URLhaus Database

You are currently viewing the URLhaus database entry for http://xn-----9kccsa1afbhzcgd9a1ay5l.xn--p1ai/scan/EN_en/scan/New_invoice/xdjG-hNRx_vKYc-Dl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:126565
URL: http://xn-----9kccsa1afbhzcgd9a1ay5l.xn--p1ai/scan/EN_en/scan/New_invoice/xdjG-hNRx_vKYc-Dl/
URL Status:Offline
Host: блок-контейнеры-бу.рф
Date added:2019-02-16 00:16:02 UTC
Last online:2019-02-16 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-02-16 00:18:02 UTC to abuse{at}ht-systems[dot]ru)
Takedown time:13 hours, 52 minutes Good (down since 2019-02-16 14:10:55 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-02-16871971673108539.docdoc 179a92ba3314be573380de2049b467d29b33a87f5ee506e357d093e7d7e46f2dVirustotal results 43.10% Heodo
2019-02-16P910857428459.docdoc 443f7a781d38ae6a58d7cf751c8703625b1b8300638ff04befc9142a0e9023afVirustotal results 38.33% Heodo
2019-02-16TPNRZ88699895409.docdoc ce8aa9c7d6c06e5fe37cc386fa16b33343f9d27eb45dcc5d5144ca97465c6f3bVirustotal results 36.67% Heodo
2019-02-16PAY8892389843860485.docdoc 6aa38232450f527768c6b38e64449750bc63fd696743d7b14619c81b6e7ece51Virustotal results 35.59% 
2019-02-16US2661311086936071.docdoc 861ff69651f5fbca47c2db5279af709edfb2d5c1178a131c99d24a873003a040Virustotal results 36.21% Heodo
2019-02-16140882739685732.docdoc 316cec27e95fde63ed487f19008068f1780fb7ac8f89d4b41780ad470cc01457Virustotal results 38.18% 
2019-02-168781381395443440943.docdoc 5b2f2eb326088774f2058a22ec27992f363cc82cf8f3b1446d9d22e21f5cf283Virustotal results 35.59% Heodo
2019-02-16ACC8213879216.docdoc c00a29d9ee8d43768a44fb6a3dd642028dfe059747a008989d37a7e9f8da54dcVirustotal results 33.33% 
2019-02-16308882897.docdoc ee86cb3bfe2e5a4c17b50b3c37d9951164f89a18f7e1a27b92baaf29b9c395e6Virustotal results 32.20% Heodo
2019-02-169118819167.docdoc cb7ffb49be1ad1a74162fa91c0e0a804ffb2cfb462a2bbc1b99389c2e65a5096Virustotal results 36.21% Heodo
2019-02-16PAY584616781654624903.docdoc 496981c2312f8ad24d9d68f2afc93f0225462431c7f32e56ae0faef98f509fd4Virustotal results 30.51% Heodo
2019-02-16ACC433081060937.docdoc 96c21a8f1fe648c4b9de0380dd45120219ab6d0e9766cdbfee7856065cf4cf5fVirustotal results 42.37% 
2019-02-16PAY605515526.docdoc d787fb5bdac0650c933df11e084d90bb33abf85ba388b02df70172953353eaa9Virustotal results 42.37% 
2019-02-16PAY414346685328.docdoc 5514b670fdb2360d7ebe349a792c17932c31e69f9ed79d6acb22facdc2b15d02Virustotal results 33.33% Heodo
2019-02-16G7644844932276562728.docdoc 8c2c81eab3724a093b4fad75d4d8f97b8699c73fd85dbfc68721e488e6162e27Virustotal results 25.00% Heodo