URLhaus Database

You are currently viewing the URLhaus database entry for http://altaredlife.com/6564E/BIZ/Commercial/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:77395
URL: http://altaredlife.com/6564E/BIZ/Commercial/
URL Status:Offline
Host: altaredlife.com
Date added:2018-11-09 01:42:08 UTC
Last online:2018-11-15 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-09 01:44:11 UTC to abuse{at}godaddy[dot]com)
Takedown time:5 days, 22 hours, 19 minutes Bad (down since 2018-11-15 00:03:29 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-09SWIFT #2RBBZD.docdoc 60c17dc600c05fc34a7ac198d6ae84f56c45f10dbddbb2f03420e7b0201d40f1Virustotal results 20.34% Heodo
2018-11-09PAYMENT #493299O.docdoc a8d0a54d290ed4edddcc377b76ef243b13852889d9cf9f07d2f827d22649d3a1Virustotal results 15.00% Heodo
2018-11-09PAYROLL #37WAGZFQAB.docdoc b2132ab94f9caa8d2a9a78d8bd70ecda3d2918d60f275f0c6008e2bf5273e372Virustotal results 55.93% 
2018-11-09BIZ #616339IRC.docdoc 7a7a96dea01318105b9ca22bb0e951f9475c1d0573fcbeabc33e10fd1ab56c41Virustotal results 53.45% Heodo
2018-11-09PAYROLL #1381504WON.docdoc b4da28a1621ea5876ecc11ece53f9ff98547b8869a6c9ee7d067d5f9e40050efVirustotal results 43.10% Heodo