URLhaus Database

You are currently viewing the URLhaus database entry for http://montegrappa.com.pa/201I/SWIFT/Commercial/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:84290
URL: http://montegrappa.com.pa/201I/SWIFT/Commercial/
URL Status:Offline
Host: montegrappa.com.pa
Date added:2018-11-23 18:29:19 UTC
Last online:2018-12-04 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-23 18:30:01 UTC to abuse{at}godaddy[dot]com)
Takedown time:10 days, 23 hours, 8 minutes Bad (down since 2018-12-04 17:38:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-26BIZ #870544KSGU.docdoc 46c708f3468052469785a18c61440521d05eeeb48625122b2f0879924fcf19a2Virustotal results 25.42% Heodo
2018-11-26PAY #7961DP.docdoc 750571c92724559337e7b3a294cb9398372007272fc39662fe2d28b958810b84n/a Heodo
2018-11-26SEP #434BCRVWNCH.docdoc b765f06492608ae3357a19d8f21178d4cf1ee8662d3084b7502a4ecb1f46f38bVirustotal results 24.14% Heodo
2018-11-26PAYROLL #9535469DV.docdoc 1df4f0f7ca0e487922aa35f1531ad118b9f80cda79face5684cf1e2d6a35cd76Virustotal results 23.33% Heodo
2018-11-26PAYROLL #32DPAR.docdoc 1a45f7876fd4fa2046716739ca8c1e445a9eba8833f817300a0ca034c227e62fVirustotal results 23.33% Heodo
2018-11-26SWIFT #19402OWETZ.docdoc 2ce7330a70040737397b483674680e27bcbdc67390dc64df11319539f15d4c79Virustotal results 28.81% Heodo
2018-11-26PAYMENT #29Y.docdoc 4acbd8ebac5a1cfcb72aad7e5f1ff3b21d2541a931964a07de2a50bcb9325121Virustotal results 25.86% Heodo
2018-11-26PAY #4GNT.docdoc 20d9a0f8fe27a43d9d99fd593c8d8af9b9799172c5b7179aa5a8cd2219de3b28Virustotal results 20.34% Heodo
2018-11-23PAYROLL #564869DNMZKFY.docdoc aafc2b406225953f1997831b6270adfc3624d08b4cba70d4cdce2f485c7c2108Virustotal results 32.76% Heodo
2018-11-23PAYMENT #1679905UPLDLI.docdoc c2600d83af5ca348dfb499ed42869fc4f8fd23125f84cf1f8c75d94b522cda8fVirustotal results 32.20% Heodo
2018-11-23SEP #7GDWSSHR.docdoc 96cc7f3d2d4ce46d68c6dfea8303b082fefbdf5b0e6028ca2d5927bb2419e9een/a Heodo
2018-11-23SWIFT #3167639QCPPW.docdoc 4c0086e6c07155b82db0cea0b52f2e7355044ac3bac1a6b8e720a09d8d1111daVirustotal results 20.34% Heodo