URLhaus Database

You are currently viewing the URLhaus database entry for http://yojersey.ru/system/MCb99174856/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273757
URL: http://yojersey.ru/system/MCb99174856/
URL Status:Offline
Host: yojersey.ru
Date added:2019-12-20 07:36:48 UTC
Last online:2019-12-30 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-20 07:38:16 UTC to abuse{at}ht-systems[dot]ru)
Takedown time:9 days, 23 hours, 1 minutes Bad (down since 2019-12-30 06:39:42 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21Pay UI43847357.docdoc c6cdc9917e62313415a14d953cac0f81cd70ca8843ca2bd16be5eebb6bc7ffd8Virustotal results 31.67% 
2019-12-20Pay Payment IefI61.docdoc aac47e0b1bfed806be29c04f6762058cd7bfccc6f21d199983ed0f1a8ca3f003Virustotal results 32.26% Heodo
2019-12-20Pay Payment tF55167.docdoc 7eef03190b30b6dae3b4b27fec3f255c748f054b96590e197b5aa465cb927460Virustotal results 29.51% 
2019-12-20Bonus Payment Notification 76279.docdoc 34c38d43e0762eb291cb497d18c9651c5441d1bbaab25f847c0ddc419947b3ceVirustotal results 32.79% 
2019-12-20Bonus Payment OZ939545697.docdoc 72e900957b68806b6a8c9801084df6526911e773ad9dbd2b5c445827c9896e55Virustotal results 31.67% Heodo
2019-12-20Bonus Payment Notification Rlah37627.docdoc 1a9a9db05064dfcb6d5f1c699a31218fc0621c148f4638fdfdae3a9a5930f0d9Virustotal results 31.15% Heodo
2019-12-20Bonus Payment Notification J67349.docdoc c5e754b236930122c0b6f1d86a993b5249e83b90ed5db2ccb5a1f68f24de7be0Virustotal results 30.00% Heodo
2019-12-20Bonus Payment sb99770391.docdoc a214bd8b2b6fec4dc1c81e025d893701de68741aaaaece9bddf6456653a5d431Virustotal results 29.03% 
2019-12-20Bonus dJR9208.docdoc fc653d3610ceb9b3e745abf2d8f54180326c210522b62f034b176864359ffdccVirustotal results 23.33% 
2019-12-20Bonus Payment SsIf2275729.docdoc b8aeb958388b6825a5d7fadc0052cede33574d7a2766a3ef9137a72c3d5cb03bVirustotal results 22.95% Heodo
2019-12-20Notify 184894.docdoc 82ae2cfcce345cdf1604b06320131de90ff62d5956d49649e9ddf7ea0dc0d12an/a Heodo
2019-12-20Bonus Payment bg540173.docdoc f18bc76a2ee51dce1994d87c9a8e9b7fb51ea9360b83e06c81cead2ec43362b2n/a