URLhaus Database

You are currently viewing the URLhaus database entry for http://everandoak.com/css/HuPeg-R4NtjSK8bmJPww_bQvCCGRCV-h1P/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:173438
URL: http://everandoak.com/css/HuPeg-R4NtjSK8bmJPww_bQvCCGRCV-h1P/
URL Status:Offline
Host: everandoak.com
Date added:2019-04-08 21:57:05 UTC
Last online:2019-04-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU001197541 created on 2019-04-08 21:58:05 UTC)
Takedown time:1 day, 23 hours, 32 minutes Poor (down since 2019-04-10 21:30:38 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-10815318425_2019_04_10.jsjs 7d91ca89ded649dd8a7f691d603d22435d13fc741a7d78b3f587b18370184029Virustotal results 11.86% Heodo
2019-04-10873884109_2019_04_10.jsjs c5aa88145481b5ec57a620084e533210b7d896e4b5f7b4aca8abdb68646a8343Virustotal results 10.91% Heodo
2019-04-10UNTITLED_7655062810_Apr_10_2019.jsjs 20f61d43bb940c959db46366a7210ec321b90552f17e6bf3502bb26b5490ded2n/a Heodo
2019-04-09UNTITLED_7096036881_Apr_10_2019.jsjs 77c98ff712a343ccc9112da423212287d0111a63c6ddb750ba49866b8e48a0ceVirustotal results 7.14% 
2019-04-09UNTITLED_57788608449_Apr_09_2019.docdoc dd627be26131f842b3ca262ee3c78210a2ade286a33cc7e8e6ed656c404c4ce1Virustotal results 22.41% Heodo
2019-04-09Untitled_674091691142_Apr_09_2019.docdoc c056e9a440666b4f8ab24fda644b9d5ed7fe2e687e34a8e3b438e3f3f52226b6Virustotal results 24.14% Heodo
2019-04-09Payroll_9635711993_Apr_09_2019.docdoc be48b0c7dbdb7c63e683f2f3d737ba9c5ed86d158522f37bfc75ae94bbdb2c57n/a Heodo
2019-04-09Payroll_6140416535_Apr_09_2019.docdoc bd03db68e2ee068a238c288e7d28a0f53b63dc16e4e82d5fa5d5dd93c6cfca42Virustotal results 40.35% Heodo
2019-04-08Statement_829021700606_Apr_09_2019.docdoc b63c22c3f05254d928cb4cf07794b8885eb8ad776c472e9c830da5a4c415fe32Virustotal results 39.34% Heodo
2019-04-08Payroll_01387983104_Apr_09_2019.docdoc ad348aa277dc9d5f5348a035a74ed3b42fe38dcf2856ecd825f5d483d0b76b6fVirustotal results 40.68% Heodo
2019-04-08Statement_7910573640_Apr_09_2019.docdoc 76f232c852ca4758d4b848e7dedcebcf2decc1d0112938bb7189f9fa44e12303n/a Heodo