URLhaus Database

You are currently viewing the URLhaus database entry for http://pusher.co/leg-covers/Sz5ujJHPoe6gvtVuApCNUBs26Kao3Ro1HkpjUgkhP1HE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:937136
URL: http://pusher.co/leg-covers/Sz5ujJHPoe6gvtVuApCNUBs26Kao3Ro1HkpjUgkhP1HE/
URL Status:Offline
Host: pusher.co
Date added:2020-12-22 04:29:03 UTC
Last online:2020-12-23 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003188559 created on 2020-12-22 04:54:06 UTC)
Takedown time:1 day, 16 hours, 23 minutes Poor (down since 2020-12-23 21:17:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-2378O7VAYEPR23I.docdoc 768f3c029cc79ae21d7c732487da93f0e8c7d19a83737f9ce7e107e3adc9054cVirustotal results 43.55%Heodo
2020-12-233TXPZBB9Q0.docdoc 6ed5539e92f43fcde23dc6343c4f41a93050576180fad637adc5014a49ed38aaVirustotal results 41.94%Heodo
2020-12-239FXHGPWJ.docdoc 2baa7224260f2947c16ecfa457d8a36e37774ad2b29d341616d9e1f2a6d4b561Virustotal results 41.94%Heodo
2020-12-23R3A35QANX9U9.docdoc 3e9a6799e7ba70727573d5d792394849b0d94f95a6d0d51e46c3a3340314f764Virustotal results 41.94%Heodo
2020-12-23CPLB0HSF3.docdoc 23c7b6514694abdd61ab7f466352e211d87cc2086939a3efcc14c94251842cc9Virustotal results 40.98%Heodo
2020-12-23Z5796CRJZIH0AX.docdoc 0339f21444ef1ad35fc320d6879ea93b08d3aea53e25aaf3c5b841a2cdad855cn/aHeodo
2020-12-23JERHYG13CQB4.docdoc 7321c475e384a9cd1c118ee71fa5e977ef762d64c7bdea4cecb33d64046469d4Virustotal results 41.27%Heodo
2020-12-23NHTL0I2W9O271.docdoc 70cc44f855631b3a9358c0b5f202406738d8b5c6a21133f6ae2d775aaa3a8ecfn/aHeodo
2020-12-23Q092W8KMOA77VVA.docdoc b45afeb8876a6d7a2a41a6a679095df9cfcf8df3df1a5b5ebf53c74fff0adde9Virustotal results 31.75%Heodo
2020-12-23A4MD1HXUXI4GZ.docdoc 395efc9f98f81ccdcbfe6f9bffdd0e0ea5a2611e4542e43f1241c649713bf46dn/aHeodo
2020-12-23VW5YBDWDVZ.docdoc 08907511869c01824c3fa593161c3d71a507c9a403faefdb197811e3adaa4f8dn/aHeodo
2020-12-23R6GBUU052RT.docdoc 6c5c7d1b7160e3257cdc503f701c9cd77ee2f45e059b200e9dd216b28ce4d787Virustotal results 26.98%Heodo
2020-12-23WHSOGZJ.docdoc 649918360167560700dc33d77632806bcc52576e640559297ce216691ea5dfd1Virustotal results 26.98%Heodo
2020-12-23GVEN5MVJJW0K9Z0.docdoc 63725aa4926dac422d6710c815b80ad10e66b882656195a75ef13b9816cf7c53Virustotal results 26.98%Heodo
2020-12-23MH4F4GQIDBF.docdoc d515c766ed70768021011da8cee6b7e50fa0a5ab48bedcce9dac95adccd4500fVirustotal results 26.98%Heodo
2020-12-235JUWOGGKJWWIKO.docdoc 0149c806df64185dc66ee1fdc857e25ee93def1f7db847487674959d2b9306d1n/aHeodo
2020-12-23N1VW7PE7TQ.docdoc 10e82c9cb8fab1398ba9caf9a04b863ad24859a41262cbc36ae16bed8c2f9cfan/aHeodo
2020-12-235JXUPX50.docdoc cb4f991bd4228ec60ab6af1bab6193e68f4fadf3a30b226e7ee9cdfe893113a0Virustotal results 23.81%Heodo
2020-12-23S030533VHW.docdoc b96bdcbde5a864db016ff0e5d071c9ab68331ac9c87debcf6e019c901fc8678fn/aHeodo
2020-12-2368F63A.docdoc f8d8367d54febac27068bc20e25b1c3260b9bdc78d4874c00368e65ec2e37ceen/aHeodo
2020-12-23Q3RZFN1T4L2O2IZJ.docdoc 8e6a0c5576e309e8d8bc23d6103bc9d355ac27c354d69992c7fe8650d39e10b2n/aHeodo
2020-12-2324H8VIIGCGK.docdoc 59beb0cb64d142274d978c425b55fc8a7e7053f2f8840c09b9d751e56cd6f7d6n/aHeodo
2020-12-23N329K6ILEHZZP7NU.docdoc d5231db757615d38ce982ea1272ef281efc93dc8105418c890e8f9e59d76ef0dn/aHeodo
2020-12-23P5TB9GHTVNC.docdoc d03bdc5b9f72efd01d6cb79bfb3a1a2abb46914234af6d3439f4879a1af9d35bn/aHeodo
2020-12-23RPW5G7PZDYRPYD0.docdoc 241c359520f4cef1af1de9d4789bf620f8086c7feb5aa2deba772b87aef3d514Virustotal results 22.22%Heodo
2020-12-23VV75RNY.docdoc 6083b405a5bfb099398dc2417486e1c2913bba82b96baff811a71ee6feb0884dn/aHeodo
2020-12-23QJPZ94.docdoc 383bbcf6e40f5db6ccf0a07f33eb55614c381daaae647ebf0ed8db148d4ab7fbVirustotal results 19.35%Heodo
2020-12-23R0OLEJ81.docdoc 1b1cb32d2f4a43f7bd1699dd46b55f8deed32e31065c9f13c69f2610b96d41c6Virustotal results 40.32%Heodo
2020-12-23PPT7D7J.docdoc b35a7392b025f6920acb8828e065129ddf5a914973d233f5327619842ca7c308Virustotal results 38.71%Heodo
2020-12-23RZW3JXGO.docdoc b1094f6feb1a423a3b72309f5d023edd3d9509d5444912064029530fe0e8842cVirustotal results 39.68%Heodo
2020-12-239M1ZSWTHA.docdoc 5f5a9d7e2e333beb6d779e447aca446f5bf88a9e05585ef90b1be35599c57ca3Virustotal results 38.10%Heodo
2020-12-23YHT4Z3QMVONY3YZF.docdoc 9e353b38f1dd65bbd6f1e50dc63ddc1350f17b8e382a9fe24328cf1f1609b181n/aHeodo
2020-12-23GS4ZCM9Y7TN1MTA.docdoc b534c439ac7a89c6af82331ebd70e5b5ce5e13a2e871bb7ab122b00004605e97Virustotal results 36.51%Heodo
2020-12-23JGG17RUX.docdoc fd76c945ff05629b1e31b55378f97c543c8dce7496389385dae3fd4b8acfd12dn/aHeodo
2020-12-233STHZGE.docdoc f857002c29ef1a357a541a2a1dc3821d6f7b739ac3602a22be8c6861d0f4b8b3Virustotal results 31.75%Heodo
2020-12-23AEDZTYH27K2PKIX1.docdoc 810ffc95c449b426c6bfc03c98c5e10cfbecbfff7858f10cd9c1c5ec29e2216en/aHeodo
2020-12-23LNQ2TA.docdoc 57f57ee9a02ff9b2983b7b3110a0269f0ac9cf44c8163805edac226aa6a5cc01Virustotal results 30.65%Heodo
2020-12-23SZARHIQTVI.docdoc 1f0dd0263393040d067ed555d604d764634263e4eb014755feb5d319af9db68dn/aHeodo
2020-12-23HFV9YPI5BV.docdoc 9377cbdbd93e4aed19bd96c21d35c83fa1a0927df233e481ce3f7eebe2c0b0dbVirustotal results 27.87%Heodo
2020-12-235YWJ1E1.docdoc 158e3c1a9e0f1942aec57f44ff4569d2a576bad56846a77053f5b4f726c14258n/a Heodo
2020-12-23L93FIMBVL.docdoc 9a8b914d6bb8ae09a04b32fc897fdb9a9ffc073975b436b031ac837b7eeefb0bVirustotal results 26.98%Heodo
2020-12-232XJWDS4ZZ.docdoc 34754f71c9d37d965839231746871e3afcd7cc6d4a4515dffcf6fff4c8e7b739Virustotal results 26.23%Heodo
2020-12-23QLF7QR62CUL9B8.docdoc 1f5a0f7a62383b576ac6f661f97a2c035e72d6f054e5b63ea53123ed9081dae6n/aHeodo
2020-12-2358GJT5.docdoc 31f327ab8307786ee50af20aaf5c4c2b6ecc974b69a584c78a2dce04fe5d327en/aHeodo
2020-12-23B9FA7CAH.docdoc c693baac5d3227d362a0fe99ad187c18cde1f45a404c94c881d424023303a744Virustotal results 27.42%Heodo
2020-12-23W05R5ZWDXCMET.docdoc 996270116a72e21db7ce889a1caf3633d3f42aa2f51aadcec31112c5a590fff2Virustotal results 25.40%Heodo
2020-12-22NEV2R17BC09.docdoc 32dbb92d892c9f50e99fc70db5b9f3efe0721a6464984a3f84e6592cda81684cn/aHeodo
2020-12-223FIDTWU9W6J.docdoc b88940065daeda56e1e49c0db60c1e275b39e435f83b785742242104d173a57an/aHeodo
2020-12-22A458QX.docdoc 2d523850bbd1d5abcaf76fcaceba272f038d954a97263941a3375c3301a1e2eeVirustotal results 20.63%Heodo
2020-12-22WDDRM3YO48Y.docdoc 70325bb19664b06520c37b48c9b0deaa5232904551fa5d01a82ac5a6e735a626Virustotal results 22.22%Heodo
2020-12-229Z4LD0FHCTXEN6.docdoc fb2dc7dac3bf88b2407c132ee3640a68b2eec868b255245d07b6b88306065203n/aHeodo
2020-12-22447PCAD5C0AWIT.docdoc bf43a06432e503ed88a05c1152818a93af5c9f028441b60e6154dabfab072fafVirustotal results 20.63%Heodo
2020-12-22I1AV2D272L6F.docdoc 27906840017168a094ac6e8680394dc597113999570a3fd5bb8d19005ec8a01eVirustotal results 20.63%Heodo
2020-12-22WXPGCEGC71.docdoc 0e0a8e32415a80ba95b8af747d13f3b6312498145d1677df7641ba3c9cf8e9b6n/aHeodo
2020-12-22VNHASNZ.docdoc ffce79e8ecfa61f2f82aa9b40d611c100e6cd68cde6fc34b012ebbd21750908dVirustotal results 19.05%Heodo
2020-12-22YI6HF50A3RM1.docdoc 7202951f9a61583025149c17fbbfd11c028ddf3fb0c080886b3022f117c9b0e7Virustotal results 19.05%Heodo
2020-12-2280IKYIA0DY20Z1.docdoc f111289ca085d7d1ac0e5363acbecf0b4c2693c49a2f56f67eb171795f30909bn/a Heodo
2020-12-22Q6BJDV5KI8P98YB5.docdoc 964002e25b6ff27acd3902a75ecc4293ba67968a23055e94748a0ba2c31c8d78Virustotal results 21.67%Heodo
2020-12-22J8VVSZT46XLDH.docdoc 282e189a38374ce617073f353580971897a17a1eae677743234fa85c73cb5225Virustotal results 19.05%Heodo
2020-12-22AUC045OIW8JIGA.docdoc 424f10f02cae65598b467c5ffdc4eebcc769ffb56ff1dc7e47f50eb7fd31c368n/aHeodo
2020-12-2271OYS3F53ULT5.docdoc 4665b18e5944f23543e9221d4726aac54759376ebfec0ef20574655e71d77076Virustotal results 44.44%Heodo
2020-12-22O168A6L350R9U9.docdoc d86732f28284b8dbef93bd8eeee3150fa2696a1ccc22d520bd82a2a53c58c32bVirustotal results 42.86%Heodo
2020-12-22HGNKBJ654.docdoc b4c07579191b925b8d588484fde55e5ff1e83e7b82f482d041b8913d1f2d7485Virustotal results 42.19%Heodo
2020-12-221NX2M876UA.docdoc 0529eb660d413f7804da233612e8bd55fae073a9f2af58b046f7f8a24a5a99ben/aHeodo
2020-12-22O2O2C39FIWV3.docdoc 258bf32591a0ac34fc68c8d36075c55b6f45b79eaaf16e3e853ba48e90a3a220n/aHeodo
2020-12-22TYJC2GB7SVCO.docdoc 0bf21df6643e15a9eadc034f6e7bb35aa9d1b1433bad331c1944fe60418e23b7n/aHeodo
2020-12-225J9YLQ5X1.docdoc 6f31c56a8ea0949ade1a3cabc55e00d367bb073cfaf7f1b447258c79483910f4Virustotal results 38.10%Heodo
2020-12-226ZJXP9FM92UKZZZU.docdoc 884af4ef4c4cce6b4b6d059a23ddacf8aeb92b68fbb4dcedfbaae3352f1fc5cdn/aHeodo
2020-12-22V3RPNTTNNERNIAD.docdoc 2b9c863d07937c6130c145012febf915401100b8a7e5361cd8244ba88af53411Virustotal results 34.92%Heodo
2020-12-22ZRXTWWWBAHHBU5G.docdoc 72526ea70462d80cfb3edea310592329d47c4081c3ee6df1184a219a17b1a731Virustotal results 34.92%Heodo
2020-12-22UGP38D.docdoc 86942bbcea50514ec00c4794847620c7ab3863657d7cc8119cf593ffb539cae7Virustotal results 34.92%Heodo
2020-12-22O5QXF1.docdoc 6e80cf87bd4ef21287958848ca5250a78cf17cf17f09a9b1b11cd37a01a24202n/aHeodo
2020-12-22NMDZWUN7IUIGF5J6.docdoc 595ca6b04ee946fd5dbbb58b280ad140ada9d2c4f5dff6309281887695c8d4ban/aHeodo
2020-12-22XDNGPT.docdoc 7ec200a834392208ae8521c4804d11ff669137b4265b732a17660527ccf3cf36Virustotal results 36.51%Heodo
2020-12-221AACKHRO7LYM32S.docdoc 0ebdff0201647a1df0ad578dcdfff8ca9e91c379b6183c53845de8e226b95c39Virustotal results 34.92%Heodo
2020-12-22EYEMUD5EVYFMF.docdoc 2eb890f47074a802abff73fabb722541ca607ff36a0139e4d236e875191e0078n/aHeodo
2020-12-22L0DBK6C3.docdoc bcd43a28292c3b23ddb842d173e09e82095f9de58af9eb9feec0035c916e8156Virustotal results 36.51%Heodo
2020-12-224KKV4AP7CM9WSMB2.docdoc 8d81a91518edb9064843167a920609e56978183e85642ee805484047d2629808n/aHeodo
2020-12-22I8ECU3.docdoc 1ebb0eb36a2dba1d5dd9648b8e96e8e7c03fb0cddae7d0060ad0aa7990f5dcefn/aHeodo
2020-12-22EJX1US0CR6.docdoc 6e64c93e0929da5ff396df56de2ba50ef16098d90feea49e0a1973edb6dd4238Virustotal results 31.75%Heodo
2020-12-222MFQRLAT.docdoc bafc5c7e5ab808736b9a5cf9e676927645b1c02cf9834bf1feb49eb5c5954d24Virustotal results 30.65%Heodo
2020-12-22GO4WCQ.docdoc ff2576fe2ef3d0e73e1b95e7283535cf0d6874a1da73b31c6c320f25ac2a4245n/aHeodo
2020-12-222T4A02C5QHV9Q.docdoc 02170586397abeca0120b55a547fd80c877eb800f02d55c6aad2473b369f0a3dVirustotal results 31.75%Heodo
2020-12-22RENBH2C6WVDZMUY.docdoc 227f0020c011b4ed270fee166cb3427d282fb03559ba3fb44597f260ec70873bn/aHeodo
2020-12-22JVZ779AKJR.docdoc 5678fb2398f8ae050763eeb8ef6b94b0c43560105c301b6db5c453c84c7e6aa0Virustotal results 49.09%Heodo
2020-12-22XJGR22LLTLSO.docdoc 131c12376698272b58eac7309a57016198b292bdf5b742e66c1ed352ff788736Virustotal results 50.82%Heodo