URLhaus Database

You are currently viewing the URLhaus database entry for http://fixusgroup.com/87/NWaPzyV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:298814
URL: http://fixusgroup.com/87/NWaPzyV/
URL Status:Offline
Host: fixusgroup.com
Date added:2020-01-27 14:09:36 UTC
Last online:2020-02-06 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-27 14:10:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:9 days, 20 hours, 4 minutes Bad (down since 2020-02-06 10:14:40 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29invoice 77_368062.docdoc ac526756febc20f08f708ba667099d002839779083b6c455bb3ab6dd634ab0bfVirustotal results 26.98% Heodo
2020-01-29invoice 77_368062.docdoc ac526756febc20f08f708ba667099d002839779083b6c455bb3ab6dd634ab0bfVirustotal results 26.98% Heodo
2020-01-29invoice_MXB53_6858281.docdoc 6077c5ee924fd1317126a29882130f9dd36500a876d171c9789ef0427b7f3351Virustotal results 30.65% Heodo
2020-01-29Invoice-5_282830768.docdoc e8eb03b874c14f0429931aa7f367e9b480b593c28963c964049ea04f6670caf9Virustotal results 30.16% Heodo
2020-01-29INVOICE YXB14_311718988.docdoc 7cbcad4d6e9ad8438e5febd3830bff9aef4729b98d23935ad7f9e6d290272732Virustotal results 32.79% Heodo
2020-01-29INVOICE_K6_775669507.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice-YJG831_411452.docdoc 0d59daa51eb7228797a0ca35d46c6419936ef4df01bdfe603db22aa45a7ad0eeVirustotal results 47.62% Heodo
2020-01-29INVOICE 0354_631859027.docdoc 11b4519b76957b0758381f8e19c5e15d8744f7974716642aeb586c615dde38faVirustotal results 48.39% Heodo
2020-01-29invoice-K32_107745.docdoc 4a272dd4a5c6261e983d667dd676875054dd4a4ea11620f16c553fcfd2c44861Virustotal results 46.77% Heodo
2020-01-29INVOICE 2_22225508.docdoc aa6ceb17ced471e1695c99c0718bc24c710311f0daa256cb0783d82218d772c9Virustotal results 47.54% 
2020-01-29Invoice-GK447_789346271.docdoc 8c0a8d6876a6c7fe44962883561d9f48615ee67f4544872ec98f47edcf516509Virustotal results 47.62% 
2020-01-29Inv_YPSS7_47075525.docdoc 255b6d2d7740a61962ad81bf302187f984dcefe57edd825c67985e7c4425e205Virustotal results 51.61% Heodo
2020-01-29Inv_F58_5624921.docdoc 31cceba3e1a72b632ba31d1f3ee6d78db5030851ed68faa8c545c8bd7893829eVirustotal results 50.00% 
2020-01-29INVOICE-2_402198.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42Virustotal results 43.55% Heodo
2020-01-28Invoice-4622_333994.docdoc 1f826649cf4d7894c52b645fe736ff139ff80f0e72ebad38385e8882bc545ca8n/a Heodo
2020-01-28invoice KHZ51_334252175.docdoc 0617b35ff84886cd395bbf20745f3b82a830d97b07b0085b0f4aa056bcd57cd9Virustotal results 42.19% Heodo
2020-01-28invoice-IFOH1985_23483290.docdoc b7109568a2beba7e63236e9fae5d014d43ea3164de3e4149790c89356b10766aVirustotal results 39.68% 
2020-01-28Inv 434_85822360.docdoc 85e978955f2d5b46e50d3a259f837643be8e5b3e0c643465881342f1cc7f3d31Virustotal results 35.48% Heodo
2020-01-28invoice 6529_54128178.docdoc e8c780bbb1f9fd071b00776b138b3cf27c3815c7203593068e78774d4dbdb36aVirustotal results 30.16% Heodo
2020-01-28Invoice JCU51_144738.docdoc b351412551b1d480fe50603de72c1d23a0afa22991461d2b812edbf5ad7d6021Virustotal results 25.81% Heodo
2020-01-28Inv_VLM6_46817529.docdoc ff71f06910cdebceb665fef3861262fbabd9f92ebd7285926a1b3d4ed3a7c166Virustotal results 26.67% Heodo
2020-01-28Inv_Y150_1475736.docdoc a7cd0e0d4371256091f7a81ff6100974822424c0c06e2dd5e07956b1ab62c19eVirustotal results 24.19% Heodo
2020-01-28Invoice M4639_442863262.docdoc 160fe2d4287a96770020461a685816eb0d9ba8b3a3275b86f708784b778f380eVirustotal results 22.58% 
2020-01-28INVOICE_S4_33475648.docdoc a6b9f25b3f632a071e548d1e092d8557eedd074094e5e1a2dd684a724fb07fe6Virustotal results 26.98% Heodo
2020-01-28INVOICE-CUF2_087283.docdoc 32a27468a4355d462e5de6e29290189f023ad6b51836d3134dcb19a74f615f51Virustotal results 25.81% Heodo
2020-01-28Invoice YF5_073464887.docdoc fad431f81e098efc657ea4c9787427f6080e70ef1ea7631dbf51f35578e79438Virustotal results 26.98% Heodo
2020-01-28Inv-EXIT9_097378.docdoc c281f5dc7b7f7e91c714324444133165bc38d375cb72d3a5624d452111fa3af0Virustotal results 27.42% Heodo
2020-01-28Inv-D2_897458.docdoc 42cf3dc2c05800ee63913c2437b824f17dc2999d761edc2c318a7b94fd9ac4a4Virustotal results 22.22% Heodo
2020-01-28INVOICE FL9_94470313.docdoc 0f30073111c54d8f89bd3d4c031b77db7d32447f0bee27914ac94ffedc2baef1Virustotal results 23.81% Heodo
2020-01-28invoice_OIU661_02706969.docdoc 69e19219795fcc89a44dc863d7b1c970f92a785afb3c7bfe3923562119c32adeVirustotal results 24.59% Heodo
2020-01-28INVOICE-RMK676_864343.docdoc 37f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbVirustotal results 40.32% Heodo
2020-01-28INVOICE-4160_87824000.docdoc fbe992a68ce37d101a4005da5062aee9e868e5885fe5b4c69e69c0981c8eeaffVirustotal results 40.98% Heodo
2020-01-28invoice_UGZP0_94721337.docdoc 6f7ef2942319a8f55b338d43ac0717e2999baaf867ba160e6cdc15c85b47a4e1Virustotal results 34.43% Heodo
2020-01-28Invoice-8_2767435.docdoc 4732690cf746cecd8bd49d095d5514cf185703860490402cc2a5cfbb9e3fadf1Virustotal results 32.26% 
2020-01-27invoice-N96_963527306.docdoc 212ac9821bc94807499f7c70ca0a521512acc944d0bbd2c1a61078fc96303634Virustotal results 32.26% Heodo
2020-01-27INVOICE-5864_4859974.docdoc 4ec6f4e3c42c761d38c46394803e40b4a8e590ee2baa48b27ace184f052c7546Virustotal results 30.00% 
2020-01-27Inv V8_16270660.docdoc e16aaeed5f48de4896425925bfbdd114b6e826d637a742994234703ea8cd20eeVirustotal results 23.81% Heodo
2020-01-27invoice_WAQ3419_49377922.docdoc 844e6dce32ab6c95097c5fd947761f9c4c47cd4a18f6f88e94b906eec219b073Virustotal results 21.31% Heodo
2020-01-27Inv_QO760_762939.docdoc a82a5565fa6fa3cc58f4ef09aba324cd26d2df87c09e7e74c9e318bc858fdebfVirustotal results 24.19% Heodo
2020-01-27Inv_HYOI045_161040.docdoc a17c7a0cfb68c56218c84e60bc9a2c632ade47c95377dc16522a34e62579406dVirustotal results 24.19% Heodo
2020-01-27Inv-KO0_7249308.docdoc dfaa827439562eeff34e4ee725e9e1d19ecab21556134361ab102dbb7f41afceVirustotal results 22.58% Heodo
2020-01-27invoice 26_287520974.docdoc 6cddcfd58c789c8db9ae41d6a91bf3070fa44d597a43db9d3726e6b7bf56a93cVirustotal results 26.98% Heodo
2020-01-27invoice_C659_47515289.docdoc 68fa47236ef5188fef3189ae8f5839c486a5f313d0c22c5457d01822e8bbfdaeVirustotal results 22.58%