URLhaus Database

You are currently viewing the URLhaus database entry for http://clicksbyayush.com/snippet/payment/jbuul35h44uf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287387
URL: http://clicksbyayush.com/snippet/payment/jbuul35h44uf/
URL Status:Offline
Host: clicksbyayush.com
Date added:2020-01-13 20:48:35 UTC
Last online:2020-01-27 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002242899 created on 2020-01-13 20:50:05 UTC)
Takedown time:14 days, 1 hours, 19 minutes Bad (down since 2020-01-27 22:09:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-15RP_61483166.docdoc 3f1cd2855f72e6a6e14bfccf0d3716f1a8073f16094b2def3fc2245a1893086fVirustotal results 34.43% Heodo
2020-01-15W_GLP_010120_NRJ_011520.docdoc 325df5875941d1bf51f7c6099269c3396771f3188c57b74bd17c51373b32b1c8Virustotal results 32.26% Heodo
2020-01-15PAY_UIJ_010120_VYY_011520.docdoc 71a1acb5645dcc9ba07cc7f6b61b13e4bf132d4d1b53664b6f34f438216b3399Virustotal results 36.07% Heodo
2020-01-15RP_NJY_010120_BCT_011520.docdoc 2004c6f1abd300fa135b56f65c133ebad43e42aafae2b9b9726e3dd274424ea0Virustotal results 32.79% Heodo
2020-01-15T_YFOSZ0L4VEFCDES.docdoc 41d4ab7959bb5f129efc52538f7d799786a868cd42bad36c06d311a84727d1b6Virustotal results 25.81% Heodo
2020-01-15KV0454789009EX.docdoc d402892bded1fe7f48f7fffef9c87ada82d08ef2c2ea534d8b28ccd94d08e2c5Virustotal results 25.00% Heodo
2020-01-15INV_NEY_010120_KDV_011520.docdoc b936b2575a8eefa3b592b53c6012122e6965f28cdd12ad4d24b9ef2c44b0cd98Virustotal results 22.03% Heodo
2020-01-158849797992393555757044458.docdoc 40b77e83876ede98fb4aa2c83113d90573eb22dfbc4bf3a0a2b8597a2da9b7f6Virustotal results 21.31% 
2020-01-15RP_DFZ_010120_MFU_011520.docdoc c9368e7d1cbbbc90b37dac429596452e1d0e2905219f252d6a91524fc9a35f6aVirustotal results 24.59% Heodo
2020-01-15U569FQS.docdoc ae23c3284230d31527a8b2f8a4721cfa9d31535c93604fcd9be10894eeffc01bVirustotal results 18.33% Heodo
2020-01-15R_FCUAU525G562.docdoc 9982b18660c6aa9b8419bd84843d2d578fd2afb2516782ac69f0e7f8eee4efb9Virustotal results 18.33% 
2020-01-1598762821.docdoc e4fa19c4736ffb554aacdb6de08c4ad081fd55105dddc85b31eac5c6082e601bVirustotal results 18.33% 
2020-01-15ST_7169308131336847154729.docdoc a7d4e714a1656fa280fa345e1956d3b62141ac7b29d8fc4563c85a5616f886aaVirustotal results 37.70% Heodo
2020-01-15RUD_010120_GSB_011520.docdoc 632e28a523c920e3035782ad086e6d3f0e39445486e86e7ce6a05c0e4f337292Virustotal results 31.03% Heodo
2020-01-15DOC_YB3448813745US.docdoc 17cbb232fc64e8c775b7ed47a28ec7a2cfaf6cca790994fad3c41fb60a648062Virustotal results 33.90% Heodo
2020-01-150755265504679.docdoc e05aa4d17d2a8ef068f246bb5e9328c81f3fb36cc872dfe49c8b45419df2087eVirustotal results 30.65% Heodo
2020-01-15ST_4LHKVF08LQXA.docdoc 556f0f62580588094bb0d595bdbb880b58a48148af61569258c9a84653374cbbVirustotal results 30.65% Heodo
2020-01-14SW_WEP_010120_TLD_011520.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23% Heodo
2020-01-14SW_25POSIZ.docdoc e8e877eb89bc1a478fee7e89597bcac889a3776e27aae4692b63920428f58e53Virustotal results 19.67% Heodo
2020-01-14PO_01142020EX.docdoc 492655597c23981d73b96d4362411003a44320bf9a4af05574c4dd5638f84716Virustotal results 19.67% Heodo
2020-01-14RP_58G8KVRRSSILL.docdoc e3cd5ab045097c55bcb00a1cdc84e11c8d7214e15f536baffd899dfb8e0a3149Virustotal results 17.74% Heodo
2020-01-14PO_01142020EX.docdoc f73efe44e8484ba991700fc3485cb9e497fb8b59f05af254a385348a2cc5b71dVirustotal results 19.30% Heodo
2020-01-14PAY_32117827.docdoc ace87f0ad1ea6c26dd979dc2120722b3fb1bc858afbcd771a4f8452e7f56658cVirustotal results 18.33% Heodo
2020-01-14DOC_PR4708563278AO.docdoc f5f4d5f08a7cb7e623d0bbfae4b90f9cf9151135d1218fc30b351b23903cbea3Virustotal results 17.74% Heodo
2020-01-14PAY_9206453993277378752296451.docdoc 5d9329d9984325cb262d7fda534e57520edbb464d3da16a442cb5d9fee3c4033Virustotal results 18.03% Heodo
2020-01-14TVS_010120_YTF_011420.docdoc 9f6fadf2f4def948ec447af92930f40918987338f8dc4e20a73446a1cde6cb20Virustotal results 16.13% Heodo
2020-01-14INV_30292328.docdoc f55d03e3ad7e00c22487c4297a898c96e36b144a5619d181623997b6b4782d13Virustotal results 19.35% Heodo
2020-01-14REP_FN9303834929RF.docdoc 34259939d4e8b82382d0e7459f253f955cd391b3990528e2ce1efa9faf71e07bVirustotal results 17.74% Heodo
2020-01-14REP_PO_01142020EX.docdoc 68d4cf5b4876d3a27666509c2ec491a54651c4096c311fc641a51d38c9999777Virustotal results 16.13% Heodo
2020-01-14INV_1722898893300752705842.docdoc 6949527d955a71fe60c74bcf256e202a4c03143041b7f9f2bb5763a0efb59eefVirustotal results 16.13% Heodo
2020-01-14QH6006267023AE.docdoc e43c9ff61cb560195d5292e4b9112a9cd911a56bc9e0e75e3d8226e8a47bf60bVirustotal results 14.52% Heodo
2020-01-14INV_MI3237195498AQ.docdoc f8e9758d488a0f17ee9781763287d1451d2c8b0e8bc7faa5f44d861d5a5aa79eVirustotal results 42.62% Heodo
2020-01-14REP_18174414.docdoc f0675978d07200b1098cb8daa477dc639bf71abeedd1a6c1451b0a75f748f1f5Virustotal results 41.67% Heodo
2020-01-14SW_KMZ_010120_BOE_011420.docdoc 56f51040d9c1665339529cd8bbf3f85c264d4996df08e6b388ae9fadcd88aa87Virustotal results 38.71% Heodo
2020-01-140287959965038661387495223.docdoc 7b1a3d9aa0ce52fb438355535ff9009fbe3e6c832fabe5895c4f03777b14c1bcVirustotal results 30.65% Heodo
2020-01-14DOC_GY5694918672AE.docdoc 843b38010b78f69a9c7531e95d13d1a0bf81b6ef0cd05136b7962bcf1211a13dVirustotal results 27.42% Heodo
2020-01-14INV_9A8A7MH6IJP85TE.docdoc 1843eb2b424df29991df3fd7ff4ee6658f540134ce196e1b150162ce70952fa1Virustotal results 25.81% Heodo
2020-01-13ST_HS9181941671VJ.docdoc 31d96e1ef61fe0c37d3d310dc3dbf3199394d707c651f822c1e0d9ce782c98faVirustotal results 27.12% Heodo
2020-01-13ST_IQ8873149028SC.docdoc 2c885a88498ec14933c342b3084ea588d14d809c6f19d68a968f7924f0d6fd38Virustotal results 33.87% Heodo
2020-01-13OD7W51B82ID1SPO1.docdoc 84e05566cb505dfc6843cb6ccd9f6c7aaf586801fa0444a2105b141566e535d3Virustotal results 30.65% Heodo
2020-01-13BAL_559874453905647.docdoc 3cbcd18a74eaf8c4310095f67d48dbb005e5b1f22fcfa48673a8373435e48fe1Virustotal results 31.15% Heodo