URLhaus Database

You are currently viewing the URLhaus database entry for http://candyflossadvisor.com/eArP_jFX-JMXIRXSH/aPc/Information/2019-02/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:117901
URL:http://candyflossadvisor.com/eArP_jFX-JMXIRXSH/aPc/Information/2019-02/
URL Status:Offline
Host:candyflossadvisor.com
Date added:2019-02-05 21:04:42 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-02-05 21:06:25 UTC to abuse{at}24shells[dot]net)
Takedown time:4 hours, 10 minutes Good
Tags:doc emotet epoch1 heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-06payment_02062019.docdoc598e60462bc61a1f64990cf2639860e85781b0a56f3d1badf9e85c9e4ca7d669Virustotal results 12 / 58 (20.69)
2019-02-06payment_2019_02_06.docdoc4c0a652f2abfa9b8ad4ef88903e96d1743c55ecc935e715a9e9778c169fe535aVirustotal results 12 / 60 (20.00)
2019-02-06payment_2019_02_06.docdoc8f314b59098bd8cfbf4f6ceda569a6472e38b16c23fe4eca6548b19800424aceVirustotal results 11 / 58 (18.97)Heodo
2019-02-05ebill_file_2019-02-06.docdoc611c8f95358a60d965403583c35fd83a89e138ff94c56017bc51b01be33ea009Virustotal results 12 / 59 (20.34)Heodo
2019-02-05PAY_2019-02-06.docdoc02ef9ba79a3664ccc1180177f24660c4dd6742afa69a4dcf88f46110af47120cn/aHeodo
2019-02-05invoice_02062019.docdocb7fc95a2bc7a30daf68c9809cba01c8617e876c753bd0261beda9f4eaddac0dfVirustotal results 12 / 60 (20.00)Heodo
2019-02-05receipt_2019-02-06.docdoc0abbc41f1cedc2e9202f66d9121d46f008542cddb90c306d4285f83db662783bVirustotal results 12 / 58 (20.69)Heodo
2019-02-05bill_02062019.docdocf534dfd35d9a361f68be09b596dd207675b1e93b8f0049201cd8c6047e727a23Virustotal results 12 / 58 (20.69)
2019-02-05PAY_20190206.docdocfabe6396d0f66857df66a99e1d28cb788d48a6d02014c878fc9edc11806f6cb8Virustotal results 14 / 58 (24.14)Heodo