URLhaus Database

You are currently viewing the URLhaus database entry for http://click4ship.com/Phreedom/ntfB-k36s3ZlMfbmZsSC_PGKIydqJ-2hH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178122
URL: http://click4ship.com/Phreedom/ntfB-k36s3ZlMfbmZsSC_PGKIydqJ-2hH/
URL Status:Offline
Host: click4ship.com
Date added:2019-04-15 21:49:06 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@spamhaus
Abuse complaint sent (?): Yes (2019-04-15 21:50:02 UTC to abuse{at}scalabledns[dot]com)
Takedown time:5 days, 18 hours, 25 minutes Bad
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-04-17Document_16538045322US_Apr_18_2019.zipzip 3f6018467dd35e03b4d2da6d2882636b3ed2fb4d09b7eb4626f1edce38191a48n/a
2019-04-17Scan_9684527972US_Apr_18_2019.zipzip 90a92fdb84ea070886093e5d592eb51e701911164089b735a8d7b82ebfcf64f6n/a
2019-04-17FILE_3050752315US_Apr_17_2019.zipzip 22e0059505dcc50585904dd87531798a6600eebeaba992f48ec85f96e8ccbc41n/a
2019-04-17Scan_767135986405US_Apr_17_2019.zipzip 2575c4dbc9ec309c0e55eac92002e44196c178de01d11c655d0577b6f60b9274n/a
2019-04-17LLC_37337441546US_Apr_17_2019.zipzip 7cda733f32ecf62ebcd01c008e43b7ef0b86e4d4237d9d076269369c0bcd2829n/a
2019-04-17FILE_4145646651US_Apr_17_2019.zipzip 1dba3b461e6f8874d2f6331628af11b3f54a7284afb6b5ecfc27b05396de49b3n/a
2019-04-17FILE_654335636872US_Apr_17_2019.zipzip 6026ce7416c997785d70726626a9e3d6ea0f2e0ff1e4251437869555aaadb126n/a
2019-04-17LLC_81001576390US_Apr_17_2019.zipzip 49aadbdf0fa3a7d14dae429a28a1e56c00e236dc4bf7e9f32843406cf5067b82n/a
2019-04-17Document_2882465044US_Apr_17_2019.zipzip b66498abdc9787587af60b0a6b59f36167b856f9597fe9b2ceee9916bd82cc04n/a
2019-04-1712644177950_Apr_17_2019.docdoc dfd14cdee37ce2e553ccccff81916d88857b9fef88abe657911e59c39d9bce4dVirustotal results 22.41%Heodo
2019-04-1734214055583_Apr_17_2019.docdoc 22b6830432e47e54619e0448c93f699b096e0e73165e051598a82836ab8e38abVirustotal results 22.03%Heodo
2019-04-17182052150171_Apr_17_2019.docdoc 71da59481ca34680c6459f5947bd9e90fc7ecb570e040045c5d200bf313d5e12Virustotal results 22.03%Heodo
2019-04-1794528113799_Apr_17_2019.docdoc a48e0c240b28f69cf7854c090a5463f4b392e125f647c66b2f535a084958d611Virustotal results 22.03%Heodo
2019-04-17847890276238_Apr_17_2019.docdoc 566c79acc5b6aca21ec8ad0859b2f53a1f0d4a00e793b4e6cba5fdb53cb2bafaVirustotal results 22.41%
2019-04-170598199200_Apr_17_2019.docdoc de05a81b032326fc39700039304035f207e806048aa3ac35707e297ae623cf2cVirustotal results 22.81%Heodo
2019-04-17878105776523_Apr_17_2019.zipzip f2929a3b706c80168c9a486fcfe1e458e0251cb7f265ffcc969350c9783ac119n/a
2019-04-17641023181353_Apr_17_2019.zipzip 07c35ef727b417e9f49191f0fb357a8e01786d89bdd8d966da4e3cd9924015ban/a
2019-04-1799637719185_Apr_17_2019.zipzip e5dceec74e83324463626a6a2b3c77d3bebb8ca724c964ca625cda4580b52f44n/a
2019-04-17866478251961_Apr_17_2019.zipzip f65c463c0201e237e6538424b0b7361978c5da4b23958a43a21394134ba502c5n/a
2019-04-177267424875_Apr_17_2019.zipzip 2ed574a0d02cdd00e36dee88cb52ad482255d1ce2b34cf1fc4ff7f94813fe199n/a
2019-04-17612292752334_Apr_17_2019.zipzip d52f6f98b726a01555c8dd1d134fde08c0abc8d9d4b7ce384d6692db71ab24a9n/a
2019-04-175237240082_Apr_17_2019.zipzip 9bd524fd43077d7b700740468d8504db96a4a75d1998d11370125db03041de30n/a
2019-04-178033208925_Apr_17_2019.zipzip a6df35b890e022199871ba38c7efe3331cce1f399b6c8e2b49ceb23ab486b568n/a
2019-04-1741377644954_Apr_17_2019.zipzip 61584238333a5bdfa96a345e15d81e8a9a6e037ee7f3cb05494244295dd30196n/a
2019-04-17917279072343_Apr_17_2019.zipzip 0b4d6115b7536b57231b7105b76cc07c680d210d90e34fe1e211ab6304d92e37n/a
2019-04-17023541027840_Apr_17_2019.zipzip a09e1eac4a3307283501cdfb35485fd6cad44d0ea2b58e47a37b52639135f322n/a
2019-04-172080773024_Apr_17_2019.zipzip 256e3bfeecf9272c7df89d870374045ada9002493d2371b4c0c1f91fec4078a0n/a
2019-04-17572113191054_Apr_17_2019.zipzip 0cf2ed1d329db6592165716f8126f55e6fcdf540a3cb7594a7c511a43f60efafn/a
2019-04-17906521493755_Apr_17_2019.zipzip 5104967c8eef03351654d6dc1ac74a22a3d9112f1af476ccb047a31752b9e43en/a
2019-04-170957610597_Apr_17_2019.zipzip dec1c4f1c9b4ccc2e9b0d14bc2f21db12dc651d9c07383126eb40b092987ae86n/a
2019-04-1782115199203_Apr_17_2019.zipzip 949c06db3555386aa5dc2df7aabe023fc014e2d79f389430b464a87094360989n/a
2019-04-1781779367216_Apr_17_2019.zipzip 5bee50daec35819e10b679ec1e13b01d1b40752697204d42330c404d3548d842n/a
2019-04-17012499470170_Apr_17_2019.zipzip 06a610508b98f85ff0ca5fbad046650bc05088751e102b1d175903cb8070a78bn/a
2019-04-163570681600_Apr_17_2019.zipzip 808f55a7410443217f560e14735d1a44842cdfa1f97b8262acd370c4ac76b86bn/a
2019-04-163881672567_Apr_17_2019.docdoc 3828b5d43c9a954b999a9aec7777e8a36b97d8a00de5ac023fbcd09b210cb543Virustotal results 25.42%Heodo
2019-04-1639803720210_Apr_17_2019.docdoc f4057cf66759a43716d9fa6733db73448df6fc66303df5616dcce6496b83b167Virustotal results 25.42%Heodo
2019-04-167015795441_Apr_17_2019.docdoc 4b1ccb75644b61d0f3c1df18a238066171bf3f3b8ffbdce21a963a032676bb61Virustotal results 24.14%Heodo
2019-04-16357131006118_Apr_16_2019.docdoc 3824b2db3b14d88a11d155d0894a6af22bedb3bc12a029f9563344208354aff6Virustotal results 35.09%Heodo
2019-04-169775923207_Apr_16_2019.docdoc 4f9800723d9da1abd4a9270d2ca1608a8540cbc15ddaa67f2b8a18aa2d75620aVirustotal results 31.03%Heodo
2019-04-1631678197640_Apr_16_2019.docdoc e8a46a8b0686f80f2a59786232894b4a1b299ec8a0a1326a107deb5ee4e7cadeVirustotal results 31.03%Heodo
2019-04-16552924800918_Apr_16_2019.docdoc fa660e7b9ff937c7e5c479dc9cde90110956fb283453d09e1dfde4853b96296bVirustotal results 30.51%Heodo
2019-04-1631040261933_Apr_16_2019.docdoc 033fa72fe48a853b99e41ed7467c1ccc488d5abe69dff887b8a6b7b2c5a5452fVirustotal results 31.03%Heodo
2019-04-1600507519242_Apr_16_2019.docdoc 2424f686781cc0fb887ff5606a77f090dfe38b9539e94e0d5d55b20dcb212041n/aHeodo
2019-04-16157709013144_Apr_16_2019.docdoc 0d6e79a1ce172fd964c9c98a3bc5a94cb5f901e7253f1c2ce14bf30c34747b2aVirustotal results 31.03%Heodo
2019-04-163923189835_Apr_16_2019.docdoc 020ed32f0c3de6a24817e3326fe676c4e07896c71f9474db5b9948847d8e2873Virustotal results 31.67%Heodo
2019-04-1689734052492_Apr_16_2019.docdoc ebbd8471022a4d525eb5bd3537e6a1688980bcd861300807f5c4a14ec7ea777fVirustotal results 30.51%Heodo
2019-04-1699248777781_Apr_16_2019.docdoc aea48fc08e1c0ee59879373c140af99229887fd6cc38f32308b4ffa4fe8bb8a8Virustotal results 28.07%Heodo
2019-04-164773923437_Apr_16_2019.docdoc 6280cad89edea53c8bd3f428396c3a736f6d67e6f8279026effbbc8f27c35035Virustotal results 26.32%Heodo
2019-04-168842023932_Apr_16_2019.docdoc 48c513176b0c56e199f567a5fc4309950fc2a2c9f09365dfa7d879c94d57be8bVirustotal results 28.81%Heodo
2019-04-16444151755161_Apr_16_2019.docdoc 97527232dd3b2eb16f5e3a733698d5553e27350e942cc1204d01d092593d0442Virustotal results 26.32%Heodo
2019-04-16186083231413_Apr_16_2019.docdoc bdf2f945cfaa821212c3034f5f0f004f8a4c3e26896d4431bb6ee0503e320edfVirustotal results 25.86%Heodo
2019-04-16586655615532_Apr_16_2019.docdoc c40f3f595365f71600c24ebe5c2fd245bb7584364c4b2f3f294e1dfe675891bcVirustotal results 27.59%Heodo
2019-04-16321481005440_Apr_16_2019.docdoc 0c42ff307f9831e057e019051253081abc1001fd290feb13f5467ce2c4ad435aVirustotal results 26.32%Heodo
2019-04-163990474900_Apr_16_2019.docdoc 1073385d94089c725063ce1a488c157293e6aa8cd6574597042ad5d5f9f6004cn/aHeodo
2019-04-1672379258789_Apr_16_2019.docdoc cf34076fe15384682ff04d5a15a94d36af4ff3dee94d651c33c4b4c60731ed88Virustotal results 26.79%Heodo
2019-04-16278261001086_Apr_16_2019.jsjs e328f1a48cce3e9220c38d847ccea9f81b6135d120bd76b224c4be21405f700eVirustotal results 7.27%Heodo
2019-04-157833474730_Apr_16_2019.docdoc 8cd4e36661364ce87f1ab5d766e5dc204b3087c58acb95765dbfeafcf5f43534Virustotal results 44.26%Heodo
2019-04-15909163792850_Apr_16_2019.docdoc da956cc8f7e31477de3ad6df05f775b0ed58912dcf2f4c427d629e39d4f77394Virustotal results 32.76%Heodo
2019-04-15767668027616_Apr_16_2019.docdoc 8e97344465fdaf703df002910300917f1727a7d8b0a495862cbd8db05ce10fffVirustotal results 31.03%Heodo