URLhaus Database

You are currently viewing the URLhaus database entry for https://online.ezidrive.net/fonts/oaa3-p4c-410/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299501
URL: https://online.ezidrive.net/fonts/oaa3-p4c-410/
URL Status:Offline
Host: online.ezidrive.net
Date added:2020-01-28 04:55:38 UTC
Last online:2020-03-08 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 04:56:03 UTC to abuse{at}esds[dot]co[dot]in)
Takedown time:1 month, 9 days, 21 hours, 50 minutes Bad (down since 2020-03-08 02:46:36 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29Invoice MXOJ4_7811565.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29Inv-VSNE8_59846542.docdoc e14bd51bea91be160aefdfd75c853ce85ef348e87400f0d1e14b64c7d46eb748Virustotal results 33.87% Heodo
2020-01-29Inv_DZHF259_867094.docdoc bd1eac417a2f82f5ed9f7dc86783678343738758322a16a7d21d77cd587a4f55Virustotal results 30.91% Heodo
2020-01-29Inv-U141_186360.docdoc 70b79f7a9104113770865d6b9495150c39a6d3f9a5f98750ea69871f38ac5566Virustotal results 29.51% Heodo
2020-01-29invoice-SJBS225_257679849.docdoc d965b7c533614e4ad1f1a9090edd5e83a4f4aae50a67b1ab1158ceaa31cfe7c0Virustotal results 29.03% Heodo
2020-01-29Invoice-IT416_40011856.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29INVOICE_DV25_51698339.docdoc 9ab92e41150dd1c132be3b79097a4b4fff2a151a9a5d77bd3e0aaeb41a5b862bVirustotal results 26.23% Heodo
2020-01-29Invoice-D921_6450777.docdoc 67180fabd5a9287998057cd7666b1b8896941d37ba3bca1e197e27b447edec6dVirustotal results 25.40% Heodo
2020-01-29INVOICE MC28_63472391.docdoc e8eb03b874c14f0429931aa7f367e9b480b593c28963c964049ea04f6670caf9Virustotal results 30.16% Heodo
2020-01-29Invoice-DTRU91_75085455.docdoc b49c9eba58537f8d856daded80bc9493a83c508d73423b98686d4e8b232d61c3Virustotal results 32.81% Heodo
2020-01-29invoice HX523_534771.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice-H2_0801355.docdoc e32cca6446f2ddd8430400b16fc171ab3163cf8222669d7d9144e9c85904d5f5Virustotal results 46.88% Heodo
2020-01-29INVOICE 7_0319799.docdoc a286e3be694b9525530ec6a65b71a8a91e04042c3471e8a9e440f503fe8ce995Virustotal results 46.77% Heodo
2020-01-29INVOICE DRR805_8771017.docdoc bdcef0f16c70086414ff95b69fdbbe7eb0c9814308d3d60143b6c04dfc077257Virustotal results 45.31% Heodo
2020-01-29invoice IL001_62596235.docdoc f6879431b901df789082452c1c4ffa29e857d247886e421df6dda5fb3d81ca5eVirustotal results 46.77% Heodo
2020-01-29invoice-QT08_46850769.docdoc 8c0a8d6876a6c7fe44962883561d9f48615ee67f4544872ec98f47edcf516509Virustotal results 47.62% 
2020-01-29Invoice-1827_6724506.docdoc 255b6d2d7740a61962ad81bf302187f984dcefe57edd825c67985e7c4425e205Virustotal results 51.61% Heodo
2020-01-29Inv-O953_58134843.docdoc c25db0a6d33ba3de2ea0ea992b98117d92ef8cc0a1dc6d9ff79788db6ce7e06eVirustotal results 47.54% Heodo
2020-01-29invoice-L78_873122819.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42Virustotal results 43.55% Heodo
2020-01-28Inv-VD972_615018763.docdoc 1f826649cf4d7894c52b645fe736ff139ff80f0e72ebad38385e8882bc545ca8n/a Heodo
2020-01-28Invoice-D1363_69484948.docdoc 0617b35ff84886cd395bbf20745f3b82a830d97b07b0085b0f4aa056bcd57cd9Virustotal results 42.19% Heodo
2020-01-28invoice ND42_4747239.docdoc 9dbf7690bf328942e99f61b0eae8db502e74c272b7499da4342e6ee7d915bda2Virustotal results 40.32% Heodo
2020-01-28invoice-UDT6275_474689.docdoc 85e978955f2d5b46e50d3a259f837643be8e5b3e0c643465881342f1cc7f3d31Virustotal results 35.48% Heodo
2020-01-28invoice-OR976_648675.docdoc e6551fa9814756f1d99f86fe2713d695e930e5930e397affed4aa07d4ea63ba6Virustotal results 29.69% 
2020-01-28Inv L3087_88594182.docdoc 92c3a1a03abdc8976c1b9e1b200a2b08e114d2e6dfa54566f81f16a2671e9735Virustotal results 26.23% Heodo
2020-01-28invoice_7974_1998579.docdoc ff71f06910cdebceb665fef3861262fbabd9f92ebd7285926a1b3d4ed3a7c166Virustotal results 26.67% Heodo
2020-01-28Inv_0231_9503270.docdoc a7cd0e0d4371256091f7a81ff6100974822424c0c06e2dd5e07956b1ab62c19eVirustotal results 24.19% Heodo
2020-01-28invoice-B9524_109588.docdoc 9db28f01c7a26ba6a757542ddb44145a167395b639df0eac4d9f48a926d8f810Virustotal results 22.95% Heodo
2020-01-28Invoice_DC437_2763304.docdoc 58cd4f0ffbd2cfb01f153efd0e8560a2475bc3f98abaf8ed787f8fe17166524bVirustotal results 28.07% 
2020-01-28invoice-L796_7617068.docdoc a6b9f25b3f632a071e548d1e092d8557eedd074094e5e1a2dd684a724fb07fe6Virustotal results 26.98% Heodo
2020-01-28INVOICE_9_98678814.docdoc 32a27468a4355d462e5de6e29290189f023ad6b51836d3134dcb19a74f615f51Virustotal results 25.81% Heodo
2020-01-28invoice L6_401949.docdoc fad431f81e098efc657ea4c9787427f6080e70ef1ea7631dbf51f35578e79438Virustotal results 25.81% Heodo
2020-01-28INVOICE P5_186583900.docdoc 42cf3dc2c05800ee63913c2437b824f17dc2999d761edc2c318a7b94fd9ac4a4Virustotal results 22.22% Heodo
2020-01-28INVOICE-6005_785338.docdoc 0f30073111c54d8f89bd3d4c031b77db7d32447f0bee27914ac94ffedc2baef1Virustotal results 23.81% Heodo
2020-01-28invoice-44_142211.docdoc 37f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbVirustotal results 40.32% Heodo