URLhaus Database

You are currently viewing the URLhaus database entry for http://dandbtrucking.com/fc/NrmG-ba-0541/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:270300
URL: http://dandbtrucking.com/fc/NrmG-ba-0541/
URL Status:Offline
Host: dandbtrucking.com
Date added:2019-12-17 04:27:06 UTC
Last online:2019-12-18 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-17 04:28:11 UTC to abuse{at}liquidweb[dot]com)
Takedown time:1 day, 2 hours, 57 minutes Poor (down since 2019-12-18 07:26:03 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-18Bonus Payment Notification ss685.docdoc 7ecd418f499c379ce5e26a430ee6b3c012aba02686a78c7bb652336666fa8873Virustotal results 43.55% Heodo
2019-12-18Bonus Payment Notification X031227.docdoc a3586470404b553e9048f8b822a362d419e170a2249ee10965f8f597d12a60feVirustotal results 41.94% 
2019-12-18Bonus Payment Notification 1553.docdoc bae97d7f1b776e06c4425f1f40209eb0f9be839818b4d38ddcd4dd9148bee55fVirustotal results 39.34% Heodo
2019-12-17Bonus Payment Notification B481829899.docdoc ffffede7ea632982a76b1b3afa34b322ed75cd9eea5dd11dcc43bacfb0d10917Virustotal results 37.10% Heodo
2019-12-17Bonus Payment DO7417450.docdoc 41a08ef8f1c194750f269c5f26c787e405d4002a3a091c4f95656005febf321eVirustotal results 36.67% 
2019-12-17Pay Payment pi3064.docdoc a0ec5ab66a2fff1c36584488a9dfb25563d9558af4f8c39fe4ef9778c47c4a2dn/a 
2019-12-17Pay Payment w5705.docdoc 64e2f49cfdf6fabf6bce465fe1826c47f3dfac443dcdbec6b92e908f07dee278n/a Heodo
2019-12-17Bonus Payment Notification 812.docdoc 29d697765067c3697dfb256faa280ce17731733a0aae35d2e86cba06d898ad2cn/a 
2019-12-17Bonus Payment Notification N547716157.docdoc 4debd65e5eae6541f0ce1a0e039ccb8a59438c9cb515820b6260f77b08f02065n/a Heodo
2019-12-17Bonus Payment u0396.docdoc 6b7c34d5cb597e4144608ceb867fe0ba1ff6a94564da88d1db8cbd050397bc90n/a 
2019-12-17Bonus 550569.docdoc 11609d6fef162c18390a302feed05a4ecdb2967762a2dab7dadca59a5526efedn/a 
2019-12-17Pay DeS7134141.docdoc a1e17db1817375edd6735f442bb2e7778952f5bce34d02f42059aeea8f672e11n/a Heodo
2019-12-17Bonus Payment Notification ZP43651.docdoc 9dc1afce7d2bd7ec6d7b0da2d7eff6b3dcfe34620272b3620ae299e4396a5e3bn/a Heodo
2019-12-17Bonus Payment Notification 551.docdoc 7100103fcd10dfc0a5773f8c3bd74ff8a0a5c7aecdc2c77ddf5fced772d01c30n/a 
2019-12-17Bonus q9932554.docdoc 61238acfcc8bdd6c0bfdb44167021cd20457a4b50e10e0aa4eac11a9172dc59an/a Heodo
2019-12-17Bonus Payment Notification Dc72835.docdoc 976a87c807cc6916b189eee5139dce17380aae5b911ab3ab7c62c2f1b73e2f87n/a Heodo
2019-12-17Bonus Payment Notification Cje736.docdoc 7e076bec50d066d433553b8134f680ecb65ec425a10535dd8ccb52d6da3e16d0Virustotal results 19.35% Heodo
2019-12-17Pay c5625.docdoc a0a0e9f2908955f2e6533d1c10a96868fa4992f37397a64071260f4726b602aaVirustotal results 30.65% Heodo