URLhaus Database

You are currently viewing the URLhaus database entry for http://accurateastrologys.com/cgi-bin/QvOKxH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:265381
URL: http://accurateastrologys.com/cgi-bin/QvOKxH/
URL Status:Offline
Host: accurateastrologys.com
Date added:2019-12-09 14:14:32 UTC
Last online:2019-12-20 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002156220 created on 2019-12-09 14:16:10 UTC)
Takedown time:10 days, 10 hours, 47 minutes Bad (down since 2019-12-20 01:03:26 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-14INVOICE FVD28_94622.docdoc 10c8c3649588c1021aafa3b8b54b49e7ebc0233e28895856dbffea8211ef012aVirustotal results 26.67% Heodo
2019-12-10invoice_T17_64.docdoc 5997cee15e626ed5ca230c30eac86d7d1db74e9713f4c8a7adf235c468e5950dVirustotal results 26.23% 
2019-12-10Invoice KE61_33868.docdoc 043127a78952f4652779b6fd418417fcb667a2a395157096a9fc4fb6260a474cn/a Heodo
2019-12-10INVOICE-J345_72.docdoc fa4cd2cd3e278ab1bdf90de58b210b94b26d537b1daaab4771fd09eba8675705Virustotal results 26.67% 
2019-12-10Invoice-NHW003_46.docdoc 0220ae8276ecfe24b95a1c024faff1db988596163166a2bd7ba0c6f5014987f7n/a 
2019-12-10INVOICE-QHJ36_99.docdoc 75d4ee6494909cba06ef82260dbc8ff2528578cb8657a54387fec56418b1a82fn/a 
2019-12-10INVOICE_A53_1514.docdoc 8ca93aee72b8d7fccf197d30f18fbafb058c66dcfe6ae4c4db65dec5b38eb908n/a Heodo
2019-12-10invoice Z825_9021.docdoc a91244d91531587d87ab5d8c387dc5127890856307d409499d97ac67208bb285n/a Heodo
2019-12-10invoice T75_6791.docdoc 70ec5cb9d8550ad4f9a9e8c4ee0b41e3b9ba7d5bd16b65aa15412417d242be20Virustotal results 32.20% 
2019-12-09Inv E55_9496.docdoc f93960eeb1c885d2b561ecaf9b4db5009bbf79a9e9693c7f279a46c3f5ad42dfVirustotal results 28.81% 
2019-12-09invoice ZY43_5601.docdoc 1d0413ed696479c640a033422ca6b8ad7076d1529221f4e760054673faa1d667Virustotal results 27.12% Heodo
2019-12-09INVOICE-NED89_9202.docdoc 5401bff858e99a6cdf7cb3af9cad35fa2f3dc927a004e06c610a6e988ea12772n/a Heodo
2019-12-09Invoice KZF337_5604.docdoc d03493d3dd09dabe81fc12760c310cc96974c508b09705ea6f5c4b81b5b2077en/a Heodo
2019-12-09INVOICE F033_38.docdoc 4f631703b7dae0944dc91f05cc713eee379ad04ba1aae3ba56c11fe50b6352a2n/a Heodo
2019-12-09INVOICE-LZR42_61123.docdoc 9831d1839f60fa8bc955298c208d5ad5fa5297960b26976326961513a2ad9c77Virustotal results 22.95% Heodo
2019-12-09Inv QH85_564.docdoc 36a0ab6722e9dbf93ae74c0263dfd48e2b9a704a0f7d2634c6f83d0df9009500Virustotal results 22.58% 
2019-12-09INVOICE-TP34_914.docdoc c25153dc2b3f99188d0861a277e542fb81ff3404ffa3f6075f122f3431fefb38n/a Heodo