URLhaus Database

You are currently viewing the URLhaus database entry for http://jitkla.com/mambots/Overdue-payment/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:10735
URL: http://jitkla.com/mambots/Overdue-payment/
URL Status:Offline
Host: jitkla.com
Date added:2018-05-17 15:23:50 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?):No
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-05-18Open-invoices.docdoc 22b94903d6c21b6af7e3aec0e6e0799f49b3c7da9316aa68d6cb92c4ded80f62Virustotal results 27.12% Heodo
2018-05-18Service-Report-58750.docdoc c9e6dd2d2945839fa72e0f6850cd299613ef7e09853b27b97bbc273f68e999c0Virustotal results 20.69% 
2018-05-18Outstanding-Invoices.docdoc cb690cb278f95f8b28eee18ee13352c6adbc3dcbaa7bf5f4a4ce12878e6d5e34Virustotal results 18.64% 
2018-05-17Invoice-Corrections-for-65/46.docdoc 1daa2556fe70041ffa6eba12c46b1b610dc7acd8d3f93f0640fb3b36dc3cc4aaVirustotal results 13.79%