URLhaus Database

You are currently viewing the URLhaus database entry for http://texasveteransroofing.com/nofij3ksa/1p79ylo-wn7s6-53005/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295008
URL: http://texasveteransroofing.com/nofij3ksa/1p79ylo-wn7s6-53005/
URL Status:Offline
Host: texasveteransroofing.com
Date added:2020-01-22 16:54:36 UTC
Last online:2020-01-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002268645 created on 2020-01-22 16:56:04 UTC)
Takedown time:4 days, 15 hours, 36 minutes Bad (down since 2020-01-27 08:32:53 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24Invoice-MQWY48_45116026.docdoc e94857e026eb6167901eb0f35ce767a9660a979e222d58bd7742dc856d375b43Virustotal results 26.67%
2020-01-24INVOICE-NR4661_957890373.docdoc 664e050389254800634ec4fd84eb6e748398d66fbee6849ad672fcf9120afc64Virustotal results 28.57% Heodo
2020-01-24INVOICE-VO366_84163072.docdoc fd255ebc4d7aba49696043197ea56c9eb9c19d23fa9582fbb03f5c09f21de9efVirustotal results 28.33% 
2020-01-24INVOICE-HIAV252_018382605.docdoc c482640e741603ad0f30884fdadd2e747985fbf957756e3ceedda5066125d914Virustotal results 26.56% 
2020-01-24INVOICE-F6713_415327069.docdoc f7176eac15d95eac5bd88c3cd09312abd4262b2688155641a95e1ab43420f4d4Virustotal results 29.03% Heodo
2020-01-24Inv 801_704077.docdoc 8b2e4b7244319f99c6c6813e954f42c6f9580320d266b016e4752e25c56f812fVirustotal results 27.42% Heodo
2020-01-24Invoice-68_114574580.docdoc 2622b65b82b50b0bda3c379b3782aff1e989e1c9532e2cc2155ba123bcba3896Virustotal results 25.40% Heodo
2020-01-24Inv-CVVV07_6928819.docdoc e6227f508ea8149469cf318e6939e1fd1d8b32b728997677e8220d7c4b827ac3Virustotal results 25.40% Heodo
2020-01-24INVOICE-GX189_955193.docdoc f650d229a5a7baea3cf86104f874121c82bb34994d2be1d3344cf45769387accVirustotal results 25.81% Heodo
2020-01-24INVOICE_RFA1_338729045.docdoc 7c181b5800d9b531de9f431cbd6947e93f55ac0e5f6fcad200acf2466f411a8cVirustotal results 49.18% Heodo
2020-01-24Inv HD18_450281.docdoc 3019c5713b1eae96e9080ac03f4c948abb9012ec8937fd082bf6f26c9aabbd98Virustotal results 46.77% Heodo
2020-01-24INVOICE-N5_192444.docdoc 8e96c8617604fd15ab39a4e48e257ad769bfc12440f857da0cb0b21ddcaa86ddVirustotal results 47.46% Heodo
2020-01-24Invoice UKS144_92757656.docdoc 34691ccf852ea3e1fc484a1b5e18dab1768f593de138bd42ccb9d6e36e58c87bVirustotal results 45.31% Heodo
2020-01-23invoice 1_20908790.docdoc 893a038578e5f21affe22f84929bfe83d54f52703b0e206956e26d9441e1c67eVirustotal results 32.26% Heodo
2020-01-23INVOICE_EQS256_9234990.docdoc 4cb4d8d3fe9f861f5ab75bb11d23fedf98a1561b3aac9173f5dc211b8bb8bd5cVirustotal results 40.62% Heodo
2020-01-23INVOICE_AF1267_96761655.docdoc d36e75fa61fbc43888ece86dae242e0123a0047b493fcf7e19a77659e8e7c952Virustotal results 30.65% Heodo
2020-01-23invoice D8787_483074050.docdoc af8976ac691aa40327d9844ef283ec4de84fd38c56d57218befd747516e4e92eVirustotal results 32.79% 
2020-01-23Inv_AKXJ107_30772020.docdoc a822d46ff789d95a0a7433319bc99c759a917cbcc998042645f54bd8bed3eb40Virustotal results 31.75% Heodo
2020-01-23Inv_AAL6_59966119.docdoc 593006cba92a18ecc6b5477610f948d7c833fb615f44c9663ec463b99307f945Virustotal results 30.65% Heodo
2020-01-23Invoice-099_69620768.docdoc 93cea3c1010026439c96c2937d17417feda4f0ea115804f4fb81ec63b50857ffVirustotal results 27.42% Heodo
2020-01-23INVOICE-3_33750391.docdoc 2b367119ba824e8b4abf036e54347d5fcbd98254e62b9d9f2b9c145c8c664c25Virustotal results 20.97% 
2020-01-23Invoice-SM800_1969030.docdoc b4f3c614764ab55febfefc958d4fb70920c4c17380c6d2adf4f77d68878598daVirustotal results 33.33% Heodo
2020-01-22Invoice-AZQ8_363781.docdoc d91efab982b2077b0cc1bb14745a710087e5faf6cf342c6e8ce97c54c04f66a6Virustotal results 35.38% Heodo
2020-01-22invoice H60_077681.docdoc 3c883920142d8e22088985f3f3594665bd83571bfb755aa1aa5b7354fa7912bfVirustotal results 29.03% Heodo
2020-01-22INVOICE_GACB1_65247325.docdoc 2c1f196e82bd394889cd401b4cd1bcc4ccb56f44577137f42f68ede8a63722a4Virustotal results 28.12% Heodo