URLhaus Database

You are currently viewing the URLhaus database entry for http://cloudcottage.cloud/wp-admin/invoice/j-6695499619-2613574-vwiso8w-171g400/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:292684
URL: http://cloudcottage.cloud/wp-admin/invoice/j-6695499619-2613574-vwiso8w-171g400/
URL Status:Offline
Host: cloudcottage.cloud
Date added:2020-01-20 13:47:04 UTC
Last online:2020-01-30 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002259817 created on 2020-01-20 13:48:05 UTC)
Takedown time:9 days, 12 hours, 38 minutes Bad (down since 2020-01-30 02:26:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-22FILE_7604373522.docdoc 88bf8d08abbaa434038e444a69dff9877dbadf1ef53e5e09b640adce1996cc03Virustotal results 32.26% 
2020-01-22K_PO_01222020EX.docdoc a8e86ce1edef7bad9f725d8f9b127d50d0a80a4e3477a2294f61bd2be001bfc7Virustotal results 31.75% Heodo
2020-01-22PO_01222020EX.docdoc ea33290e67700a0e040d99a2e1678ff58babdf5bc35437e99b372aabc8318607Virustotal results 31.15% Heodo
2020-01-22INV_DWE_010120_QFF_012220.docdoc c4b215a59659e1c91fffadf971f2d9f6a0865a757e23c4ded707e894927c7837Virustotal results 26.09% Heodo
2020-01-22M_4836418092681028258.docdoc ae732e2481c442c721b9c70bbbafde35384fc2d9c8e8426e67eabd9863b3e009Virustotal results 26.23% 
2020-01-22SW_DJU_010120_HMJ_012220.docdoc ef2c024ea8044358a0cccd5cc4d0a39745ceb272e550c3718c2617c16b822de0Virustotal results 27.42% Heodo
2020-01-22AUP_58294484.docdoc 336ab3a461e1a9206d529c38bf94f01e340884585fe63edd765c3fd0821f68e6Virustotal results 29.03% Heodo
2020-01-22SW_13565750.docdoc 96e71ebc8855336f1ff5006afcd5167486abf09cebca7b194da01a83388a9053Virustotal results 21.43% Heodo
2020-01-22DN0146208695PA.docdoc 38787b38f9ed7908075086f02ec866791014775637c563d31e7926535cfad02eVirustotal results 20.97% Heodo
2020-01-22RP_WQ1539365200PO.docdoc 8205eac5713b6e780f44ca0ead54f7b14258c7553e717184eee2ab927d901095Virustotal results 21.67% Heodo
2020-01-22PO_01222020EX.docdoc 51415e188210f4ed65f226d3c95db3cebe8f11eb840220809f57b6463eba2dfeVirustotal results 20.69% Heodo
2020-01-22SW_PO_01222020EX.docdoc 8bb40f94230c4779d38d4849765d3c668b37c66d257ecbf89fe76f042c850958Virustotal results 19.35% Heodo
2020-01-22SW_PO_01222020EX.docdoc 6321d13c864a5af9a0a39e72120db0999714232489e7bf8461b8a795db19a222Virustotal results 19.67% Heodo
2020-01-21REP_12198957.docdoc 73ae92b67a773aeb211f7520d6d98ff0b4f01babd23ad51535129e1c09c78e97Virustotal results 21.31% 
2020-01-21BAL_WZ8726113472TI.docdoc afc71ff2f950fe201610ccb3658ecabd28277de445f299d235048e06bb3c02ben/a Heodo
2020-01-21FILE_877428823138262968477.docdoc 616b942341fb4aa9e7ef9a9812fc490798f6d57020915c7fdeeb4d6abd868b77Virustotal results 19.67% 
2020-01-21BAL_18063424.docdoc 3971d2f8dad1df7ae025551c02c685cf456405eb7ba164f380e38518f2d228eaVirustotal results 19.67% Heodo
2020-01-21RRNWR7J37.docdoc b27efe734620499ff72dafb2bd9cf0650ea42d6b08f670e80149d1a7087d4f51Virustotal results 19.67% Heodo
2020-01-21PO_01212020EX.docdoc 0ba2bc2d8ddd7c95e3a17870d34c390e31968ea645b5ca3c5978da28719eeb99Virustotal results 19.35% Heodo
2020-01-21REP_FVR_010120_KBU_012120.docdoc fff53210bdb63327220fff3391a23e72f83f7224d0732a2993a962d3214adf38Virustotal results 20.00% Heodo
2020-01-21REP_FG6040542881HY.docdoc 2f2a0cf5f701e2014ef05a565aab080235be85106bd630e67bb5c9e1aabefad5Virustotal results 20.97% Heodo
2020-01-21V_AS5AODDSZL.docdoc ce7997a982cda9e7c2591ab8566bbdc583595e079b68bb121820bd81bc0f5c7cVirustotal results 20.97% Heodo
2020-01-21WX_VB8805545512WY.docdoc 3fd7f5dcc627af3f5f832b508d626dfa8691089e643a00c47c88bc2fe760fb23Virustotal results 23.81% Heodo
2020-01-21BAL_IKT_010120_GPV_012120.docdoc b3027e1a517aecd6ce516879fe1f0b6ccb4565a07aedac1df279f168ab71abd4n/a Heodo
2020-01-21RP_2152091162722060325160592.docdoc d1117a28a75e18b39ecab237339947455fc2f362df875ff30e726b14dc16ee62n/a Heodo
2020-01-21ST_VLV_010120_PUR_012120.docdoc e4932995a94e0c841f96d023503d1a1bb8e8278fe5478a736b9a4cbc83283ab7n/a Heodo
2020-01-21RP_I76U2ZJ0Y7.docdoc 3d7638d3dfb9736e90003021fd9a8a5dde3aef6a2d13539f6734043630d1d035Virustotal results 22.03% Heodo
2020-01-21ST_HWO_010120_ZOC_012120.docdoc 02ffafb9df3c1817c1407b645b452bf63dea66ee2992bd41a6a1dbc7ffed0bd3Virustotal results 21.31% 
2020-01-21RP_79023528362413333743137.docdoc b8083992ca8cf08ef3353bdea04c93eaeb2c2d9a0840119f89868e27b2261a32n/a Heodo
2020-01-21FILE_PO_01212020EX.docdoc 1a54c57512dbcac388648552cf8ec7536827af1c60f032cf6b3b6fc3197033c4Virustotal results 38.71% Heodo
2020-01-21PAY_IZN_010120_MRP_012120.docdoc 75c18f408894f1bd20cec6f8a0ee58eeafcdb92b73ab75859ce6132806d9bd4eVirustotal results 36.67% 
2020-01-21BAL_V0G36U58S424F4.docdoc bab6c6989935ad3265af5fe641a9070d85fafb84e2148f1eb356282fd2a51aecVirustotal results 32.26% Heodo
2020-01-21PAY_PO_01212020EX.docdoc 97f55cd9a4169904bb304d25dec8f7e772082dc8c1aa3468206307bb6e95df26Virustotal results 28.33% Heodo
2020-01-21PAY_BNC3KV71.docdoc 6f95ea0f92c00748e1215edfe2c7b4c7e772776fc5e4c48e67ead100f4c5c835Virustotal results 26.67% Heodo
2020-01-21BAL_19628293.docdoc 852d7c2fe2e50b54bcc8b4bd89978251dbcf736f134ce9226fbb287d77394db9Virustotal results 26.67% 
2020-01-21DOC_PO_01212020EX.docdoc ce417917d630c51e1bb6109039a5ce04622a3ca4ef6f05ed22256e1db647b5f9Virustotal results 26.67% Heodo
2020-01-20255766911025531.docdoc 22396867fdac01104cf39ac62c3bae2f0137d249c9bebc8cc1bfd2f8933f5c5cVirustotal results 26.67% Heodo
2020-01-20FILE_289292015223241683.docdoc 177f0694174d24009b23b06083a4995eccf60585b7e62d34d417adf1289579ceVirustotal results 27.42% Heodo
2020-01-20DOC_068844767242644625371210.docdoc 8c315ebf4829f97717eb97eda8aaa254483ebaf7f43e3250d0efa8990f2ffa40n/a Heodo
2020-01-20DOC_RR5229126369MM.docdoc b16d36112cca3155b6cbef2da3016063331fb3e36f67c3ea1cfc45ffbffa858eVirustotal results 27.87% Heodo
2020-01-20DOC_PO_01202020EX.docdoc 678ade151e9690c4e5554104212bb97160c5fd2fc610bf2097a6f3fe4276657eVirustotal results 27.12% Heodo
2020-01-20BAL_47538116.docdoc aa3c760924ba7c9087decd46d2af6ac7b5790dc6724f87102b5c9f3dcca76da0n/a Heodo
2020-01-20Z_RA5057005467ZL.docdoc 401366727856a23b5eaad06b1df4f9da0f5e59194b4699a4611e44ec39064cc3Virustotal results 27.87% Heodo
2020-01-20INV_M4RC2KA1OR.docdoc f2f9b5a3d8747c496c3d05e2971ba464f6b5bfa697a9dc1266160f948cac3dfen/a Heodo
2020-01-20SW_PO_01202020EX.docdoc 3afda698570eb84fb37aa40816d8b8bcf9a22942f1540d2eb53b7229b4b1783fn/a Heodo
2020-01-20INV_GYD_010120_TJT_012020.docdoc c9b678080ccb5769db65943649b9ec6468b150c65c65dd116a39c0bec4940825n/a Heodo
2020-01-20INV_56017540.docdoc 3a46342503b1e217dbc8bcfcbc367d0844404dfbceec9c423765915f603198aan/a Heodo