URLhaus Database

You are currently viewing the URLhaus database entry for http://tubbzmix.com/zJnYWk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272037
URL: http://tubbzmix.com/zJnYWk/
URL Status:Offline
Host: tubbzmix.com
Date added:2019-12-18 20:46:07 UTC
Last online:2020-01-02 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-18 20:48:02 UTC to abuse{at}web24[dot]com[dot]au)
Takedown time:14 days, 18 hours, 36 minutes Bad (down since 2020-01-02 15:24:51 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20invoice_V976_945.docdoc 34c38d43e0762eb291cb497d18c9651c5441d1bbaab25f847c0ddc419947b3ceVirustotal results 32.79% 
2019-12-20invoice FY992_81.docdoc f19e6a6fab57bb7157e808a0b892131f6c3e373286283a34f19cc5db1ab55a3cVirustotal results 31.67% Heodo
2019-12-20Inv BLW935_935.docdoc 1f53b3c43a43ef79659e6cecb0dfdfe31037e5ed092ec67e6f5f9ac2cd26338aVirustotal results 30.65% 
2019-12-20INVOICE-A33_238.docdoc aa5dd888e705275c637ccbdb974ec8299eda718438a98b5e5885eb33dfc7ca74Virustotal results 29.03% Heodo
2019-12-20invoice-ONE547_522.docdoc 98836132e77859ebda39c931d194875e25a24af6ecc148d037219383b27aa0a8Virustotal results 29.51% Heodo
2019-12-20Inv-MO176_7636.docdoc 39cf3c74fdf870bd0afd8daf31619e1b5db39dd50b261682aecf02d38c1f8aedVirustotal results 23.33% 
2019-12-20INVOICE-UCA908_6315.docdoc f3268a9726aeb77441d3a039110ebd7d07825a184770f3348b5488b3a300a57dVirustotal results 22.95% 
2019-12-20Invoice-YNB90_6287.docdoc 14bf4c4d896c5b6ebbabc3d601a882c5d2193e674c52e9750e764aa22739bc77Virustotal results 25.00% Heodo
2019-12-20INVOICE-LJB59_42.docdoc 4903616001af26a0df8c09fbf94cf5f5b8d76402d42379246df3b7524764d663Virustotal results 24.19% Heodo
2019-12-20invoice_LHI320_10253.docdoc e8f4adbc33575dfdc6cc8046ec0478baee34237bda285c3e9fd4798aea4ea516Virustotal results 37.10% 
2019-12-19invoice-AG65_26.docdoc c1f124d9a0111a6d2c112831a307d02e8efbb9c0d959c05207987f33fcb0df41Virustotal results 35.59% Heodo
2019-12-19INVOICE LN65_4634.docdoc f94d841b4359be57b37745252d21aef9a4a511bfe3b52998753b001d38415849Virustotal results 29.51% 
2019-12-19Invoice DS744_05.docdoc 87be47eb44b548bcf19b0d1b0d66666f3ae61b8a6f728ed9c5cd38a28d2096d1Virustotal results 29.51% Heodo
2019-12-19Invoice-ICK19_3055.docdoc 4436e84973894fbcdc8be7dd0f3be96f9d1c341417e3059787d63d4013eebb8cVirustotal results 29.51% Heodo
2019-12-19INVOICE-N72_512.docdoc 60d9761ec33a814667a8a09a86ce91f7b3bef4d2591e58b59b5a8a5fd475aeecVirustotal results 30.65% Heodo
2019-12-19INVOICE-RGQ433_9788.docdoc 4b8f4e9e0e6a9ca5c821a4bc491193f24e255786a729d0a432a1ff564cb31923Virustotal results 29.51% 
2019-12-19Inv_JGO33_39661.docdoc c6b730a2a9e6484798ff301e377a0f5b5f11c6cb7c97be74845f05d9670f2dc9Virustotal results 26.23% 
2019-12-19invoice N755_96516.docdoc 37a893b98d380296db389c96da55abb6cf62f275bf0343f24bad9ac1e702a39aVirustotal results 22.95% 
2019-12-19INVOICE T83_716.docdoc 50502b1309e5510dc666c2dd81f978bacd097de74ad3839f00cf37bd162c193aVirustotal results 27.42% Heodo
2019-12-19Invoice-H52_278.docdoc a654dd0cf8ae94d1ae4d9396385a2642ecf7906659b36e47ecc51afe07c0ff2eVirustotal results 24.59% Heodo
2019-12-19Invoice-YEJ300_35.docdoc 440f2be984c10507e16a8b970ed8a0a6e09a56132ee66cd29cbab02e63864bb2Virustotal results 22.58% Heodo
2019-12-19invoice-O684_9289.docdoc c74befca777bd00a2cd49fb788f2e3cf1b0ccf41126d8c1c9f314a12fd55095aVirustotal results 22.58% Heodo
2019-12-19invoice XD960_39.docdoc d682c920cb5701d126dc0ef943e21d7a5c2daa7b5e07c7faabf47ca7bfe7bd51n/a Heodo
2019-12-19Invoice-X57_2682.docdoc e2f57934623f8177bce5dd944c918d436c13455b33473a6cc6bccae0442d3f37Virustotal results 21.31% 
2019-12-19Inv JX90_310.docdoc ca7caed0efe4b99e0cbb87397f8766bcb969c59f646e5afacc122d32378725fdVirustotal results 27.87% Heodo
2019-12-19Invoice_GY87_40.docdoc 89c3f11b51e8677ad318853298abf7ac9df38bac16509c58650f28be8386a996n/a 
2019-12-19Invoice_CHK911_024.docdoc 7ef6c8bba32a08498fa348b97b54ff39ec51d262b9c14176c81d0c4ce5a43150Virustotal results 27.27% Heodo
2019-12-19invoice-HO22_7452.docdoc 320e90e290901f78c4b9e8ea11988debf3c58e18cb1b0ac0a09873a9302d450en/a Heodo
2019-12-19Inv_P819_01.docdoc ee0c778b4fbc9f0fa56261fce81d0b8b05980d9c7b9b0c051034923a564c3348Virustotal results 26.23% Heodo
2019-12-18invoice_ZSA88_09.docdoc c99052d6ca6dabd3ab45f69e1d2141811b4085d7fe6a247656a39160e3c1e3aan/a 
2019-12-18INVOICE-KAS45_861.docdoc cf3dced757bf13b9026e97b0d15406f67fe15fe384f2057e387b198f585bc60dVirustotal results 26.23% Heodo