URLhaus Database

You are currently viewing the URLhaus database entry for http://chigusa-yukiko.com/blog/trust.accounts.docs.net/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:158771
URL: http://chigusa-yukiko.com/blog/trust.accounts.docs.net/
URL Status:Offline
Host: chigusa-yukiko.com
Date added:2019-03-13 20:15:04 UTC
Last online:2019-05-22 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2019-03-13 20:16:07 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:2 months, 9 days, 6 hours, 4 minutes Bad (down since 2019-05-22 02:20:07 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-14Invoice_03_2019_63193694.docdoc 459397a134b2b4a201c2855bbb2ed4d1eeda9cc7637d7c65201e0a78217a8780Virustotal results 29.31% 
2019-03-14Invoice_3688423.docdoc 8de3f82c3775e3c0b38daa26bc3f7b7a6cc6a67ad8d99b02f92bc5e0da60263cVirustotal results 26.79% 
2019-03-14Receipt_201903_6358837620.docdoc f8218ee2327f0a0d1a545aa4289a62547a4f5c186022939b8e7b7300f5dce0a8n/a 
2019-03-14Receipt_201903_96220527.docdoc 21019fdba804009eae5d26e4341954a66178838fcd0987bc4c5fa6407cf02ea9Virustotal results 25.00% Heodo
2019-03-14Invoice_2497524406.docdoc c2cc283b1dacbd7b0adcbe069aff437c1fc7c93ffd2d3bad152333301e1ca913Virustotal results 27.27% Heodo
2019-03-14Receipt_814433.docdoc 312ffe5cf618e82bbe2ab1a4425b6c2927319b52c0d440721a97f3eda519f145Virustotal results 33.93% Heodo
2019-03-14Untitled_906374718.docdoc a97fa9403745a0870ce9825e8b6d5591b53dfa935e52e09d874f9118a661207fVirustotal results 26.67% Heodo
2019-03-14Receipt_03_2019.docdoc d1f2d6371dac7d666a0286551b68bf5bff6fd0c105a36c602272b7a33a8f90ecn/a Heodo
2019-03-14Invoice_201903.docdoc f307734cb3bed7d13b9a497d3388eed0aba98bd1618c2419a4c72fe609006c06n/a Heodo
2019-03-14Invoice_03_2019_585311556.docdoc 9f121e7e36b53ee05c9514868ff7bf9ac111bf4c37d39e00927a50417d6e042aVirustotal results 25.00% Heodo
2019-03-14Untitled_6320030680.docdoc 9688017da94967bee0abaed3a776532c84aeef410c40dcdfb477c2060b05248eVirustotal results 24.56% Heodo
2019-03-14Receipt_03_2019_886377058.docdoc dc2d7d84c882fbcb016241f24c84e12a57310517357d87b6733cc697bacbfa02Virustotal results 26.00% Heodo
2019-03-14Invoice_201903.docdoc 807dcf4834bfaa4587ab4cf4ae71fd1c0d1f64b67dfc9341e001b1efb6b1e949Virustotal results 25.42% Heodo
2019-03-13Invoice_032019_495184.docdoc 78d791edc7d71e6fc275a9bc93e66a58934f4cd2ad6b5468cb021d1fbd0d13c7Virustotal results 25.00% Heodo
2019-03-13Invoice.docdoc 8f03a01f8f47e53607f1a6a9297a246e336df4ea26d62a8560652bae569a3fb6Virustotal results 24.56% Heodo
2019-03-13Invoice_201903.docdoc 2e93e7c34ebf56a7df68553db3978fe84969e0689f6df6fd66f04209d2a6efa8n/a Heodo
2019-03-13Untitled.docdoc 0d5981ea8f3a35516b953b2a7388228ecc2f89da80fec3ac5b13dba11145edacVirustotal results 24.56% Heodo
2019-03-13Untitled_03_2019.docdoc 42a2583e3e1d624482f525e388ca5aa9a13f7f9759c10712879280a105b0f47dVirustotal results 24.14% Heodo
2019-03-13Receipt_1338631153.docdoc 1de033897656da4d0da38e639e78de54d3a98a93d3439787fe2eea65024cd960Virustotal results 25.00% Heodo
2019-03-13Untitled_81074933.docdoc d3b83219e9d0b536ebf678843e2f58ee30cfa9496ce391ebead925e0d1e4bb6eVirustotal results 23.64% Heodo
2019-03-13Receipt_201903_569573812.docdoc be0c3609eaf16a3be0029364ff4ff8ade035332b134e5a0768e7b8cacc210262Virustotal results 25.45% Heodo
2019-03-13Receipt_201903_66793507.docdoc c215620d5042541ca6333af0bda5d949d9bf4474a576ef376646fa99349b1a55Virustotal results 25.00% Heodo