URLhaus Database

You are currently viewing the URLhaus database entry for http://mumbaimobilecreches.org/wp-content/uploads/zfbhKVJk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300683
URL: http://mumbaimobilecreches.org/wp-content/uploads/zfbhKVJk/
URL Status:Offline
Host: mumbaimobilecreches.org
Date added:2020-01-29 02:40:05 UTC
Last online:2020-03-08 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 02:40:06 UTC to abuse{at}ezzi[dot]net)
Takedown time:1 month, 8 days, 22 hours, 47 minutes Bad (down since 2020-03-08 01:27:38 UTC)
Tags:doc emotet link epoch3 GandCrab link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31Invoice XO88_545458.docdoc 55e09691a61d983f8bb5cb7d81ca1c07171d3248c62cfcd4f3b1a89f5e9a66f1Virustotal results 33.33% Heodo
2020-01-31invoice-AUS80_61612579.docdoc 1c2d2dcc9e0140fd9e9055a697ec4c2c969590ba93a2f5ebf75bde37cc7ba0f1Virustotal results 33.87% 
2020-01-31INVOICE-WU3981_3810495.docdoc 1092c9cc1b0dbf643c81898c30d3034b4db59f49a86de85ced39a5315ce4549eVirustotal results 35.94% 
2020-01-30invoice B367_39357423.docdoc b93c176b25e95c8538cc6e80bf1dca7b57ab9a7fe306415caed9989f1c306dd3Virustotal results 33.87% Ransomware.GandCrab
2020-01-30Invoice_XHP327_12705548.docdoc 8aa2f0d5d11a3aedd257f45c6768e0c8af5a1473436c6e956d5455494349ab8cVirustotal results 34.38% Heodo
2020-01-30Inv AAS4_48496018.docdoc 343861d1fd20a1d81dfe2015bacc7d3af7bce6b55515449f9053a6f15d6e4171Virustotal results 34.38% Heodo
2020-01-30Inv-FLZ7583_916311732.docdoc ad23200b4b35cf861876a41444203cb74f57e2be7bfddbc92b3fc7a07ecfe056Virustotal results 34.38% Heodo
2020-01-30Inv-E655_6506129.docdoc e2511be44651aece200405b1e826c57ea3f3e0fdfd2335e457b7c6a70628f1b0Virustotal results 38.10% Heodo
2020-01-30invoice-DHB6796_90717199.docdoc 17a7596a2561b8ff8cc3bf7daffec3ebf35525aa363d4659cb420d42f4af92f3Virustotal results 38.10% Heodo
2020-01-30INVOICE-9_5397513.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30invoice_QIQ2_305286.docdoc 444380961c88bf398e9078529bf648cf7f4cc69a583fea9d036c4427e533d8c5Virustotal results 34.92% Heodo
2020-01-30Inv-WWQ00_824325281.docdoc 59143f942ffc2f0d43226ecdbc3042d66ba488b6fe44506a5301169d1e6306e0Virustotal results 32.26% Heodo
2020-01-30INVOICE-CXPG008_111122904.docdoc d1dcb4fa88a056a19af9634c99847a108027f1a0f5c3fc9d0219fc0f8d676b24Virustotal results 30.16% Heodo
2020-01-29invoice-MQ8_15938136.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29invoice_RCCF280_00849389.docdoc 41ef384c11051e3b98c409f476aca9a2f5a0433e0cb411f547133b5d5727044aVirustotal results 31.75% Heodo
2020-01-29invoice-8_0268178.docdoc 8f114fa9732298d525aa216d90905f24142f129d79e62500f139a3c09db00fd2Virustotal results 29.03% Heodo
2020-01-29Inv-DI3_5558911.docdoc 3bdbcccc69e55ca69203cb80868675eb9aed4e2e9f880d181e51bb341905b8b7Virustotal results 28.57% Heodo
2020-01-29Inv_464_429797593.docdoc d965b7c533614e4ad1f1a9090edd5e83a4f4aae50a67b1ab1158ceaa31cfe7c0Virustotal results 29.03% Heodo
2020-01-29Inv VHW62_8424020.docdoc 4ebbc029641c276924244405d1b630b683f1fd7b23da40587548e7afcf5bfda8Virustotal results 26.98% Heodo
2020-01-29Invoice-3_47978139.docdoc 3be00db967f63065494037f5de7659deb23f83c948d103057222421fc50cc775Virustotal results 28.57% Heodo
2020-01-29Invoice U862_01000785.docdoc 603a04c67b941a3ff9345c94e890896e5570dd544e8ca3998f5197f45ab28f00Virustotal results 26.56% 
2020-01-29Inv-JQK5540_651218247.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29INVOICE_P6_474299.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29Invoice-1779_67823187.docdoc b49c9eba58537f8d856daded80bc9493a83c508d73423b98686d4e8b232d61c3Virustotal results 32.81% Heodo
2020-01-29Invoice_TWQ806_570256251.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Inv_2990_962593.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-29INVOICE_182_773331.docdoc b34f4ec4ae8d66b030f547efe3acc2a71c9ab564f78aac68719ec91dab613bb3Virustotal results 47.54% Heodo
2020-01-29Inv YL276_77901406.docdoc bdcef0f16c70086414ff95b69fdbbe7eb0c9814308d3d60143b6c04dfc077257Virustotal results 45.31% Heodo
2020-01-29invoice 33_7717372.docdoc f6879431b901df789082452c1c4ffa29e857d247886e421df6dda5fb3d81ca5eVirustotal results 46.77% Heodo
2020-01-29Inv SYR9_526186.docdoc 4a821bdd3d078f334c0bd64c125a412ad54ce14cdf5216cfed93b6ac8401d318n/a Heodo
2020-01-29Invoice_4460_5269100.docdoc 8a724fc60bde738694779751d6c63a7ed1caa03518b8f26b9acb36d5c1b29930Virustotal results 46.03%