URLhaus Database

You are currently viewing the URLhaus database entry for https://www.cythia0805.com/wp-content/invoice/7g1gdvyjxe/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:297637
URL: https://www.cythia0805.com/wp-content/invoice/7g1gdvyjxe/
URL Status:Offline
Host: www.cythia0805.com
Date added:2020-01-25 00:28:03 UTC
Last online:2020-01-25 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-25 00:30:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:18 hours, 47 minutes Good (down since 2020-01-25 19:17:08 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-25DOC_PO_01252020EX.docdoc 34aa6087e68b3ce662e6557691a32813facf9d5a8b055940a76193565f6473d4Virustotal results 43.75%Heodo
2020-01-25FILE_37488238.docdoc f8ee59107bdd75ff94333f4c6e033dff2f63c36e718dc1d03c6ff6ace161c3e3Virustotal results 43.55% Heodo
2020-01-25RP_PO_01252020EX.docdoc 3f93a1894db7469c24ccb346653065517cbf6808ffa94c8049bad3505289d9efVirustotal results 45.00% Heodo
2020-01-25PAY_EMD_010120_QWF_012520.docdoc 1922500a8b7f965546a36175f30b676e283aaadfc423b1e413c0ec12d746227bVirustotal results 40.62% Heodo
2020-01-25HZX_9OJMZ3SV9W5V2V.docdoc d78753389d585731fc8ba673fddfdbe703213d197621c83a09a5076abea28b71Virustotal results 40.32% Heodo
2020-01-25DOC_32693248.docdoc 80912bbaaf3a07accf197672d0682f43795eaad5b8ab154170db3a552b14877fVirustotal results 40.32% Heodo
2020-01-25SW_07667551.docdoc 5bab3be34a267e5704e0a91e2761e11507b3eb03d5c35d64686372010bc0c87cVirustotal results 41.27% Heodo
2020-01-25FILE_8A2N7SPMIE9UF8JQ.docdoc c14d937dc4e0b3887adf845313fad5e4dcda9f891802606087dbd8eda07ada20Virustotal results 40.32% Heodo
2020-01-25ST_EI1284046808CU.docdoc a3d7b01446bfb5f062098c68a00c1bd211e610bc191f04a20e751c5140a8478bVirustotal results 37.10% Heodo
2020-01-25U_UP7220077680OO.docdoc 10ccb0e6114b2932239292f029d8acd20c85228b81942340acfa1379b887ba02Virustotal results 34.92% Heodo