URLhaus Database

You are currently viewing the URLhaus database entry for http://www.falconcastings.com/wp-content/N0VFh4sXUdY5E9VP7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:765802
URL: http://www.falconcastings.com/wp-content/N0VFh4sXUdY5E9VP7/
URL Status:Offline
Host: www.falconcastings.com
Date added:2020-10-29 15:37:05 UTC
Last online:2020-11-02 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003042142 created on 2020-10-29 15:38:05 UTC)
Takedown time:4 days, 0 hours, 54 minutes Bad (down since 2020-11-02 16:32:55 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-31UNTITLED_2020_10_31_RHX02281.docdoc c2239c86191e6dbe4cb7a13e085fd47f5e4f9212cdeea61bfa295a9399bc4686Virustotal results 54.10%Heodo
2020-10-31Attachment_2020_10_31_650597.docdoc b64f9d2cdc0c2e84301c1fc9dce4dab16a0a8013f6c7961ab0fc423d2b842a8fn/aHeodo
2020-10-31mes_2020_10_31_845.docdoc f02302761b9bea32d6ef774d20d52687208198e16db81a56741e7ae0feeaa5f6n/aHeodo
2020-10-31REP-2020_10_31-K831.docdoc 02ac5e50e2041552454275aba9a58d1a828a0177dcc51d15b2186d30be06dd3en/aHeodo
2020-10-31File_938.docdoc f8f86643efd6433a142018fb074f42ba96c3080b30f8da26abb009c03432b02en/aHeodo
2020-10-31Attachment 20201031 5211.docdoc 11938da3e639a51c381760b52ff130c7739cc55ce44513cb71a1695bff359e7fVirustotal results 50.00%Heodo
2020-10-31File 20201031 G160877.docdoc 83ff58f68e610a02dd13d1ddeeb2b602b05076e1aaf491321ada977d957cf6ean/aHeodo
2020-10-31Attachment-20201031-715965.docdoc 22610e4ec1dadecea8cf8bed9e0cc318877401a02d6f680dc520821c3fb8d716n/aHeodo
2020-10-31mes_2020_10_31_64416.docdoc 7cd3f78ce8d586224296825a76895b52e275a9adef40a55045c7ddcd487182d4n/aHeodo
2020-10-31FILE-2020_10_31.docdoc 00417023b5ea01da1802c7c13dbee66598567d6202022cfa4cc80a3a3ff2ae2eVirustotal results 50.00%Heodo
2020-10-31Inf 20201031 7389466.docdoc 58b4b01b27226f4c2fcf20dd17aac4604e04c0e736be3d8d1a8291dd0542f1dbn/aHeodo
2020-10-31rep_2020_10_31_GV477336.docdoc beb55dbd5a9404b1cee833f348f37fd16b64df5cc89e939e8e12dc49ef29fe31Virustotal results 46.81%Heodo
2020-10-31Mes_2020_10_31_VFN4033.docdoc ece2b34c4325d63381dc959a42e9fd3bff2c79eacd15749f97da19d9fc631b7bn/aHeodo
2020-10-31mes-20201031-1778.docdoc c0094a2537141700d89182a20e365fce3cd4f7a7c9a3924d0a5ef894c7a6aaafn/aHeodo
2020-10-30REP 2020_10_31 766.docdoc 0df110553135d059b75092a5ffb20c46fe16bc7f61ca0fb662977078201cf6a5Virustotal results 46.77%Heodo
2020-10-30Rep-2020_10_31.docdoc e97a94a4cfc7974e9f0c6b6733a7bcb4b8de1f79e441cbac9624c10448939ff1n/aHeodo
2020-10-30Attachment 2020_10_31 YUF88626.docdoc e85c32ae68a655edf933be2fded9239c8cbc165e13aebaac456585df69ca4a10n/aHeodo
2020-10-304567_2020_10_31_N411.docdoc 35cb8bedd530c792d8b3cab49ba71c507f68d79348871c033ef9663c437b2aa1n/aHeodo
2020-10-30doc_2020_10_31_K151.docdoc b42ec3154bf81b9db8b0aa9f3dbdaf4c02eaf40766ddcb5542779307674a532an/aHeodo
2020-10-30ARC-2020_10_31-401.docdoc 6af7c087d281ec6713e1b1488d66ab4376fd8575b0eb76dcacd6c35f96b28cacn/aHeodo
2020-10-30list_2020_10_31_HC9665.docdoc b78c3c97378f49dbe83d704f3dfb2d6b8df5e20e5e72cb23c354608f6680d1faVirustotal results 48.39%Heodo
2020-10-30UNTITLED_20201031_6316.docdoc bf12c3f37f0ca001687397eceb33c424cc49a285371a92fc3a3ced7e99570121n/aHeodo
2020-10-30Doc_688313.docdoc 102949c3283cd419c7fa9d1a87ffad267839a60543d41deaab75ac16f11cdf8cn/aHeodo
2020-10-30Arc-2020_10_30-O17888.docdoc 87564a4a8db98fbd859cef5d7886836ba62a7e3a5179a204457eb13ba41012b6n/aHeodo
2020-10-30list-2020_10_30-TD2498.docdoc c8e72bdeeb6e62097bac2920b037450e19215cf8b49f5c614f5bfdae2d7d10d7n/aHeodo
2020-10-30File-918.docdoc b80748e5abff124c2e769811b6d07ee49b612be307a825ec4d6cb37f18ca1c24n/aHeodo
2020-10-30MES-2020_10_30-488.docdoc fd381117b2d836cce5e55ce31d9f05c26028783457ab22c7289b6b7185e37e61n/aHeodo
2020-10-30Untitled_20201030_FSO681.docdoc 395264bd90b31a6048e4bc4591e133e47f6cf2e268b84b4c48213574b8f209fcn/aHeodo
2020-10-30Inf-20201030-O6567.docdoc b6802ed0d67d436cb620790db9622265d1efe9facc3604a3866937838bd567e8n/aHeodo
2020-10-30list 158.docdoc c3f938d4cdecd6141a6463ac07615398d82ce521c1e86c0e5ed70d9a26eec354n/aHeodo
2020-10-30OD50774-518121.docdoc 021505c118250f4126e9aac734e19f238bd2045fcc18957ed6d027f60a3c8827n/aHeodo
2020-10-30list 2020_10_30 1060.docdoc 918652ec4894abeed6fea66bebcab423df702c12611f58c5a67332615c30c9ecVirustotal results 32.81%Heodo
2020-10-30mes KD506.docdoc 94475692dcd80bc6c6c60a7fa254144bf115bad1ab83db49cb7e31adc04dc445n/aHeodo
2020-10-30Untitled_2020_10_30_M5905.docdoc 7ddaad676e2cad0f5aa0b7af862168d98171f03f7da12a7ec894d75faa88947an/aHeodo
2020-10-30Attachment 2020_10_30 13846.docdoc 2b41d5254b875b78206ebe49e01e8560cade3874b0b924ea3fe1eff438b9aaeen/aHeodo
2020-10-30ARC-20201030.docdoc 822cca2b64c01e694b6f62afdf09a0cd5aa27f3a0585c9e004cff54fe0e7cefen/aHeodo
2020-10-30list_20201030_QVP8135.docdoc 5a2e23932bdbdbf97b1abc748d155d9135d032c72cf764296b9552845e5cc850Virustotal results 33.87%Heodo
2020-10-30Mes 688822.docdoc d8bfd4be9d542043d38192e58ac1118dded572fc34fe74683a4c1f9e7801d524n/aHeodo
2020-10-30MES 2020_10_30 06724.docdoc fccb2d705dea3213ad114cccb819717b0be64264f06779e9084ec9b4e98dccd1Virustotal results 32.79%Heodo
2020-10-30INF 20201030 DAX173.docdoc bb052a3b2194baa0eaf80cab0def28d1a47fdbe44eb5fb56bc22af81cd6b5075Virustotal results 29.03%Heodo
2020-10-30Mes 2020_10_30.docdoc 20230cce2431c3441e7fd0bc90c32ac73fb894b43b0ca53910d7888ead1ce196n/aHeodo
2020-10-30MES-20201030-5390.docdoc 82b84e8b989abdb526facd2f2dda1f7f68c45acdee4c400cd6d7733ebd6a1354n/aHeodo
2020-10-30Untitled-2020_10_30-I800351.docdoc 9a3cf0ee5d4dd3b313ee5bcd29a8d47438f7eef1880734caca989e6ffbe45092n/aHeodo
2020-10-30doc-20201030-LLO286418.docdoc c69f698245bf053d81ad10f95963c8991f117abcce72439600cd42c5619a520cn/aHeodo
2020-10-30Dat 2020_10_30 FLG847.docdoc e62f4b327a8908aca08edb3a69ad2d7a27ab440b3b0aafbe859d55035f905f0bn/aHeodo
2020-10-30mes-2020_10_30-V288.docdoc 3d56cf9604a80d2994eec4f535b62e98b662a087ebfb58691e0d544efc22a15bn/aHeodo
2020-10-30List_20201030_049.docdoc 1da688acac13e5306fbbe1dd92c16af2acf14f18abfc3dcfbd6b662229b6cb5fn/aHeodo
2020-10-30rep-BM2089.docdoc 98d1c2eec01fc9e0f9106bf41b1611884e74a45ab849644b9f01bcd4f7a42768n/aHeodo
2020-10-30arc 2020_10_30 6963.docdoc 9b1d40456192d2959fc96b36323a642e7c860d3ac3fbfe453a978c1f87becdaan/aHeodo
2020-10-30doc 20201030.docdoc c3794e6d63d3891a1c52606677b2811abba100cea304ba7df7296ade4f6cddecn/aHeodo
2020-10-3007870 RGK679736.docdoc fbbe6a9112285c6511075644a37575be3f4b09df736f145ec048c94b7dedd72fn/aHeodo
2020-10-30Inf 2020_10_30 160902.docdoc e4649f0ee5354ff5857c31cb9edb642663fffa6b960201a7a10ea3adb8e877den/aHeodo
2020-10-30arc_20201030.docdoc 68093e32e1557938ea73d8b95906e6e344aacc345e85683b0f838f26bd01fd11n/aHeodo
2020-10-30Attachment-1057.docdoc 221d1ea189ab22be290818493a26860b54e61219fad0d7e39714eec24a36e19bn/aHeodo
2020-10-30Arc_2020_10_30_BR0618.docdoc 49c26c43eb2d1a6902e08ac9fb28d01e2bbbb280158487ea75354dc80be59e31n/aHeodo
2020-10-3031126-J28345.docdoc 72502fab1f404078984874bd71e560d05f4c4f87d71dcea75dfbd7108fe9e0f6n/aHeodo
2020-10-30List 2020_10_30 4791575.docdoc 6f982323ebbee2d1dd34d9712ffd26cc99b3080b50d596d3da9ea7154c202958n/aHeodo
2020-10-30LIST_2020_10_30.docdoc 62b438f1aa3f77084e934f91334751fa1ec4e661d03cdc927e0ea7343fb53a1bVirustotal results 28.12%Heodo
2020-10-30List-VO1467.docdoc a2bf8d5a7361b5e31066653eb6522f5c2995e7407290bfe2a74296abe2914ff0n/aHeodo
2020-10-30Attachment_VQF619782.docdoc 5e85d638260191bd2081fa7d7c9f0e45ac098acd5b2080e7535ed59823864599n/aHeodo
2020-10-30Arc-20201030-K55621.docdoc 6b766925de9c4cda22bdd6c7da535788023c12dcd880a7ec02d40e69f63aca4aVirustotal results 28.57%Heodo
2020-10-30MES-20201030-0081880.docdoc 491808f80c7325dc185a42e1438b9fb0176566c67ed40ce43e771122822007ccVirustotal results 29.03%Heodo
2020-10-30INF 20201030 C15742.docdoc f85dfdadc90127312e82fee2bec640f2f4a69cc0509f36337e0078bc603109e7n/aHeodo
2020-10-30PIC162_2020_10_30.docdoc bbcefc8c00253b2f803fd51e84768525a6fbc85a48189ba3e23a6af208570f74n/aHeodo
2020-10-30LIST_20201030_EA276.docdoc 3407fbd416d6c637eee3972fd3c1f7444488d18862e846dbf1d9e68a9e5d0727Virustotal results 28.12%Heodo
2020-10-30Arc_20201030_RAA984294.docdoc 8bef0374dd23e76792649c9adbf5761934a98f790da0e6d49b18592c5a15097bn/aHeodo
2020-10-30File_20201030_108824.docdoc 0959eb24414ed4905b9b3ae4892e1489673cb1dcfda78853f7cd12bb8506984en/aHeodo
2020-10-29Rep 2020_10_30 Y1706.docdoc 34ebdddd214c6abbd22fc74af04fdf1d1af2b6ad1563f85e1d2c63ddd5f4be05n/a 
2020-10-29469895 20201030 NY152.docdoc 39aac454150ec504ceb483a99e30bdcb29a3725664a6ef2e1a02c37f57569e91n/aHeodo
2020-10-29Doc_20201030_WQG37864.docdoc b259d446961f8e221ea21da155dc5a16bf3f4baeb15bf4e443f776608e5b74cfVirustotal results 28.57%Heodo
2020-10-29Arc-20201030-M744.docdoc 1c802678220f65ea3b50e82874a9888689aec3c069499e2941f3bfc7d001c726Virustotal results 27.87%Heodo
2020-10-29arc_20201030_WFJ477940.docdoc ab1677b6e3da1bbafc0938559b2a9731e7a126660dd10d5961abc1d4bb4a0905Virustotal results 28.12%Heodo
2020-10-29rep 2020_10_30 P280.docdoc 61fe1f318088e3606d51b60f09ebe1de5f1fa0b55fc2c2b3185b2f255400a5abVirustotal results 26.56% 
2020-10-29083579 20201030 UCB7424.docdoc 11b4592603903a4f6783a2c905e9f163ceb9b48f854fd1addc4b670505f4dd0fn/aHeodo
2020-10-29mes_14638.docdoc e65980d588f0fd5d79db25edfc5ef6d7fea680a7d3c857569dbd110067369398Virustotal results 26.56%Heodo
2020-10-29rep_2020_10_29_645700.docdoc 749a637bdf40f86a5743764dfcf9c1654d7c1943f00127bf4cdf440d04412f31Virustotal results 26.56%Heodo
2020-10-29file 20201029 GU706.docdoc d3b7602fbabfbe5f4e8541ebb6badcc12190ae2addbc480908fc63ec43b4ab67n/aHeodo
2020-10-29Rep-2020_10_29-98693.docdoc a9adf996fc16c172ac4f9b304cd5bba6914adfff11025c697e9c0ade0193e353n/aHeodo
2020-10-29INF_2020_10_29.docdoc 8d9d4d850d036b687ad9c840d4b9667d172fcdc5cb3e7d303b95bbff842ecf42n/a 
2020-10-29Doc 2020_10_29 OC478890.docdoc f452ebbb6a749f0cd58dd03de749ef6a2158119219902efa67d5f025461e96f3n/aHeodo
2020-10-29Dat 2020_10_29 878.docdoc 3ce86ebeb7522e05953bd5076f603c7937e47449bce8168d8ec536b1c388d54cn/aHeodo
2020-10-29Doc 20201029 N330626.docdoc 21548033541fee7db2b338fc22b8edf6d0630f22aef14a0f2d664c644ee948d4n/aHeodo
2020-10-29DAT 2020_10_29.docdoc 5c9357004aabdd59025b4e6cff228ddf6e9ef59b9bc97fffc36d36fe7ce8f421Virustotal results 25.40%Heodo
2020-10-29dat 2020_10_29.docdoc f72dc65ff43a2bcd71bdb4e6f7241cb06691ed24bf9630379b104f9d414b8793n/aHeodo
2020-10-29rep-556434.docdoc 8c0858b719abc1adf308d8cd924580c9b8cfe448c49bcc411a5e7a0f3b6f6b23n/aHeodo
2020-10-29UNTITLED.docdoc 12785e4d508a88f8ba6bbf31b2e115fa181f62e19a0a6fcaf9f61f5e41b0c806n/aHeodo
2020-10-29Inf_2020_10_29_JR631.docdoc 33cb7f958bec519b7913f6c21d9c4c00ec1968a9f4de14cfff0ec251f9c5e8a8Virustotal results 21.88%Heodo
2020-10-29IIC058-2020_10_29-6071132.docdoc 80ebc730b2596e69a24336bc44a42d1643e6996487151db380c328bc66e3b64an/aHeodo
2020-10-29Attachments_2020_10_29_218372.docdoc c6eea0359a87d3f6b39ebc7115393ee78e0544300a10f031f087fc6ba7db2a7an/aHeodo
2020-10-29rep 5360.docdoc 5597d783bf7dc649677795638f8bbd5f97676ce49e443df3ee1fd032008f5609Virustotal results 20.31%Heodo
2020-10-29LIST-2020_10_29-B15644.docdoc 46d9e560db1a1d687d58d92ded82cd4ddc77a154a7c66bcc99d628f7386c97aeVirustotal results 20.31%Heodo