URLhaus Database

You are currently viewing the URLhaus database entry for http://vabshost.site/cgi-bin/public/93585245252125337/nj0k9or3-000502/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761085
URL: http://vabshost.site/cgi-bin/public/93585245252125337/nj0k9or3-000502/
URL Status:Offline
Host: vabshost.site
Date added:2020-10-28 13:37:07 UTC
Last online:2020-11-01 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 13:38:09 UTC to HostingSpell{at}gmail[dot]com)
Takedown time:4 days, 4 hours, 39 minutes Bad (down since 2020-11-01 18:17:29 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Payment.docdoc 2efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfVirustotal results 34.38% Heodo
2020-10-29HCD-100120 BRPB-102920.docdoc b646a2f2855c1348d2d8cbdf2d3f54747bcd727069000f64e1bd824991732442Virustotal results 34.38% Heodo
2020-10-29October Invoice.docdoc 0901573af4a97ebd93569fe9c30d3510244016e5fb1de981458b860ac4ef3b11Virustotal results 34.38% Heodo
2020-10-29invoice.docdoc 7e173c2910c46914628671824ef22427cbcb254a69f4c6bcd99d243a6ddf42dbVirustotal results 34.38% Heodo
2020-10-29INV_26362.docdoc 1425e6db29a588c212da92116660246ff0b96ee0e493edb96c54bcf45dcf66c6Virustotal results 34.38% Heodo
2020-10-29Invoice #288837336.docdoc 490447ab0221c1d099b57c81080eeddf31c23a6b90f4e753aaa82be8e80aefacVirustotal results 34.38% Heodo
2020-10-29R152 invoicing.docdoc 739b604f19e74fa2a4c12ca8e77df879b1ea0fbde304cf63d53247285e5f976dVirustotal results 34.38% Heodo
2020-10-29invoice.docdoc acbe2412c4aff06ae0a1c4b17bf4acab3d67874fa57aa0a31578e524d063f715Virustotal results 33.87% Heodo
2020-10-29PO# 10292020.docdoc c37dda7bf03e68902558b688b41f727bab5a1db704b0f7c6e65ce4fbf75b46fbVirustotal results 34.92% Heodo
2020-10-29October invoice.docdoc 407011017107dd82209d02b6714d52efaf3270f55a81de711db2f20d9b918d23Virustotal results 34.38% Heodo
2020-10-29PO# 10292020.docdoc 324aedabb0f28b770abb91d9a80adb7075c17d446112ef40261ec9b469e450b3Virustotal results 33.33% Heodo
2020-10-29form.docdoc 67adcb665e495bdce7d8234ef01fe0cebc5d615a6b630a2222366cd51a871658Virustotal results 31.75% Heodo
2020-10-29ZN2307303489RV.docdoc e48485a5f02afb4fa932b38c41f278e6a4571911311828ff8fc0cae186be9be2Virustotal results 35.59% Heodo
2020-10-29061784.docdoc 8d290f947fefa21f9f913406a08c14c04905e3d9989479adbc6e4a46bc8640bdVirustotal results 31.75% Heodo
2020-10-29invoices 34326 & 55593.docdoc bc8bdd4abaf022be86a96fc336146814eb7621b99b913b02c91f93941e298c96Virustotal results 28.12% Heodo
2020-10-29October Invoice.docdoc 99d886c1a8460ebf04f28f6695c165f45ead399cf1d98bf8ab140aeaaf04572bVirustotal results 31.15% Heodo
2020-10-29Payment.docdoc b50a2289ce6842be2773eea454559c2f2295dcbfc9331beb1fb66cc5d09f6828Virustotal results 28.57% Heodo
2020-10-29625351839.docdoc 493d0b6b7fe96f6e344c94ed7931ec69f8344a424f6083374387322b6ce037c7Virustotal results 29.03% Heodo
2020-10-29October invoice.docdoc 6ea355604d5c6f335af929f8e6508e90e7d2f18e82267091c99d8fdebf945346Virustotal results 27.42% Heodo
2020-10-29Electronic form.docdoc 9bedff10d91854bee6daf53c351b6ab3254895e11c0b77a9ea5c6433021a04ddVirustotal results 26.56% Heodo
2020-10-29Copy invoice #85087.docdoc ed51269c3602786ff6ddef3a808d8178d26e4e5960f4ac7af765e4bd642128ddVirustotal results 27.42%Heodo
2020-10-29invoice.docdoc fb4e266871e925f780d416984177d01ccf3dd5a3ffb76d031a5cc3738a76a3bfVirustotal results 24.59% Heodo
2020-10-29October Invoice.docdoc 154471acb1707b19c1efb5b7bc06211dd35e28a69e0db7f663b983d8712d8727Virustotal results 26.98% Heodo
2020-10-29October invoice.docdoc f2abbdc375e02c34831922b417357bdbbc322e4ef3b25e03dfe0250aef261a12Virustotal results 21.88% Heodo
2020-10-29invoice.docdoc 8200214bee8f21c170b9173814cac8166b9f605ebeee543870d9facdefa73d76Virustotal results 21.88% Heodo
2020-10-29Payment status.docdoc 0f34d0527521d358b1ac6aad3fb49b422bb06378891bf93065188f0db702bfc6Virustotal results 22.22% Heodo
2020-10-29Inv_127268.docdoc dd46084c550c55905276f7c43df92dbe4a91d31ba7afebe0313262ddbfbd56edVirustotal results 22.95% Heodo
2020-10-29DR7145256530TQ.docdoc 8072c6df686242c611cf697252c4e98152f0d6bd68e125f1527d3cc6192707a0Virustotal results 19.05% Heodo
2020-10-29BE0094 invoicing.docdoc df634084d9cb08a06d2e82f00cc3fef1f64efc21da9ebd08ba86b684ee237863Virustotal results 19.05% Heodo
2020-10-29E46 invoicing.docdoc 8b689836a9b1034619fdff9ed1e672a6c18d09887f73cfa9e3243ae5071badbfn/a Heodo
2020-10-29Electronic form.docdoc 2c9ff8e37385daa5453c52ae127481515435d634effca3453e09a863943386abVirustotal results 19.05% Heodo
2020-10-29invoice #650112.docdoc 86784b37bc0a4c5ad8f488356ec333dbeda709272a5aa412aeff54fee3f9db46Virustotal results 17.46% Heodo
2020-10-29Form.docdoc 1fd97c3d16ba4383f3df637bbd3ab25b987657d4afd5541d2bef1045db9028c4Virustotal results 19.05% Heodo
2020-10-28VPD-100120 NQNE-102920.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-28442715.docdoc 262b9ae34d1556927301b3a7e49f106e8a49724b527eaa327938fd5af61ec2ebVirustotal results 25.81% Heodo
2020-10-28PO# 10292020.docdoc 09ccc81a0d3dd19981c937faf388f0fe7117243b355255e387dce0dfb43f7769Virustotal results 26.98% Heodo
2020-10-28PO# 10292020.docdoc 0c5643d4a7b85e177802b1eae495641a49631f1e3016455f0c7ba45709d27026Virustotal results 25.40% Heodo
2020-10-28Invoice 00775338.docdoc ec428d84e9c1aebaf97ee36639823702c4cc91734d326acc91799ba2b3b40495Virustotal results 23.81% Heodo
2020-10-28INV #00364555 FOR PO #030106472.docdoc 19f5c63fa8696a0eaab016bdd4d8d1bcfb5dd7f07d1da25caabaaedf0088dc23Virustotal results 23.33% Heodo
2020-10-28Invoice 0050760.docdoc 1ffb519f7ee20c735692e941193543d406a780fa0756200654c9d442c5166fd4Virustotal results 22.95% Heodo
2020-10-28Payment status.docdoc 3b31e20a19f924917aea1e08d62b46e74ecf47777ab81e3843195449c1ceb80dVirustotal results 20.97% Heodo
2020-10-28invoices 9358 & 8319.docdoc 3abc8e8f02edb4b173ddb0aa9e5b5db794486c769bd4aa8adcbe2da23ec8cee2Virustotal results 22.22% Heodo
2020-10-28PO# 10282020.docdoc 661694d6fc62c1af16ddbe2db10c54b471f5acb387cde760666a6a672635f16dVirustotal results 17.46% Heodo
2020-10-28Inv_480265.docdoc 6b556db13a6bc97a4628816c0d73e375e246ba9dcf0767a7ff38910b06976de6Virustotal results 18.03% Heodo
2020-10-28INV_331751.docdoc 2c21d1cfbb9a5260ceaaf6bec0fee68158b5d635045c6a4de1f1289272a7fb38Virustotal results 17.74% Heodo
2020-10-28invoice.docdoc 7e7bd61af07906f31a4efa5442f7cfda98c0047ef70e15f64e37c5d4882917b2Virustotal results 17.46%Heodo
2020-10-28invoices 24599 & 3141.docdoc 24fc98fb4608b0e6216b4bf1a61772268c565b9b40cf66c95011f32d64591333Virustotal results 17.74% Heodo
2020-10-28Form.docdoc 3732182a2ad2854b3f9ae9a1eeaaec7d53eb43bbc485318ae0a2f573a0159b0cVirustotal results 16.39% Heodo
2020-10-28Copy invoice #95640.docdoc 7cd5248f6eed960168d2898ffde985d947702c9dc04b50d021161ffbed128e95Virustotal results 17.46% Heodo
2020-10-28Invoice #4755.docdoc 2d02f7d64430a41c50eaaed46dce33dcc544dc0d4904fd4561e8ebd851447952Virustotal results 18.03% Heodo
2020-10-28invoice.docdoc 6b8a13edbe6d2e19282d97fae23cb4eed96c854672c61fc5724b9fdda058760en/a Heodo
2020-10-28Copy invoice #2066.docdoc 5a9c040e67efe0446aaaeff9b0dacd2f668516484cf5487449360cd489ce268aVirustotal results 17.46% Heodo
2020-10-28C-100120 KTVG-102820.docdoc 9819d665344dae10323a62049a4b5193c88afbdd1792f6d8ad80b7df403b6c73Virustotal results 17.46% Heodo
2020-10-28Q6063303729XL.docdoc f104662c93957cb9de8b8b5db529dcd6dc40bd62d362d375d4894efba21b8c94Virustotal results 17.24% Heodo
2020-10-28invoice #6891.docdoc 14f85fe5da64996ebcf0d4bc76d753c6b0551d457e6849f53399cc1a60ca5e5bVirustotal results 22.22% Heodo
2020-10-28invoice #2477.docdoc 8d1b0623db4f3599679e4e49851df6cc812d8838f4b4428e1884fbbc8b5d44ceVirustotal results 20.63% Heodo
2020-10-28October invoice.docdoc cf5066738d5862bead47940e22a0cab26d7236c22d450506b045f226bfbf624cVirustotal results 17.46% Heodo
2020-10-28October Invoice.docdoc f973018352488fe6ba623919161c5b4387f67d9aca131af19480684ae2740544Virustotal results 17.46% Heodo
2020-10-280559792.docdoc 947ad40b782030b5eb73b4e4957c0f95d236c1414fd8d72520a422461cd211a8n/a Heodo
2020-10-28Invoice.docdoc 5a559e7ae73b3dfc7c7dc4894ad3be202468c4531516315cdd9b18c1ffca464fVirustotal results 17.74% Heodo