URLhaus Database

You are currently viewing the URLhaus database entry for http://tongdaigroup.com/bill/r6u-kvds-04351/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:272044
URL: http://tongdaigroup.com/bill/r6u-kvds-04351/
URL Status:Offline
Host: tongdaigroup.com
Date added:2019-12-18 20:57:05 UTC
Last online:2019-12-31 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-18 20:58:02 UTC to abuse{at}totisp[dot]net)
Takedown time:12 days, 8 hours, 40 minutes Bad (down since 2019-12-31 05:38:51 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20Invoice-JZ72_32861.docdoc b554687e67437c34ba161bf732d8c04112d581e589a111f9a45772172f3e4f1dVirustotal results 40.98% 
2019-12-20INVOICE GGG895_69.docdoc 34c38d43e0762eb291cb497d18c9651c5441d1bbaab25f847c0ddc419947b3ceVirustotal results 32.79% 
2019-12-20invoice_UZ90_220.docdoc f19e6a6fab57bb7157e808a0b892131f6c3e373286283a34f19cc5db1ab55a3cVirustotal results 31.67% Heodo
2019-12-20invoice-LWG01_57.docdoc 1f53b3c43a43ef79659e6cecb0dfdfe31037e5ed092ec67e6f5f9ac2cd26338aVirustotal results 30.65% 
2019-12-20invoice-AKG900_89.docdoc 06a852431fa26a35eb48e054cbb1869ee748f631d06fbe4371c4e4ee158b6872Virustotal results 29.51% Heodo
2019-12-20invoice-RYW59_39935.docdoc a214bd8b2b6fec4dc1c81e025d893701de68741aaaaece9bddf6456653a5d431Virustotal results 29.03% 
2019-12-20Inv A924_777.docdoc 39cf3c74fdf870bd0afd8daf31619e1b5db39dd50b261682aecf02d38c1f8aedVirustotal results 23.33% 
2019-12-20Invoice-VV565_407.docdoc f3268a9726aeb77441d3a039110ebd7d07825a184770f3348b5488b3a300a57dVirustotal results 22.95% 
2019-12-20Invoice R856_30799.docdoc 14bf4c4d896c5b6ebbabc3d601a882c5d2193e674c52e9750e764aa22739bc77Virustotal results 25.00% Heodo
2019-12-20INVOICE_M50_58559.docdoc e156d8bd8a32384ee8629d5cc06e510ead107771a37246a32e1ba4ea09421080Virustotal results 24.19% 
2019-12-20Invoice-XR096_77.docdoc e8f4adbc33575dfdc6cc8046ec0478baee34237bda285c3e9fd4798aea4ea516Virustotal results 37.10% 
2019-12-19invoice-WRU38_7647.docdoc c1f124d9a0111a6d2c112831a307d02e8efbb9c0d959c05207987f33fcb0df41Virustotal results 35.59% Heodo
2019-12-19Inv_ES735_11.docdoc f94d841b4359be57b37745252d21aef9a4a511bfe3b52998753b001d38415849Virustotal results 29.51% 
2019-12-19INVOICE-I35_24.docdoc 87be47eb44b548bcf19b0d1b0d66666f3ae61b8a6f728ed9c5cd38a28d2096d1Virustotal results 29.51% Heodo
2019-12-19invoice J89_07553.docdoc 4436e84973894fbcdc8be7dd0f3be96f9d1c341417e3059787d63d4013eebb8cVirustotal results 29.51% Heodo
2019-12-19INVOICE L141_51.docdoc 2ebe4dd083e74ae2889a6f5110cb679bea262948cf40d13ad4f94f0654ff1e58Virustotal results 30.65% 
2019-12-19invoice VFQ461_1262.docdoc c164e422f15dce9bf73d9cae6925b5b7e28b7744189775bef9388a53fdc9c922Virustotal results 31.15% Heodo
2019-12-19Inv-K73_20817.docdoc c0a0545beb2cb40bf661714b59697aaceefb7472dad692d1fc4fcbca11f17feaVirustotal results 26.23% Heodo
2019-12-19Invoice_US638_7289.docdoc 5056d7de897aec253441613685a0bee32f545314631166d0791f6febf4c41b1aVirustotal results 24.44% 
2019-12-19invoice A39_40.docdoc 50502b1309e5510dc666c2dd81f978bacd097de74ad3839f00cf37bd162c193aVirustotal results 27.42% Heodo
2019-12-19Invoice_WAN368_764.docdoc 07fffe7ba1cbcbb7e48d12fc1c7c94f01c875af638ff012022244e2176711e69Virustotal results 25.00% Heodo
2019-12-19invoice-FZ132_289.docdoc 440f2be984c10507e16a8b970ed8a0a6e09a56132ee66cd29cbab02e63864bb2Virustotal results 22.58% Heodo
2019-12-19invoice-R816_8641.docdoc c74befca777bd00a2cd49fb788f2e3cf1b0ccf41126d8c1c9f314a12fd55095aVirustotal results 22.58% Heodo
2019-12-19Inv_UKO59_89941.docdoc d682c920cb5701d126dc0ef943e21d7a5c2daa7b5e07c7faabf47ca7bfe7bd51n/a Heodo
2019-12-19Invoice-MG34_013.docdoc e2f57934623f8177bce5dd944c918d436c13455b33473a6cc6bccae0442d3f37Virustotal results 21.31% 
2019-12-19Inv E563_4042.docdoc ca7caed0efe4b99e0cbb87397f8766bcb969c59f646e5afacc122d32378725fdVirustotal results 27.87% Heodo
2019-12-19Invoice S008_35.docdoc 89c3f11b51e8677ad318853298abf7ac9df38bac16509c58650f28be8386a996n/a 
2019-12-19Invoice_FM403_740.docdoc 126cec3feb653048275d4a88bf3ce13e845f4c26796d364b4a7f50dc070d3375n/a Heodo
2019-12-19Inv-W73_02812.docdoc 320e90e290901f78c4b9e8ea11988debf3c58e18cb1b0ac0a09873a9302d450en/a Heodo
2019-12-19INVOICE-DEJ465_930.docdoc ee0c778b4fbc9f0fa56261fce81d0b8b05980d9c7b9b0c051034923a564c3348Virustotal results 26.23% Heodo
2019-12-18invoice-AEX86_60892.docdoc c99052d6ca6dabd3ab45f69e1d2141811b4085d7fe6a247656a39160e3c1e3aan/a 
2019-12-18invoice-B23_54920.docdoc e449b8f4d38bad6efce3dbff1b87adb4f14058bb96dd30a296e6886e9108db17n/a