URLhaus Database

You are currently viewing the URLhaus database entry for http://jitkla.com/images/ACCOUNT/INV44779073/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:20718
URL: http://jitkla.com/images/ACCOUNT/INV44779073/
URL Status:Offline
Host: jitkla.com
Date added:2018-06-19 05:25:23 UTC
Last online:2020-02-01 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2018-06-19 05:32:29 UTC to ip_admin{at}csloxinfo[dot]net)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-19ZLH-INV-675032211.docdoc 56875fe302e20500785ebab45b0b76e6e191abe57cf98455a6372e04a781bf90n/a 
2019-03-26ZLH-INV-675032211.docdoc b8b94da3538cbad6e17293c9b76d7d57bcda50a626c13d4dbf62751c9acdabf2n/a 
2018-06-28ZLH-INV-675032211.docdoc 0cde82a70af66975034f93ae52b6a7a9bc0be76dc25e8da666bc97fff05eed0cVirustotal results 66.67% Heodo
2018-06-19AKZ-INV-9165313226653.docdoc b3e0c3db94c18eed05404d8f29c8353b9601e170a4ed6456df5b7a77d2924e74Virustotal results 36.67% Heodo
2018-06-19QPZ-INV-11341752656.docdoc ceb070480f3fd618c25a3f6f418081e7d5a9f136b7fdc7dec42c36ed57756e97Virustotal results 35.00% Heodo
2018-06-19YIO-INV-6495800023.docdoc eccd918c92aabcaf146d3fc9c9211308f24db2ee8b039155eafb0d1d92e5ebc4Virustotal results 32.20% Heodo