URLhaus Database

You are currently viewing the URLhaus database entry for http://premiumctoursapp.com/plugins/payment/c-1180-84-fzv7iw9-lvfon4gge6p/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:292598
URL: http://premiumctoursapp.com/plugins/payment/c-1180-84-fzv7iw9-lvfon4gge6p/
URL Status:Offline
Host: premiumctoursapp.com
Date added:2020-01-20 11:14:04 UTC
Last online:2020-01-29 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-20 11:16:03 UTC to abuse{at}hostinger[dot]com)
Takedown time:8 days, 17 hours, 20 minutes Bad (down since 2020-01-29 04:36:49 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-22PO_01222020EX.docdoc b6999705277729c939e96716e980ab59bfa3fc515914805b4f4d3a3b3fd82f19Virustotal results 20.00% 
2020-01-22T_83138229.docdoc 38787b38f9ed7908075086f02ec866791014775637c563d31e7926535cfad02eVirustotal results 20.97% Heodo
2020-01-22SW_PO_01222020EX.docdoc a3bb6d6bcd9d88ac88e712c7414053eed187a6374f15e40ecdda06f08573ab44Virustotal results 20.00% 
2020-01-22Z_PO_01222020EX.docdoc 6dd831fbe1f601834039bd80bbaf9b2bbe45f08d144b5d4ad5caa0e8135df998Virustotal results 20.00% 
2020-01-2204622195.docdoc 1e54cd50a3b76b1793e808e5a24b2fce52575465d078bedf95d58b42d62ff7fbVirustotal results 20.00% 
2020-01-22NC1610401662YL.docdoc 6321d13c864a5af9a0a39e72120db0999714232489e7bf8461b8a795db19a222Virustotal results 19.67% Heodo
2020-01-218FNO3NYSAOTW.docdoc e7cfcc5924207c0384febd2ca4125ab12dc6c893443adf4fecf44f056f3e243cVirustotal results 20.97% Heodo
2020-01-21PAY_SNO_010120_TIU_012020.docdoc 894abb9c75bfdd49638d03fd938c506194154e552372c3b4b639f08d351ac004Virustotal results 51.61% Heodo
2020-01-20FXJL7SLIE7BBJ6.docdoc cee1fe9ba8180b8e239586bb644d6f1383fe738b9a91df4071fa6018872aa2c3n/a Heodo
2020-01-20PAY_46166683.docdoc c7358ce49c500331663e15cc7789c296cec40e96d53a85c57cfcb1c7b017195fVirustotal results 25.00% Heodo