URLhaus Database

You are currently viewing the URLhaus database entry for http://ufaam789.com/cgi-bin/LslQ2d8Y2BhqMwc1XmtOFIPXCrM21GoAlp2yQQb6LeTWPvUX/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:939166
URL: http://ufaam789.com/cgi-bin/LslQ2d8Y2BhqMwc1XmtOFIPXCrM21GoAlp2yQQb6LeTWPvUX/
URL Status:Offline
Host: ufaam789.com
Date added:2020-12-22 18:18:16 UTC
Last online:2020-12-23 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003190229 created on 2020-12-22 18:20:10 UTC)
Takedown time:1 day, 3 hours, 29 minutes Poor (down since 2020-12-23 21:49:20 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23SF7NJFLK0.docdoc b96bdcbde5a864db016ff0e5d071c9ab68331ac9c87debcf6e019c901fc8678fVirustotal results 25.86%Heodo
2020-12-23MH3Q3I0SKJLEE.docdoc ef1fccd54eea48427d2f6011fe8786cd9ae4f0fc4966130f9f3a99877c49dd04n/aHeodo
2020-12-23H2AASL1F.docdoc 7e0f29831e6732a730d1b231a94cae3a27525976381cf6b97d15fe45c295f239Virustotal results 22.58%Heodo
2020-12-23BJZ1H4XXN2O.docdoc d5231db757615d38ce982ea1272ef281efc93dc8105418c890e8f9e59d76ef0dVirustotal results 22.58%Heodo
2020-12-23G01MF1.docdoc 49b57af908f1e6a1383dd5b05ff24cc5208663b87a405e1e35828689f7c9cdd3Virustotal results 22.22%Heodo
2020-12-236H04QJOSV.docdoc 318cf158cf886f17e7e947feaaf989f25e514c91bec35e9dcca2a4f2ef4baa95Virustotal results 22.22%Heodo
2020-12-235HFOOJHAR63NC.docdoc 44aee606dc504bf6c7dc3847572d34d88c3e5b99c4a2f13d401778d12d69a0e3Virustotal results 20.63%Heodo
2020-12-230ERCOY14XHI.docdoc ebfadd85753d033e248aedd9f9c5772331aff8dc35049d0842e8c423d64ea08cVirustotal results 20.97%Heodo
2020-12-23XWBQYV.docdoc f0a4ee510f94aaef257225740c62c4a65b2da3ced23ca6b1513b9fbe11fd3cd8Virustotal results 20.97%Heodo
2020-12-23ZSCVLB6SC8MNZP.docdoc f2c16e9517e4e5e59a8640d99cda01c3078c6e7720f68f7f47a8a4d7b422b72dVirustotal results 20.63%Heodo
2020-12-23XNXOE20XED.docdoc 3fbfd6e982d209b8a17b661954954d34ed049c93ae235bd736f558199b81aa94Virustotal results 41.27%Heodo
2020-12-233M4Z0YQ533.docdoc ba9ea1c4a35b426bb909eae9b8b40a6acdd5a80c1cea10d8a336338a7b282522n/aHeodo
2020-12-23F0O11IRQWH4XP97C.docdoc 77476e25aa9034df5f54eb93a92ea7144c57945b92eed68b1956044666957d33n/aHeodo
2020-12-23BMUT9WCB816JC.docdoc e269c87f3edd655d2fa4f379bac4ddee2c652386ccd598daf260157b1b9c033cVirustotal results 41.27%Heodo
2020-12-23UVQVZEXLU31G7PA.docdoc 0b92e01b938b2941f4f0940c53a2f53da1f523d08ac18e2f8bc4dd9cc96b52a5Virustotal results 41.27%Heodo
2020-12-23DFWUYJF.docdoc 70cd2d38d41ecad15addac25c6e09641cce2f946161ecf261e639a09576ecb8bn/aHeodo
2020-12-23N87QBYRCW5P.docdoc e7dad257d34343067d95c256a0693969e37308759a34642386f0bfbd66adf416Virustotal results 34.92%Heodo
2020-12-23ZFCX87V8WJM9Z5.docdoc fd76c945ff05629b1e31b55378f97c543c8dce7496389385dae3fd4b8acfd12dVirustotal results 31.75%Heodo
2020-12-23W3GANA.docdoc 2cb1d46e5ca1af22841c4a613b16ee60be1c474065ae89053cc02c6d3740101bVirustotal results 32.26%Heodo
2020-12-23Z2Q4OOB6P8C7F9G.docdoc c80244df2388e37d8c799e9968c52c9ad8c72b789ad85a2a91c35f8c28b0afd3Virustotal results 30.16%Heodo
2020-12-235ULZGO0.docdoc 57f57ee9a02ff9b2983b7b3110a0269f0ac9cf44c8163805edac226aa6a5cc01Virustotal results 30.65%Heodo
2020-12-23D7PLL16NE6F6D.docdoc 58d4bd6bd7acaf8809df8354441ca6b7b0045d93c96f73c90736c23bd06f2563Virustotal results 28.57%Heodo
2020-12-23D07URWGNTK0FW5P.docdoc 9377cbdbd93e4aed19bd96c21d35c83fa1a0927df233e481ce3f7eebe2c0b0dbVirustotal results 28.57%Heodo
2020-12-23LCLCHY4D5.docdoc c29f20dc33cf2304271a54734dc3746f342898284264bd66094dee544fc133bdVirustotal results 26.98%Heodo
2020-12-2361TN5CQ1QM.docdoc 158e3c1a9e0f1942aec57f44ff4569d2a576bad56846a77053f5b4f726c14258n/a Heodo
2020-12-23SQUDDHLQS.docdoc 31f327ab8307786ee50af20aaf5c4c2b6ecc974b69a584c78a2dce04fe5d327en/aHeodo
2020-12-230EHI5LZ.docdoc b6a4c5fd2aa2119a83b7372ac02aa65feae5a7d083a93656c4a437dd865a447fVirustotal results 22.22%Heodo
2020-12-23J7YMIQEHTZ5E4N.docdoc 64e04bddf27b3d535ea895f4dc08267a98a4c401edadc68e3caf7f6f850c4f64Virustotal results 25.40%Heodo
2020-12-220I1WYSS45J8P.docdoc 000b049debe1595e96d46d2cb910795e269d9d3f1b3210bfa45901356b3b3b3aVirustotal results 25.81%Heodo
2020-12-22Z39CM2R16RZQH.docdoc 32dbb92d892c9f50e99fc70db5b9f3efe0721a6464984a3f84e6592cda81684cn/aHeodo
2020-12-22TP2HR9FYJ5X1.docdoc 58c10297f0dc8855dad74aeb405b2efb43deb6f9cb498639a9acfb7a6041f6dcVirustotal results 24.59%Heodo
2020-12-22WHQ3DST.docdoc bc80ebc602752fe60bc486b8620ac2692c2cf2f368e79cecd3a281ce807855e8Virustotal results 20.63%Heodo
2020-12-22UKP1XS9HKPIJ8W.docdoc bdfab9675a34c6da34487f2c70f297960002e6c3c2a8e6fdc60ae7edbe67101en/aHeodo
2020-12-22YSKNB2VULU7HG.docdoc d4f5f3aaeeddc099dd63c275bdb2ae1bfcb6c3232c75e93fa0f670eecb36e518Virustotal results 22.22%Heodo
2020-12-22MYX48N1.docdoc f03c5a8d271acc63d9646bb77c30ddbb5fae5ad755449342e6c34b5ca71a6980Virustotal results 20.63%Heodo
2020-12-22WRBDH80WI3X.docdoc 09539a4c4da9f2859e64cc2653090ed420b3788068156a3dd76a38c60dea7f35Virustotal results 20.97%Heodo
2020-12-22WNBA864ANOKW3YE.docdoc fdae3e00f4bbdb0f496d2b32042e4e5ceb4c10422ae4c809777f5677e0f4a2eeVirustotal results 20.97%Heodo
2020-12-22BL0AXJKS.docdoc c8edf2d6bf8063fe5d26adc5deb79ebba1b6f2d9fb6d25f560e2c4791b6668bbn/aHeodo
2020-12-224ZXK4D1N3A81.docdoc 79b2694e59e609ca6d7fcb4ae72e5c099d9da1a40eb352edeed9d7032ed5c9d5Virustotal results 20.63%Heodo
2020-12-22YDEKJJP5EBQTC4TO.docdoc e50ca86a89c2be0f4e271feba71c17c73e846bfdfc1f3ebd69d442f098acc0a0Virustotal results 19.35%Heodo
2020-12-226XHXHHFEY3WZ.docdoc 73132ef9149825650cd15e4cc30adc5672a95f12f241a676c2887d1af9d205ecVirustotal results 20.63%Heodo
2020-12-22DYHQ0TY3EGH9O.docdoc a5bdf83f7a7007f23b721bd73c5219830d2685673835bcb9a2af37e47ad2603dVirustotal results 19.35%Heodo
2020-12-22MH8ESHHJ27O6T2R.docdoc 7502643f790e60f6929633b08e891ff81ad310001525c345b9dc2b448c1373b0n/aHeodo
2020-12-22WNFGQ0XHO8GB.docdoc fabd2798310f1b90dc1321bffbfa1ee8c41695839459d40fd6e32618d3df7ccbVirustotal results 44.44%Heodo