URLhaus Database

You are currently viewing the URLhaus database entry for http://mirusstaffing.com/UPS-Billing-US-June-095/1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:15511
URL: http://mirusstaffing.com/UPS-Billing-US-June-095/1/
URL Status:Offline
Host: mirusstaffing.com
Date added:2018-06-05 15:35:03 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-11 10:25:20 UTC to abuse{at}godaddy[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-11n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2018-06-06open-invoice-June-090R8548/8.docdoc ae173035d9362c2ae0d807af3181e7d6e306f2ef1ef7697eb61ecdb306f31821Virustotal results 25.00% Heodo
2018-06-06INV-document-June-06-089/380.docdoc ddbd3c102c34cf64699283b4c7ab55479dcb85c23b813926fbbc5ea4ee7a3ec8n/a Heodo
2018-06-06INV-document-09K253/19.docdoc 1eef38f1d659cf3f516dcf6ba50c7b6296f6384e290f91e4784154b859a183ceVirustotal results 40.00% Heodo
2018-06-06new-Invoice-June-06-039-53880.docdoc 1eea03bdcef98b27a8b73a640014107d51f33775f187c3b246b7ab440ce5406aVirustotal results 40.68% Heodo
2018-06-06past-due-invoice-June-06-022O8532/6.docdoc ec00189498b668dbb44abd187b80de6e22ea79736d5793246c84b0e1ffc18484n/a Heodo
2018-06-06corrections-083269/56.docdoc 7c6927f81db22f59270fd02e255a8990e983f4db89d7e77b19163d362c0ea45cn/a Heodo
2018-06-06INVOICE-04-1394.docdoc 1c42571247e3e6c2e046644b6d4cfbef649a7a60af976b09836bed68e7a750d0Virustotal results 35.00% Heodo
2018-06-06Invoice-08880/7.docdoc 7e71d0990309ab69c1f037f49f1ee28a59b4b1a11895b5a7827f296c0155726fVirustotal results 31.03% Heodo
2018-06-06Inv-06062018-039624/37.docdoc 04aff85ff1e6d2504e18df0e99174f5ae4190c797f158bb50d7aa302eaf291b7Virustotal results 28.81% Heodo
2018-06-06Payment-receipt-June-050825/87.docdoc 2bf857edaff236b0b89e9e41bd3105ac4bcf44a47cb24c27bfaef2b402b0be8fVirustotal results 30.00% Heodo
2018-06-05available-invoice-09518/78.docdoc 3e1104205778d2e06154efae7b26b2e665292b45860aadbd5050874d4ce88c32Virustotal results 23.73% Heodo
2018-06-05for-check-June-07F3896/0.docdoc 0e2122fb15f833766d78a52c9374ed30e90f557e608c270063be5b5172d39d59Virustotal results 35.59% Heodo
2018-06-05Invoice-form-08/217.docdoc e4c2fe61344da7f72e1d869e2958280f69f9eefc0b56b26effc63039981aa38fVirustotal results 36.67% Heodo
2018-06-05available-invoice-06052018-01/0351.docdoc c7fd6d2dc4035b538015b130fd9e79a539097dc024193ebd71d23ced4661fd9eVirustotal results 36.67% Heodo
2018-06-05invoice-028/986.docdoc 5c2ea841aa113939aca637de690e296e08c0a39c79f40ce4c814951968686112Virustotal results 26.67% Heodo
2018-06-05past-due-invoice-06052018-081-8562.docdoc a93a1cf204e2f16476871af0b1168139825499cb5dae3299fd43fb8c14753cf7n/a Heodo