URLhaus Database

You are currently viewing the URLhaus database entry for http://naeff.ch/pics/trust.accounts.send.biz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:166617
URL: http://naeff.ch/pics/trust.accounts.send.biz/
URL Status:Offline
Host: naeff.ch
Date added:2019-03-26 22:56:18 UTC
Last online:2019-03-27 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-26 22:58:05 UTC to abuse{at}hosttech[dot]eu)
Takedown time:7 hours, 45 minutes Good (down since 2019-03-27 06:44:04 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-27invoice_number-03_2019_X6_0-36_X869.docdoc 28558d1a2e24e5a4488d71b7ca4de29d553efae10b81d2a57cd35517cf0ae7e6Virustotal results 37.93% Heodo
2019-03-27inv_num-201903_D0_90-54_I294.docdoc bb3c5b56d6d614cb598b4794bd07676807d804cd97d4e9888ce7578b7a75fb60Virustotal results 38.60% Heodo
2019-03-27NEWFILE_W6_29-93_67682.docdoc d33c2f96facfd8a2e38b608449676b53fb7816e319196208acc1c89f3aed6687Virustotal results 42.11% Heodo
2019-03-27NEWFILE_201903_D6_8-85_H1533.docdoc 32b50465098b642879702c1a118a933d239466fed0cab72cfb595e0bcf20a4b9n/a Heodo
2019-03-27last_invoice-M8_15-23_X881.docdoc 6461067f4cc442b618f615cb2550d49a22e3713cc8ded5c37e4c33790e6b3ac6Virustotal results 34.48% Heodo
2019-03-27inv_num-T4_0-95_R9044.docdoc 0d10fe705e970034049229c93062cce13a3c212827b5a94aa9bd51764fac480fn/a Heodo
2019-03-27032019_N5_3-78_V357.docdoc c61249e0be72032f2d7e5c7077675d4a8b727a4fc34939242138578ac36fe4f8n/a Heodo
2019-03-27201903_R7_9-88_O200.docdoc c726a571842a6a994426f89fceac37f0814be50027f5740eed06a67e99866718Virustotal results 35.09% Heodo
2019-03-27NEWFILE_201903_G4_6-54_Q7858.docdoc 644fb6e3362074360b0ebe741c0f4b35db1056592ebe4ae87e3ad72da715b936n/a Heodo
2019-03-27inv_num-032019_G8_52-75_J731.docdoc a8c972d20ee636ae08ea92cc42bf637b0b563120d0769fe624bfae2ca9fea616n/a Heodo
2019-03-27last_invoice-K6_8-23_A1250.docdoc f10851f56f0d72b44f10858d77f34b90554550c6c536a59814014c608da10afbVirustotal results 33.90% Heodo
2019-03-26INVOICE_DOC_N9_74-78_J134.docdoc 3def65c76aaad7814e2bd400ddb6801b610afa0f7b5829302cdd46422851a236Virustotal results 34.48% Heodo
2019-03-26OPEN_INVOICE_B0_11-24_B449.docdoc f1bc63e5f837b29a1d4a8d3b7eea34e0ccce4c914183951d52fc4a176ed48f26Virustotal results 33.90% Heodo
2019-03-26OPEN_INVOICE_03_2019_K9_63-27_65762.docdoc 4c6eeeabdf7cd01e8b5eea4afd8aaa1196f891c9cca4d762225d014bb38200a3Virustotal results 33.90% Heodo