URLhaus Database

You are currently viewing the URLhaus database entry for http://altarfx.com/LNtTZ-CN4cV1Fih6eYit_dVkfyDLau-iv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:96401
URL:http://altarfx.com/LNtTZ-CN4cV1Fih6eYit_dVkfyDLau-iv/
URL Status:Offline
Host:altarfx.com
Date added:2018-12-17 16:49:50 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Spammer domain
SURBL:Not listed
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-12-17 16:50:41 UTC to abuse{at}hostway[dot]com)
Takedown time:4 hours, 15 minutes Good
Tags:doc emotet heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-12-17PAYMENT_6183481ZMUUDAYZ.docdocb8678e574a1ea9b25601b8fdfb46ce7061b35f43cad9a7688de8f12c9657e2e9Virustotal results 16 / 58 (27.59)Heodo
2018-12-17PAYMENT_648149AMEALQL_12_17_18.docdoc1427da3ca8f0daa57d17681f357ebf21bab118218054cd6051fbacaee996b2d7Virustotal results 17 / 59 (28.81)Heodo
2018-12-17ACH_992EUKWRW_12_17_18.docdoce8a06d9faebb561e5b33e6616484870d2e5c47e92dd4138d8e7f2d72f20f1a53Virustotal results 17 / 57 (29.82)Heodo
2018-12-17ACH_216XPYEPER.docdocabf57db83c704eb1330eff70afe8a351e3120cc2df6e9b114c55053222e97456Virustotal results 16 / 59 (27.12)Heodo
2018-12-17BIZ_49765SZLREX.docdoc884781beac926c7f0d2fafd86d7c2e9adcb975c6f0dc95590e9a9053cd6e66d0n/aHeodo
2018-12-17PAY_876PUYQDOX_12_17_18.docdoca83a4f2f1317b8355893f9855e000022edd090117b011c0fec52ff54a4166ac1Virustotal results 18 / 60 (30.00)Heodo
2018-12-17PAY_5EKBBXAA.docdoc6cefcccb04cb8279c8e526df0493a652757070895024883a93cb0fd6a46effb1Virustotal results 18 / 59 (30.51)Heodo
2018-12-17PAY_9VHGVJFN_12_17_18.docdocd2d4dd6abfece8c4ff8f038241e9c3786cfaa7b1d7980ea9900b95b8b7496e8dVirustotal results 18 / 58 (31.03)Heodo
2018-12-17PAY_880453KKMICLKV_12_17_18.docdoc8effa8d24257d3cf6a49fa740d57b953d30a5eb7eafcf6b6aa6032fa3b3fe412Virustotal results 19 / 59 (32.20)Heodo
2018-12-17PAYMENT_9676RZHXLTHG.docdoccd58ef6b3f85a12a56aee211aaa32ea7b6bc2b9ee09a1e0f5eaf80bfa83bd67fVirustotal results 19 / 57 (33.33)Heodo
2018-12-17PAYMENT_81EDAWIN.docdoca7fc4292a2199a88ccc065039d3c0aedc498363934ab5b44667aa40bc0c7a0d1Virustotal results 16 / 60 (26.67)Heodo
2018-12-17BIZ_55755CVLYLVM.docdoc5fc837cec1abb150354341cfd7c63d4207320bf62164728c435cab8d8c953bcdVirustotal results 17 / 59 (28.81)Heodo
2018-12-17PAYROLL_572RQEWVEEB_12_17_18.docdoc1494e0e1b3d206505f792badd5b63ec6965f130cdaf95aa426a18dec1de69d36Virustotal results 16 / 59 (27.12)Heodo