URLhaus Database

You are currently viewing the URLhaus database entry for http://currantmedia.com/cgi-bin/secure.myacc.send.com/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:160174
URL: http://currantmedia.com/cgi-bin/secure.myacc.send.com/
URL Status:Offline
Host: currantmedia.com
Date added:2019-03-15 16:15:04 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Abused domain (malware) link
SURBL :Blacklisted
Quad9 :Blocked
AdGuard :Blocked link
Reporter:@unixronin
Abuse complaint sent (?): Yes (2019-03-15 16:16:19 UTC to abuse{at}liquidweb[dot]com)
Takedown time:1 month, 14 days, 16 hours, 41 minutes Bad (down since 2019-04-29 08:57:39 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-03-15Invoice_9814523465.docdoc bcd76cfbb19148316273e9474206fc37f92a3359838a63c6898368ced0ba3fccVirustotal results 36.21%Heodo
2019-03-15Untitled_201903_226427533.docdoc a5509b36a9b9f001b6ec7abf32474ea8f71e3d79df8567e19b2bb3b30009deeeVirustotal results 35.09%Heodo
2019-03-15Receipt_032019.docdoc bf14aedaf97ce161aa6c05eb12a9d956ccd320a333e7df811eab261657efaecaVirustotal results 35.71%Heodo
2019-03-15Receipt_032019.docdoc 14db79623415fc45e2354cfed559f6c56aa3cae7385f9eb7359f5ad7335cb583n/aHeodo
2019-03-15Untitled_032019.docdoc 01b1232dee4ac560ba34061aa65f5de79c7182de3b6f313ad1a83c39ce61550cVirustotal results 30.91%
2019-03-15Invoice.docdoc dd98ba51e60c6208b445fa6bbfcfa758762387c292698ff1bc3b19bf4c4d2460Virustotal results 29.31%Heodo
2019-03-15Untitled_03_2019.docdoc 555a4d9d27d754c07ff182e3ecc1f68310479ea5a6cb30303bcfba232d49ebe0Virustotal results 24.56%Heodo
2019-03-15Untitled_793326790.docdoc b663ef80f6300005b31579ac18d5525c3958535989acc1b8776f5fe5d10418ddVirustotal results 25.42%
2019-03-15Invoice_201903_2061201153.docdoc 099bcb5b2179f7c14bd95dc7c3f3f19bb0ed63e0bb5ebf8a687fb95947d12430Virustotal results 24.14%Heodo
2019-03-15Receipt_6354123428.docdoc 57277c706a102860896ee631755e31fa9624d1fb3e1683da4ae2bdef627b5b72Virustotal results 24.14%Heodo
2019-03-15Untitled_201903_044214.docdoc 21af84f4b453bf740bd23fd90d43f3f3c135895f04f838a9ddcbc50bcb7f3754Virustotal results 24.14%Heodo
2019-03-15Invoice_201903_351127841.docdoc 531d1d9c1f88f2f4608df5714cded69207e27052a9efa757a95da6007a790dc4Virustotal results 25.42%Heodo
2019-03-15Untitled_7949289226.docdoc aefe7bc9669501aac86e7657da9bee8eae28002b3e1744cdcc1710a242e1fc5bVirustotal results 30.36%Heodo