d753c6b0551d457e6849f53399cc1a60ca5e5bn/a Heodo
2020-10-28Electronic form.docdoc 8d1b0623db4f3599679e4e49851df6cc812d8838f4b4428e1884fbbc8b5d44ceVirustotal results 20.63% Heodo
2020-10-28INV_82217.docdoc 7e8996f6c2bb380cdd8ee5149be9a14a338720b1db9e4ba106e9e039361ecbd8n/a Heodo
2020-10-2800198527080.docdoc a15065cc7906ff0f92eab6e94d12157947b02e7b25586b84a8ed21aa4852e7b0n/a Heodo
2020-10-28L4516948836UH.docdoc f973018352488fe6ba623919161c5b4387f67d9aca131af19480684ae2740544Virustotal results 17.46% Heodo
2020-10-28Payment.docdoc d4d88bb7b289fc8fe85835f356c30440662efd3f2a033d4b99bda2f234647243Virustotal results 17.46% Heodo
2020-10-28October Invoice.docdoc 913ad0deee7db9012293779fa15d6491806e2ea0d1935f45991a652ec1b76d4eVirustotal results 17.74%Heodo
2020-10-28INV_33006.docdoc 52cffa7b6a722c32c17560a5d71ac09a91bdcd9cd36ab8b9913c92063aa109c5n/a Heodo
2020-10-28FY02 invoicing.docdoc 8a5d45742906d99f6a25870884036c29e1df4a190ada0ad3af81feae44092f1cn/a Heodo
2020-10-28Inv_6648.docdoc 4a38ce8b06088d33fe7de915230a1cdb6b703c5b235ae2f1022c4055c4c8ed57n/a Heodo
2020-10-28AH4359253113BB.docdoc 82cfe085365c8087b1f710c983c18cef34c5f2f81bb43171cd34050cc0984a54n/a Heodo