URLhaus Database

You are currently viewing the URLhaus database entry for https://pusher.co/leg-covers/Sz5ujJHPoe6gvtVuApCNUBs26Kao3Ro1HkpjUgkhP1HE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:936734
URL: https://pusher.co/leg-covers/Sz5ujJHPoe6gvtVuApCNUBs26Kao3Ro1HkpjUgkhP1HE/
URL Status:Offline
Host: pusher.co
Date added:2020-12-22 00:27:08 UTC
Last online:2020-12-23 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003188183 created on 2020-12-22 00:36:05 UTC)
Takedown time:1 day, 20 hours, 38 minutes Poor (down since 2020-12-23 21:14:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23P5YUX39U.docdoc 768f3c029cc79ae21d7c732487da93f0e8c7d19a83737f9ce7e107e3adc9054cVirustotal results 43.55%Heodo
2020-12-23ADUU496Y208YVULL.docdoc bce89cd09be85ac647d834fb41cec14c3f695ddd559477288bd3853accb78258n/aHeodo
2020-12-233TXPZBB9Q0.docdoc 6ed5539e92f43fcde23dc6343c4f41a93050576180fad637adc5014a49ed38aaVirustotal results 41.94%Heodo
2020-12-23R3A35QANX9U9.docdoc 3e9a6799e7ba70727573d5d792394849b0d94f95a6d0d51e46c3a3340314f764Virustotal results 41.94%Heodo
2020-12-23CPLB0HSF3.docdoc 23c7b6514694abdd61ab7f466352e211d87cc2086939a3efcc14c94251842cc9Virustotal results 40.98%Heodo
2020-12-23Z5796CRJZIH0AX.docdoc 0339f21444ef1ad35fc320d6879ea93b08d3aea53e25aaf3c5b841a2cdad855cn/aHeodo
2020-12-23JERHYG13CQB4.docdoc 7321c475e384a9cd1c118ee71fa5e977ef762d64c7bdea4cecb33d64046469d4Virustotal results 41.27%Heodo
2020-12-23H4CRESITLJ.docdoc 70cc44f855631b3a9358c0b5f202406738d8b5c6a21133f6ae2d775aaa3a8ecfn/aHeodo
2020-12-23BR75W7.docdoc 94d804683ab1c9195ece193461e872d75b4835c2ee0fc73886dcca02a89463edn/aHeodo
2020-12-23A4MD1HXUXI4GZ.docdoc 395efc9f98f81ccdcbfe6f9bffdd0e0ea5a2611e4542e43f1241c649713bf46dn/aHeodo
2020-12-236YIQGNVC797IST.docdoc 6a99fa281763f28746b1f915866c7f2897b69d09801f3b0ac0a61517f17d90e7Virustotal results 27.87%Heodo
2020-12-23Q3C9E6.docdoc 63725aa4926dac422d6710c815b80ad10e66b882656195a75ef13b9816cf7c53n/aHeodo
2020-12-235JUWOGGKJWWIKO.docdoc 0149c806df64185dc66ee1fdc857e25ee93def1f7db847487674959d2b9306d1n/aHeodo
2020-12-2361L0KQ9LWP.docdoc a28b7c24587230e5ac5533afb0324572f1d1341d264eccba2aaf6b2a34e5ce81Virustotal results 25.40%Heodo
2020-12-235JXUPX50.docdoc cb4f991bd4228ec60ab6af1bab6193e68f4fadf3a30b226e7ee9cdfe893113a0Virustotal results 23.81%Heodo
2020-12-2368F63A.docdoc f8d8367d54febac27068bc20e25b1c3260b9bdc78d4874c00368e65ec2e37ceen/aHeodo
2020-12-23LN82YPZN.docdoc 7e0f29831e6732a730d1b231a94cae3a27525976381cf6b97d15fe45c295f239Virustotal results 22.58%Heodo
2020-12-239QG4MY7ZHOLEE47P.docdoc afca4fb94300e4d7cd65cf15d802e9a4e1e6fe20051f8c2428b3a821bb3c8cben/aHeodo
2020-12-230GHY2QACBNKG7.docdoc d5231db757615d38ce982ea1272ef281efc93dc8105418c890e8f9e59d76ef0dVirustotal results 22.58%Heodo
2020-12-23EGLC8H8L6HM6.docdoc 241c359520f4cef1af1de9d4789bf620f8086c7feb5aa2deba772b87aef3d514Virustotal results 22.22%Heodo
2020-12-23VV75RNY.docdoc 6083b405a5bfb099398dc2417486e1c2913bba82b96baff811a71ee6feb0884dVirustotal results 22.22%Heodo
2020-12-23NKY5MINR1Y.docdoc ebfadd85753d033e248aedd9f9c5772331aff8dc35049d0842e8c423d64ea08cVirustotal results 20.63%Heodo
2020-12-23ZHLF6HE0PXA.docdoc f0a4ee510f94aaef257225740c62c4a65b2da3ced23ca6b1513b9fbe11fd3cd8Virustotal results 20.97%Heodo
2020-12-23R0OLEJ81.docdoc 1b1cb32d2f4a43f7bd1699dd46b55f8deed32e31065c9f13c69f2610b96d41c6Virustotal results 40.32%Heodo
2020-12-2341MEZS.docdoc 4a6d02a3adc59903ee067a5abc702d78fb31c61deb56b7360fade2ec85195569n/aHeodo
2020-12-2358FKY5G.docdoc dad7761c55d0c4eb6fbd18182bab52f99242f7107fdf629b056cb6965ba073cen/aHeodo
2020-12-23MKL1DJ3XS.docdoc cf2b33d88046f8e39c8299718c9132fc22247ef02bfe6ae6d404b0ca1c7c6119n/aHeodo
2020-12-23YHT4Z3QMVONY3YZF.docdoc 9e353b38f1dd65bbd6f1e50dc63ddc1350f17b8e382a9fe24328cf1f1609b181n/aHeodo
2020-12-23LTLXLOY5BZSBV.docdoc e1624ae5f5ab385ff8468ca483e628d08be7ee14d23f030d3682a3f97d360c5cVirustotal results 36.07%Heodo
2020-12-23X4VWADY.docdoc 525689f16129765cbfcab859edd5d99fbbec461ea04160605819b2f4b6150042Virustotal results 27.87%Heodo
2020-12-23GHPGAK71I0W820TT.docdoc cd26f4220386d91ffb1a0233ece99c207f4335aab6a4c6227d64756f16500ef7Virustotal results 31.75%Heodo
2020-12-23SZARHIQTVI.docdoc 1f0dd0263393040d067ed555d604d764634263e4eb014755feb5d319af9db68dn/aHeodo
2020-12-23L93FIMBVL.docdoc 9a8b914d6bb8ae09a04b32fc897fdb9a9ffc073975b436b031ac837b7eeefb0bVirustotal results 26.98%Heodo
2020-12-23X7C1601S2571T0RM.docdoc 1a0263e1f86a9148e3b7434c12cc232b3a3c92df63c0aa48641c627e87949106Virustotal results 26.98%Heodo
2020-12-23WU26E5CZQG6.docdoc 47a492a3a0bfd3d8e0e6c5b72d0594fc8f387d657c457da34d5b7c097f8ab9deVirustotal results 26.98%Heodo
2020-12-23B9FA7CAH.docdoc c693baac5d3227d362a0fe99ad187c18cde1f45a404c94c881d424023303a744Virustotal results 27.42%Heodo
2020-12-23HCQDKXGXO1GPWSA.docdoc d4b572062438c3b6331322be310ee0209e104c180931c63dab258983c69f6dadn/aHeodo
2020-12-22NEV2R17BC09.docdoc 32dbb92d892c9f50e99fc70db5b9f3efe0721a6464984a3f84e6592cda81684cn/aHeodo
2020-12-22IRNFXJ01EEE04DP.docdoc 6db84ec96bdba956f2a1aaf37771903b47d79d69fc01b53e33ba039b8e7669adVirustotal results 21.31%Heodo
2020-12-22R2D7MTV.docdoc bdfab9675a34c6da34487f2c70f297960002e6c3c2a8e6fdc60ae7edbe67101en/aHeodo
2020-12-2243X7JJ7ZCRV.docdoc e2e85f53c26daaa6cc7e1fe602e51f272ac256cc0c23725350d37b4a5a888520n/aHeodo
2020-12-22YNXQ010LD.docdoc 3341a695c836613d9bba02fa005f2413c407d48a7fd940180b6d4c38788fa592Virustotal results 20.63%Heodo
2020-12-22U2G58GVX9J.docdoc 3a7e77468332deeec16a5228c4b955efb118e0b0d576e638a7a71ac7be04a5fcVirustotal results 20.97%Heodo
2020-12-22447PCAD5C0AWIT.docdoc bf43a06432e503ed88a05c1152818a93af5c9f028441b60e6154dabfab072fafVirustotal results 20.63%Heodo
2020-12-22I1AV2D272L6F.docdoc 27906840017168a094ac6e8680394dc597113999570a3fd5bb8d19005ec8a01eVirustotal results 20.63%Heodo
2020-12-22C8TO9JF000SX1.docdoc 0e0a8e32415a80ba95b8af747d13f3b6312498145d1677df7641ba3c9cf8e9b6n/aHeodo
2020-12-2259TROWC0.docdoc 79b2694e59e609ca6d7fcb4ae72e5c099d9da1a40eb352edeed9d7032ed5c9d5n/aHeodo
2020-12-22AAPY6U04IQIWXLTE.docdoc 755b0648467884ea407cb2be70ee59bdff597edec6e149816e553134e25aaf54Virustotal results 20.63%Heodo
2020-12-22V9QYOVWADPWYOS.docdoc de3fdb0bc2ccdff9476b876a3296cac1568293ab714ff3ef72e020df11bf809fVirustotal results 19.05%Heodo
2020-12-22Q6BJDV5KI8P98YB5.docdoc 964002e25b6ff27acd3902a75ecc4293ba67968a23055e94748a0ba2c31c8d78Virustotal results 20.63%Heodo
2020-12-22NHBX1QX25DLF7S.docdoc c694552f75318998b6225a21646a9893f1a581109b151e283b09868cc24424d8Virustotal results 19.05%Heodo
2020-12-228LGD2P3AQ3IZH.docdoc 8d0a380012f874d975499d45632b01438dc0e7a4d6bdf4791c400e375b02acb4Virustotal results 19.67%Heodo
2020-12-22DQCF9FYSZWN45.docdoc 3cf79aa67b9b74d228fd5e8d25633f13d2282edaa63d6ebc02bc95d05ed4ef45n/aHeodo
2020-12-22CGNU32EBLZ.docdoc 7bf5d728fcd19d3df1127a4d8648cd870c5d123ce9ea4b10eca54cbcd18e10afVirustotal results 43.55%Heodo
2020-12-22O168A6L350R9U9.docdoc d86732f28284b8dbef93bd8eeee3150fa2696a1ccc22d520bd82a2a53c58c32bVirustotal results 42.86%Heodo
2020-12-227OFPZSIWW8Z.docdoc dbd081ee503b65669b9a1a61dac9d5e95765bd9376783e784d2dae26751309cbVirustotal results 42.62%Heodo
2020-12-22OKH9NL.docdoc b4c07579191b925b8d588484fde55e5ff1e83e7b82f482d041b8913d1f2d7485Virustotal results 42.19%Heodo
2020-12-22O2O2C39FIWV3.docdoc 258bf32591a0ac34fc68c8d36075c55b6f45b79eaaf16e3e853ba48e90a3a220Virustotal results 41.27%Heodo
2020-12-22CV1QT6CC5YWUA.docdoc 14bd83ddc0151fe3a56edd4209b619cd49a7ec1d198bb98d31972295a7b0375an/aHeodo
2020-12-22BKU1GU.docdoc eae1bdde070f305ba23286faae3663ed98fb8c5158c0072d382679716e7c646an/a Heodo
2020-12-22ZRXTWWWBAHHBU5G.docdoc 72526ea70462d80cfb3edea310592329d47c4081c3ee6df1184a219a17b1a731Virustotal results 33.87%Heodo
2020-12-2210H1L6VQIAL.docdoc 6b865ef4ff2653d141429f88dc0b8e77f14d9315c583a24169804ef1a619dbd4Virustotal results 35.48%Heodo
2020-12-224QW5IT77.docdoc da6ae027905e668507b86b9b9b4dd2dc2585d7ac3cb4800e01b88c63796e89ecVirustotal results 35.48%Heodo
2020-12-22TGDMIADPJB2K.docdoc 7ec200a834392208ae8521c4804d11ff669137b4265b732a17660527ccf3cf36Virustotal results 36.51%Heodo
2020-12-2209CDV5T4LUL3.docdoc 0ca72ce4d6b45d4c63a514d52e63ef5d16506801e86c1580e6196848f66577d1Virustotal results 36.51%Heodo
2020-12-221S4IC2V.docdoc b243c7cc81b3d66be13ecf0f9876b4e579c80b51dbece8f9a0be2bf85542437fn/aHeodo
2020-12-22OU8T358VRA.docdoc 551910c092733b7324c377351583667a6389e76f8e36f1ee73c82d354f970cbcn/aHeodo
2020-12-221CT6W2RBSQLMN1.docdoc 7be2388880d2ad20b0cfa616a726d7c91d2904da8f3f8ad4d2236d3c79e935fcn/aHeodo
2020-12-22I8ECU3.docdoc 1ebb0eb36a2dba1d5dd9648b8e96e8e7c03fb0cddae7d0060ad0aa7990f5dcefn/aHeodo
2020-12-22EJX1US0CR6.docdoc 6e64c93e0929da5ff396df56de2ba50ef16098d90feea49e0a1973edb6dd4238Virustotal results 31.75%Heodo
2020-12-22FT9GNWXF.docdoc 33b84c4e55798d0445fa4926f79f35d6b12ed272eda6f6686060a47bf22c39c1n/aHeodo
2020-12-222MFQRLAT.docdoc bafc5c7e5ab808736b9a5cf9e676927645b1c02cf9834bf1feb49eb5c5954d24Virustotal results 32.26%Heodo
2020-12-2271BWCKDL3ZY.docdoc 90eb141295b5129c24d9912d41c928c501d0686504aa1f4df32fe72fedaabf6dn/aHeodo
2020-12-22IQBEFT9GNWXFD1.docdoc 88fe3304f1bbeb960cee2ff158f1c2963c0e97a2b2fdabb36a994b35b067b934Virustotal results 31.75%Heodo
2020-12-22RENBH2C6WVDZMUY.docdoc 227f0020c011b4ed270fee166cb3427d282fb03559ba3fb44597f260ec70873bVirustotal results 31.75%Heodo
2020-12-22XXUTSFJPKO.docdoc c6d1e6d03923c2176caab866a4f9253b45abd995a55bbde304bef7eff2d7189en/aHeodo
2020-12-229NAHYQRRJIX8Q.docdoc a442c1871b5de54fb33fa28cd9a9f5b898ba0490d6bd20f09259b15bb81f9ad8n/aHeodo
2020-12-227QS2725HZK.docdoc 5107a8bea0eaf25e9678f18390225717dd772522a6645b195e40d9e9214f058bn/aHeodo
2020-12-22XJGR22LLTLSO.docdoc 131c12376698272b58eac7309a57016198b292bdf5b742e66c1ed352ff788736Virustotal results 50.82%Heodo
2020-12-222UCGGVXJKZZW5JU9.docdoc 8fa65f5db62b92accf6ac97f78141b1121b6fe2946a4d639818589e08cbfd467Virustotal results 46.03%Heodo
2020-12-226K953NQ4L58.docdoc 6adf12a084ccf2eb6dd19a35742a35f03bcba878416ef83b9c520e17d55ac329n/aHeodo
2020-12-2244AXAIUSCBAZC19.docdoc 716592916c6f39ede3e673f03bfadfc09349bf29a45ad31bdd83faa58b0efc0aVirustotal results 45.16%Heodo
2020-12-225GL9PIZVFB5JO.docdoc 6c26774c4763bbbc05c970dbe0b96045fefbdffc80c2d7878e8ca8089f0215c9n/aHeodo
2020-12-229AGBU2AR3TJ3Y.docdoc 97f5f7f2c37a21e2f3934ceabe0df7eea42d7925f1b3a4e9a194fa005509dcc3Virustotal results 37.10%Heodo
2020-12-22FZ9DU2ZL3A2IVOB.docdoc 47d01951e8e4d0425373658359ab6e4e764c29adf9f0a674dc51fc859ee31719Virustotal results 38.10%Heodo
2020-12-22G36QCL60MIJAAU.docdoc ce6fb78ce0ce59ac239eebb55984e0497f6f9616a5a4ab3fe28b63e8456f3e8an/aHeodo