URLhaus Database

You are currently viewing the URLhaus database entry for http://plugnstage.com/logo/sec.accs.docs.net/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:160355
URL: http://plugnstage.com/logo/sec.accs.docs.net/
URL Status:Offline
Host: plugnstage.com
Date added:2019-03-15 20:58:17 UTC
Last online:2019-04-16 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-15 21:00:03 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 month, 2 days, 0 hours, 47 minutes Bad (down since 2019-04-16 21:47:47 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-16Receipt_03_2019_5449653.docdoc 176fc8d7c9b766558643e303d26923c6fa2986729865aacc86f3221f2c97f05eVirustotal results 39.29% 
2019-03-16Untitled_032019_899128.docdoc 379e9857bb740f4443cf3ec144d39eb6108d6d30bd939b6cbc68461d45aec375n/a Heodo
2019-03-16Invoice_6930264.docdoc 3826137a54e6d54a11fd3abc91ccf1f6a8ebe5fb97249b9acc1b78743e7fd2b6Virustotal results 41.07% Heodo
2019-03-16Receipt_032019_385454231.docdoc c2fafdea65121542a5eaabc866c357056578622b9ad35c5eec9d6b1f0a0e32ccn/a Heodo
2019-03-16Receipt_03_2019.docdoc b542e1dcee9bd6b5f6e568ab45e96067c823d00510b6e557f2ac138d3ef0ba70Virustotal results 41.07% 
2019-03-16Invoice_201903_3385869525.docdoc f02e6224c6abab128890cb86360afa3503ae97f368223ee0a55f0fa90e412152Virustotal results 38.60% Heodo
2019-03-16Untitled_03_2019_9004836162.docdoc d92dcadbddefbfb244f1f8b98b642fc25769f48a7ddca9cf2717ab7535ef3179n/a 
2019-03-16Invoice_487489.docdoc f973bf6429cd7f943327f693d3b924b7d8f205a063e82afb324704c3656c7f0an/a Heodo
2019-03-16Invoice_201903_093554664.docdoc 3dbd2c570a9fefab5ae5423b4a1e4ee2e5880690db9d44a85e76352e07b2421eVirustotal results 39.29% 
2019-03-16Receipt_767531.docdoc d5045f79618588abf0f79ca1aecd5e75e586453da66a54efc266df943852d44fVirustotal results 36.84% Heodo
2019-03-16Receipt_032019_0684380715.docdoc c3ea24f00b1c7d19ab9a5950fca634cc48472ef956529aa76fd97e5bb3acedc0Virustotal results 37.50% Heodo
2019-03-15Invoice_03_2019_4670116360.docdoc 72f4edd6d9a0d0f97af9d60ae15fe29fa3fb47a36b8a431004868e875192699fVirustotal results 37.29% Heodo
2019-03-15Receipt_201903_258054.docdoc 8835c4045c9d6fbd9e4ea35529a3ab434369458feab327a7d08ed878cc6f5925Virustotal results 37.29% Heodo
2019-03-15Untitled_39103099.docdoc a203b6af59485d57d4530f2ba99f787233466005eef20da05b17976311370e2fVirustotal results 36.84% Heodo
2019-03-15Untitled_201903_8879624531.docdoc 5c77f3a493cabe60afa8403288fd2cf521c373dbf286aa4299d5195a602161baVirustotal results 37.29% 
2019-03-15Receipt_201903.docdoc c4fbe1560255335c1841233e59cb2311a29a0c8e9fa048e5b9c17d63229a9af2n/a Heodo
2019-03-15Untitled_4337030.docdoc fca65dab5ad7ecf95f0fd270155481011075e57d39fd72c0c651565dfd570483n/a Heodo
2019-03-15Receipt_032019.docdoc bf14aedaf97ce161aa6c05eb12a9d956ccd320a333e7df811eab261657efaecaVirustotal results 35.71% Heodo