URLhaus Database

You are currently viewing the URLhaus database entry for http://megascule.ro/BwGE-JO_kiM-qq/Invoice/7478991/En/Service-Invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:103621
URL: http://megascule.ro/BwGE-JO_kiM-qq/Invoice/7478991/En/Service-Invoice/
URL Status:Offline
Host: megascule.ro
Date added:2019-01-15 14:52:10 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Blocked
AdGuard :Blocked link
Reporter:@malware_traffic
Abuse complaint sent (?): Yes (2019-01-15 14:54:06 UTC to abuse{at}gtstelecom[dot]ro)
Takedown time:2 days, 11 hours, 2 minutes Poor (down since 2019-01-18 01:56:44 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-01-1726451355761822.docdoc 8c03b497222977465fe7fcb76f22dd288f6412f39dd636fadd93a33fb5db424bVirustotal results 17.54%Heodo
2019-01-17PAY210465562421937677.docdoc a1100c2924068c7644213e18725dd9468555abd8c5d4102c4da3537d904a1d46Virustotal results 15.52%Heodo
2019-01-17PAY492255148943537.docdoc e14235e1a65021134395b8177252844b1fbfadd5d7ff4ad4a0d3121dc840fac1n/aHeodo
2019-01-17ATT250077612166191.docdoc b596ba2574e7ffdeee42a68c5984dc026c5fe047ed5aaa6a05b55713b1240aa1Virustotal results 17.54%Heodo
2019-01-1727171534093.docdoc ce1499f8ff66310eefbf92618c53f5584af11bdacf5088818f6edb7c794989e7Virustotal results 25.45%Heodo
2019-01-17ATT7208409007.docdoc fa2a9972975eee1ac59eda3149892beeb2c51949ab3221cdeda6a51908878617Virustotal results 20.34%Heodo
2019-01-17ATT5879045587339422874.docdoc 0bf5146bd9a780fb8b7d49e98a74264cddbd93fbd4987a78a7cd3f211e235dd6Virustotal results 21.05%Heodo
2019-01-17US060311752235.docdoc d22a0418df5b3f9426caa353e24c005d7746b4713ceee32cbbb886041a60d195Virustotal results 22.81%Heodo
2019-01-17208605420.docdoc eb2c2c89f70674a29359fcdb8d584df533182663d1caa71a969aac20d5c9b99aVirustotal results 21.05%Heodo
2019-01-17PAY90142995730.docdoc 8c27ab6286b9b097166a1717df3186f92ef8c1037e2c2c89b8e7834482109d4bVirustotal results 17.24%Heodo
2019-01-1708946648865784.docdoc 91b9982b4dca79753b777f715dc8ddc5ff4e8a239b6bc9696ac08a11797165faVirustotal results 18.97%Heodo
2019-01-17PAY92036333468754913155.docdoc f57e34bac3ba01449d2eee5026b76a53bf9f7fc23ce14b421d7382866ec3164dVirustotal results 21.05%Heodo
2019-01-17ATT97854036103297679928.docdoc 34db885f2f34af721ab4e883ed9a6e88189b826bcbdbfc33317047925bf837a5Virustotal results 17.86%Heodo
2019-01-17403809171946772.docdoc 22e447125a0943219d4f3a3b92ccc1c226580715ea508a93f6d7a1caedb4f55dVirustotal results 16.95%Heodo
2019-01-17ATT4311358923850767228.docdoc 7e4852c4cf7201cf46af76adc3297244bdc76f8bda1e335289b8968fe0816088n/aHeodo
2019-01-1714824045631248705.docdoc ca805254ac49b9c4f36fd9c13ea6f053614c7f7c5227d40e2e7d5ca529873297n/aHeodo
2019-01-17US32228887578528847560.docdoc 7463cfdd3562d9f950c1ff9c7d60f5a1cd87be03b16b7ea120d4a945b1bf147dVirustotal results 22.03%Heodo
2019-01-17PAY1185889250.docdoc 9e029e7e84abd91bc4045b2e94be71a178b07a91a8ac0745f1b3d520816ca256Virustotal results 21.31%Heodo
2019-01-17ATT566267667.docdoc 30afdd7bb8e1599ed650397fee21197abb47a871fa4c5dbe58c2ba977ff1cc3cVirustotal results 22.03%Heodo
2019-01-17US190452164702456.docdoc 141b85270a591157af1369b2729034eb5cec87445b3fb604ac5df6118ad77a2bVirustotal results 24.14%Heodo
2019-01-17US7381685380738703213.docdoc 5263d5b52ab1270adb432db5bdab2adf613c65c07adc8c71d505f737cd6d61e6Virustotal results 22.41%Heodo
2019-01-16ATT6912529456352603935.docdoc 7af0310a3b108e72739535916ef251b916f3cdf56478e460d230f28f6edf59bdVirustotal results 22.03%Heodo
2019-01-16PAY98671566226349848800.docdoc c36d7096ef6b23ad823450baf8544a5a1337363b370ca54c971ff69c2f0629c4Virustotal results 21.67%Heodo
2019-01-16ATT52038891164320104.docdoc 0be992cf0ec92ada0f3428723f9bf54697d9a70484f040a77eac7f4b692d2e9dVirustotal results 20.69%Heodo
2019-01-1613091011050655597115.docdoc 9b61ed22df0d5944d9a010b769fc238434495b727a207514b3f853227ff3ff30Virustotal results 21.82%Heodo
2019-01-16PAY247089605.docdoc 7b2286f0e134bb111f5bf9a70295675e2a501702dc6ee12ebcb7816140535dc0Virustotal results 22.03%Heodo
2019-01-16US926855742323.docdoc d890f2319d290366dc67d7ae02bca217ca67c99962de05a0f3f6fef9e51d4b4bVirustotal results 20.69%Heodo
2019-01-16US7455444588656760.docdoc e1e2f66cee0e652e0decfbe57562ec0b7956306a0663a6da0562acb1e8c9ee69n/aHeodo
2019-01-16ATT26367155238524017200.docdoc 33868d985d0751c5b2850beca90f23502600245203cb8ff210ea08b52dfa87e1Virustotal results 20.34%Heodo
2019-01-16ATT70067554538525.docdoc fa59df0ed78b6bb35a62c62cf8a6b2047830349133f7c3feb2a359c7640d1b1fVirustotal results 20.34%Heodo
2019-01-16US6151758666132711.docdoc aa45e32651af4fbe9065dc15e2567c44cc8f531270f8dcb201a5df7a4b21f03an/aHeodo
2019-01-16US59551888625608.docdoc 3ec774623b6beb04a3c8e935a169e0257cfd30929abb973795b20f1a7f0b5fecVirustotal results 27.59%Heodo
2019-01-16ATT862601102507616563.docdoc 4f034492bc4d152f98c083ba3d9a1c24b3062a2917c89551857c4d310e481c9cVirustotal results 24.59%Heodo
2019-01-1694614019130874159377.docdoc 01410e94e39c764aa99b933ac899a04eba0a77b25ecd1345f99253f37e9dabfaVirustotal results 23.73%Heodo
2019-01-16637090528.docdoc 0b7553fbe2886d6989024b9e3f2b17696442f543065c5a12e0b901e339fbcf05Virustotal results 24.14%Heodo
2019-01-16ATT43856698021.docdoc 0c77c98412d30765b2d8c8bdd38f503927770c0a08b45cbf812b1a2cc1240b28Virustotal results 23.73%Heodo
2019-01-160005280766704135.docdoc ee5583eae1e0bd0df20ed0b53900bdb750e24e741b575e33593c94c311cab871Virustotal results 23.33%Heodo
2019-01-160412883846932442.docdoc dc36ba3238a3f4761e54cc6f9bc4b43420cdb2b00705574d61898b7c5acf003dVirustotal results 23.73%Heodo
2019-01-16ATT97210665095415267.docdoc 116e6f63bd00606d7861a22bd786633c7d7d1e99c61fa2827429ce8c8a53499eVirustotal results 25.00%Heodo
2019-01-1641229776266308.docdoc 22221150a875fd5e24ee0a554b2cdead6543e35b6899641a3f21425c632b0201Virustotal results 25.00%
2019-01-16US0278217358023327.docdoc b1ed504b77cb03d7387f7cb22a98b12b661281d8983cf21fd702c7bf95129c7cVirustotal results 25.42%Heodo
2019-01-16PAY34120007139663182002.docdoc e7c1d077cbd3dd185b7e7ecd6ed2f0195b2ea098e571c78ba60da5cff90c897bVirustotal results 21.31%
2019-01-16PAY20866116883786589125.docdoc 90113ff1e4b8bb81a5f9eab309f7fa4eb349ccf741a13ed040787e3399d6eec4Virustotal results 21.67%Heodo
2019-01-16129070967839.docdoc dfdbc3d210ce4c6bf12603e227f2312e8b24baffa18959d65f2e7f548a52275dVirustotal results 21.67%Heodo
2019-01-1684012248167589.docdoc 8eae2ed2491c609398b61e288147d6071fd51ab08ab785c6fe770f83dc0152b4Virustotal results 21.67%Heodo
2019-01-16PAY119698112407.docdoc 74b9305b76f521916b8c989d7e650c8f5a5bd9bd93700ec6f8de7e3093e34b20Virustotal results 21.67%Heodo
2019-01-16ATT1523637526886381.docdoc d889f9026c11807d7c5eb44b27475d33b7960398bf2abf7acba35b381de99380Virustotal results 22.41%Heodo
2019-01-16PAY88074445700587.docdoc fc3047318d92da05133c410c2b7847da7e9beed33d7d294265d90f50eca8bc3fVirustotal results 19.67%Heodo
2019-01-16ATT7639987165.docdoc a54aee546321a9f8cce4b3f90fe12e293f606221472287b8939eaf74d18f2a9bVirustotal results 20.34%Heodo
2019-01-16US71600300397.docdoc f840a19d13ffa79af18029f409cc5cf9c6511fb7a97344d8c0ce9e1d4bf88f27Virustotal results 20.00%Heodo
2019-01-16US46860627445047738903.docdoc 64221fc97450e3aaead99f762fd84fbe1ac02be9f11ec22ad49eddde23eb034eVirustotal results 16.95%Heodo
2019-01-16PAY546754420609902967.docdoc 11d3a960368ceea3387f2b25f5c488f84835ea9d04c01a9e8fe043e49bd02496Virustotal results 18.33%Heodo
2019-01-16US0984838319.docdoc 4e956fadcd623971562214f47bfada881bb9a4e222d45a57c28c285dbb8f8369Virustotal results 17.86%Heodo
2019-01-16790032033704398.docdoc ad19964733761607dfa3e86a27be17de79bf6580e62588cc90a2c1a9a9bc8f53Virustotal results 16.95%Heodo
2019-01-16ATT62120184713739.docdoc 6c6cde186a8b11112384e7e53ecff759d36b1e28463cbc63b1822875ae5119a4Virustotal results 16.67%Heodo
2019-01-161818860371294509.docdoc bf34cdbfc143baf710e25dbbb29c52a557bbb0485e5325f085f926f32507ba63Virustotal results 16.67%Heodo
2019-01-16ATT643546044048.docdoc ba42bd3156b959557c225c8b8eebcc02394c935b8178902835924d1a150325eaVirustotal results 16.95%Heodo
2019-01-16PAY059256292694.docdoc 9b8d80b18ce7849e7be22615a192ca30f4cd2bafee6adb7b26ffb78a6ae548f5n/aHeodo
2019-01-16PAY132772053418727.docdoc a38828d94c38717c5b6c9c0ab04d792a7770e3737a1a8951259844e0d50990aaVirustotal results 21.31%Heodo
2019-01-1674291767184097180.docdoc 449e1c3c24a918b1b1ece85fe541330bc522b91d13b73280bc4774367f7c1895Virustotal results 17.54%Heodo
2019-01-16US724312436261.docdoc f9da355e1b1d67d942ca779d8dea13f69aef6d24b53bdc59df1985ddb5006d77Virustotal results 16.67%Heodo
2019-01-15US7029324405327517827.docdoc 71916eb78ce88fc298f25df2ebd8bdc253af4188e7f38e69d1b419f79102151bVirustotal results 20.00%Heodo
2019-01-15409256941.docdoc c84d790a70c401e4495ba92b136d9eba9245387b71f96c43242d74c30226ecdfVirustotal results 18.33%Heodo
2019-01-15ATT452297066155838925.docdoc fa12e8e59f2152cb3435882d7b039e961fd54789603b0cb47e1d5f5131f4ab3an/aHeodo
2019-01-158733283893222603141.docdoc 9e2df12a882dec091626f97192f98f27e565b2ea141d9245f1991edb881b6c45Virustotal results 18.33%Heodo
2019-01-15PAY72760396037.docdoc d0b5126b634f66c07b00a44ce7c0ea06e342e5354b275ed247aee67836b4b36cVirustotal results 20.34%Heodo
2019-01-15US7083029410063532500.docdoc 1abdb7044de2d11edf413a4e3a8b661d4fccabefd7b6e82334b6be08686a59b0Virustotal results 18.97%Heodo
2019-01-15PAY1650694809111.docdoc 784f5ff294989088c4d13237fb0f14cdcfb3394387250d645e40ec57af05be31Virustotal results 16.95%Heodo
2019-01-15ATT9948146524326.docdoc d10be6e5a5cd1b04b0e1faae92ba4e29f6aae6c55877a8ca9c21a52bb24b653eVirustotal results 16.67%Heodo
2019-01-15ATT251248368.docdoc dadfe9c8cf19b0f55b98147b72ba7e0849bae74e74cf4445830636027819729cVirustotal results 16.95%Heodo
2019-01-15PAY83001323070414782772.docdoc e23f4d9bccca4aeeba5d0fe21ecdbfe35c733e182e93bd5d19a83f50d8d1d364Virustotal results 16.67%Heodo
2019-01-15PAY15998991619636.docdoc c6bb5b80feae0cb8669f710efb1799e37fc24bcf6fac4c98735f1062cd32cab8Virustotal results 15.00%Heodo
2019-01-15739693779285593.docdoc 18919d6d26913abe27d00c1e64b701c2ead8cf34855863910389828388ae23d9Virustotal results 17.24%Heodo
2019-01-15PAY4445112375522.docdoc 98081b4049e02b007390f7f3d833d1ba526812f966828d0972dfb8e1faeeaf6cn/aHeodo
2019-01-15ATT026465059282298981.docdoc a8c8e126000bf6c7761b0784528b7ea4f93f3d967fc5e5e8f4644afc2d4fc8fdn/aHeodo
2019-01-1592825049684432.docdoc e18ac5345546b11319dde33e33421c03eddfeb44bc0d366114a452b6bc6aad6bVirustotal results 16.95%Heodo
2019-01-15US4360357005358266.docdoc a016a676a1623fe33c04d041ddbffd963a2db3e560442c0e8245455f624b40a5Virustotal results 15.00%Heodo
2019-01-15US970362977.docdoc 261e09d049e9361cf9229130dcf41d429f5805a9495bc1dd41203251a46c9122Virustotal results 16.95%Heodo
2019-01-15ATT18398871385474669.docdoc 54a10493652ed3ec5948775d594e34bc5b30412fbc030fe7b663a5f4a6c6ceaaVirustotal results 15.25%Heodo
2019-01-159282600709522207093.docdoc 106cf7ada1f5b7a586d3f26c562afc7c0295548fda86f68c76ec4bdaa1031061Virustotal results 15.00%Heodo
2019-01-15ATT8711016424219.docdoc 02399c48e148b053be872b0b2109ee53ab9aca9f59a030f77de00a8d9fe86239Virustotal results 15.25%Heodo
2019-01-15US78440532015059.docdoc b0d858c9dc5f9159c61d8ff59f1aa0d974083be435c1a9b420cf5939e14c0cb1n/aHeodo
2019-01-15ATT6701570175101.docdoc 981db5daa08ed93a9edba672c6246fb4559f285e230c84762719532bd0ef2968n/aHeodo
2019-01-15ATT45548914148.docdoc d1a8020bbc1e0ee0a51f48e4ecdff9e7e3a8630f593c5f43377f7971e41d35d8Virustotal results 15.00%Heodo
2019-01-15US3028166374.docdoc cfedb49ef13185d61f0e08af6c1f08fa2014e4106c974f532448ebdee25bc07eVirustotal results 18.64%Heodo
2019-01-15PAY645069866.docdoc 8814926242e7b4db726f1a6370265554057d70d71c1c069d7bfe65155d1c5f72Virustotal results 16.67%Heodo