URLhaus Database

You are currently viewing the URLhaus database entry for http://www.builditexpress.co.uk/exclusive/yh67-qrgk-4665/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287964
URL: http://www.builditexpress.co.uk/exclusive/yh67-qrgk-4665/
URL Status:Offline
Host: www.builditexpress.co.uk
Date added:2020-01-14 12:36:47 UTC
Last online:2020-01-24 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002244251 created on 2020-01-14 12:38:04 UTC)
Takedown time:10 days, 5 hours, 30 minutes Bad (down since 2020-01-24 18:08:38 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-16Invoice_56_1490911.docdoc b44638c59970903aff549cbdb9555ba334f7471ff807475bb8e1713cfa35b0afVirustotal results 29.51% Heodo
2020-01-16Inv OTO1_879632.docdoc 8d439ffba3e368203c9730aa92eafc43c775301843d7b4d3d1ddef104f13adf6Virustotal results 28.33% Heodo
2020-01-16Inv-QPPI5292_30778633.docdoc 2391b03721c41008ed90eee93211a14e34d015bd7a2d47f193059b53c1a7e335Virustotal results 23.73% Heodo
2020-01-16Inv-85_64624449.docdoc 52a5344c0fc9ddf5e6d817f2c170f379de298442e9f1095608e1b87de85eec5eVirustotal results 22.95% Heodo
2020-01-16invoice DAR24_31209.docdoc f1970d508b8e4e38daac12904d41a353706c1b7d189f0f20992c36dd831db972Virustotal results 21.67% Heodo
2020-01-16INVOICE-XSD907_948.docdoc 37e98c8ff3288199a2a4ae056b48dde6ad9ed9cbaf76e837ded084ad42271771Virustotal results 44.64% 
2020-01-16INVOICE-D56_46.docdoc 9fda3248a57da63654d03722cdf9df6bbde2ffd4129ae7a8eabcd440c58868c9Virustotal results 41.94% Heodo
2020-01-15invoice OY67_1845.docdoc a56c3ed265eea81662d995f74b97d4d70829797368d462b1a29b05c5edb329f6Virustotal results 33.87% Heodo
2020-01-15INVOICE-TP916_37518.docdoc 7a1bb65a845c067f7a327d08097b85e17646c11d6f7b226176e89d16474d54b4Virustotal results 36.07% Heodo
2020-01-15Inv KS319_4064.docdoc ced74a717f09aa4ee30f883e7140c28a91a1911384510acf14127ecd77ae577cVirustotal results 35.48% Heodo
2020-01-15Inv_OX187_865.docdoc f380d9680a29d7341cc3f1530bd4564ae36880be039d978203dffc7d4f9b517cVirustotal results 29.03% Heodo
2020-01-15INVOICE_H984_091.docdoc 99af0aebc41fb11a3bdf2668e5b92101e75255ade78fea296414a4d4d3b00dddVirustotal results 26.23% 
2020-01-15Inv_C169_4644.docdoc 354697823e92e18424ec488fa6845b48247a966c5b4d7745cf4f8daf2c5a7accVirustotal results 25.00% Heodo
2020-01-15invoice_SQM067_6402.docdoc 78a310a044510fc979e903828bdc3831844a04b5c01b34397e52e3bd62c96674Virustotal results 20.97% 
2020-01-15INVOICE-ITM189_72.docdoc b7d6a9d883ceb3098ae6e82cb15a930133fd838486587f4f1fee1145cfc87b3eVirustotal results 22.95% 
2020-01-15invoice-D442_22.docdoc 6223fba003639527f555cc2407a49f113dc4b915ab798b630fa7ab7e28dac94fn/a Heodo
2020-01-15INVOICE-Q044_64.docdoc 90c1afaa5b3ec11b45a05c31ae4bcae3f687b28bf8620503dd175905dd945c02Virustotal results 18.64% 
2020-01-14invoice_JAQ72_6211.docdoc c912fbd5e3979ce3299c6cab4db775c4d86fcd1c779d4c2b402931f558484d99n/a Heodo
2020-01-14INVOICE FI48_06.docdoc 574b2bb421e5876d279f08a21722a49102902d0a532730dc18a0051a9b53067fVirustotal results 18.03% Heodo
2020-01-14INVOICE_WXF52_40831.docdoc a59898fd4715331074453846b86b94fa80c79e937fe99036976125ccd6e9b78cn/a Heodo
2020-01-14INVOICE-TYO72_55.docdoc e19211b7c079fa51a4c909460ad266587c4ac771648c802cb4af537d71e215bdVirustotal results 16.39% Heodo
2020-01-14Inv-AOL424_5417.docdoc 75eb88048fa201b46d96cca9fa12f4b4917232c3d963596554a6970d007a639eVirustotal results 13.33% Heodo
2020-01-14Invoice-CJ941_477.docdoc 0a1e8f7bbb45314ed303115d58763e0c7c2462257edad8748e7cb51fbdff890cVirustotal results 13.11% Heodo
2020-01-14invoice-ZZ897_62.docdoc 5512265b6fbdea99b35c4cc766cde6af08cba2a1dd164d56becebdfd6e5e0c1en/a Heodo
2020-01-14INVOICE XE92_22716.docdoc 161fc3f88a83e962cab9d078f53eba5954e08150c3fdd3d74882f93bdcd4b7cbn/a Heodo
2020-01-14invoice-VUX273_46101.docdoc bff484c3a259993eded74499820830eb2da53828fcc763b8f600261572c42b98n/a Heodo
2020-01-14invoice QM34_52926.docdoc 2278c3dac898445a7d43373ce735b3fb6d805d8cf5a8805d6ba8cf8fb2b3511bVirustotal results 16.67% Heodo