URLhaus Database

You are currently viewing the URLhaus database entry for http://tech4bargain.com/IRS-Tax-Transcipts-004P/62/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:18706
URL: http://tech4bargain.com/IRS-Tax-Transcipts-004P/62/
URL Status:Offline
Host: tech4bargain.com
Date added:2018-06-13 19:05:10 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-13 19:05:18 UTC to abuse{at}uk2group[dot]com)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-14tax-transcript-084-71563.docdoc 70c1f8e19efe850e20e7ac60f652bf7ce366f2dd8b95f8eb29ead7413585a3d2Virustotal results 27.12% Heodo
2018-06-14account-transcript-07/211.docdoc 973b95941bbc195c08d240d19a6d9e17daf54c2b4afe12608737feeabcd6ad26n/a Heodo
2018-06-14transcript-091-1761.docdoc 98eafc7e7b3f808d7cf635ab3e0e16cccd3b4381aa80830d4108e208f0a4d44dVirustotal results 28.33% Heodo
2018-06-14transcript-June142018-059869/17.docdoc e8925700ba6c46e627deade85580d23783ef838de58102b68a3cf7d411100dc3Virustotal results 26.67% Heodo
2018-06-13transcript-078857/87.docdoc e24e78ea350aa0b7e69bd40ac33c3bc4eb3dc8cdc17a5dc13ef98a14cbecb2abVirustotal results 20.34% Heodo
2018-06-13account-transcript-07H7565/55.docdoc 44082acd8f335ba1765e0c1b6abd84918ac84358e87c45309e587101b66f15baVirustotal results 22.03% Heodo
2018-06-13tax-transcript-June142018-004/7636.docdoc cf49767f716f26529a1fdc7b664ecaebee90c5ac67d85e667096e3d693cbe048n/a Heodo
2018-06-13transcript-June132018-032Z692/31.docdoc 502bb31e2269447e09b57b815a592c320506385c11824e13b75a5b4dc133161bVirustotal results 21.67% Heodo
2018-06-13account-transcript-076-9344.docdoc b4d056e87cbbdf49baf4d87a0be32e1763bca314e21b085a7a4fea18a251b016Virustotal results 21.67% Heodo