URLhaus Database

You are currently viewing the URLhaus database entry for http://mynotesfromnewengland.com/cgi-bin/nnoz0m-4xl0-4357/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300889
URL: http://mynotesfromnewengland.com/cgi-bin/nnoz0m-4xl0-4357/
URL Status:Offline
Host: mynotesfromnewengland.com
Date added:2020-01-29 06:44:06 UTC
Last online:2020-02-01 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 06:46:04 UTC to abuse{at}a2hosting[dot]com)
Takedown time:2 days, 20 hours, 35 minutes Poor (down since 2020-02-01 03:21:30 UTC)
Tags:doc Downloader.Upatre emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31INVOICE-LZH51_88625608.docdoc db29ff54d37ebd7694c5190fc3ddb0ceffd896c7ed43b3f4abb8ab28658ff955Virustotal results 36.51%
2020-01-31Invoice LLOP430_5485133.docdoc 943444f98f1bb22118cddf2198722733aa216ad0aa313ece459ae6e268a9e2c0Virustotal results 35.48% Heodo
2020-01-31INVOICE-8868_4888407.docdoc 27d755aa7bf58559ed73cec0d481fe32fe0d81d2f18da774763c0da9e5c15b5bVirustotal results 33.33% 
2020-01-31INVOICE-859_7126068.docdoc 797c8a01976f70efa8f735c4a8f0d80a805578978d7f025c204d3e99a1a67d29Virustotal results 33.33% Heodo
2020-01-31INVOICE DHQ1235_034111168.docdoc 9931f06412385e83080f75415b9fba75bafafe36cb481e478b635d4dca29d0f3Virustotal results 33.33% 
2020-01-31invoice 6905_75571716.docdoc 8dece0d2130198c1d3acb7688f96392e3ded40745d7d8f7c01f03337209801f9Virustotal results 34.38% Downloader.Upatre
2020-01-31INVOICE-32_32572404.docdoc 2a154df78f570ed8acf939ecc71aa078e047b4a0b7cadbcc449df5c0d3f0f665Virustotal results 34.92% 
2020-01-30Invoice_F1677_15844956.docdoc 228960ea68978d82cf8f245946c0522095c90c78bd4a188a620e87d306c2619aVirustotal results 34.43% Heodo
2020-01-30INVOICE-M1970_18016057.docdoc 8aa2f0d5d11a3aedd257f45c6768e0c8af5a1473436c6e956d5455494349ab8cVirustotal results 34.38% Heodo
2020-01-30Inv-XLH0304_675450.docdoc 9e5e33a967ae502e2a528fd31502336cc68f2deff565b4760bc2eee148ae87f7Virustotal results 35.48% 
2020-01-30Invoice_49_5910345.docdoc 0cd2361c959ed9e7e67f305e10241dac8c04cf6aa8816a02fa0ecd57f3b8e66eVirustotal results 35.00% 
2020-01-30INVOICE JUBX7825_945639212.docdoc 9d23b6da889229ad96e4d4ac90dd6c382fca9006273b8de6254bd3fe1415f403n/a Heodo
2020-01-30Invoice YCO9997_6694633.docdoc ea0054ea77bae531dfe21c9c57ed960e3fdea5d9d5472e752c8cb6e12589e6f1Virustotal results 35.94% 
2020-01-30Invoice-FLD41_9794128.docdoc d56e776237f0e2f1be46e032a21e425c59b7e0269fdb96d3cf6ec91326785b19Virustotal results 38.10% 
2020-01-30Invoice-759_46642711.docdoc f274292ec06934b8c2417a6103a2558010703119785efb96e2443e57f4e1c658Virustotal results 34.38% Heodo
2020-01-30Inv-2_70859927.docdoc 9440498706f2d925d78ed85c677ee615fe3fdf05c7188cf59cadf543e59e0c32Virustotal results 32.81% Heodo
2020-01-30INVOICE_0459_062098.docdoc e88c11fe26e7cad165df54049eeb12ea47f3cbb684fb6f8a5235d4a379e646ddVirustotal results 31.75% Heodo
2020-01-29Inv-47_257721829.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29Inv UPJ9601_1789382.docdoc 41ef384c11051e3b98c409f476aca9a2f5a0433e0cb411f547133b5d5727044aVirustotal results 31.75% Heodo
2020-01-29Inv_2_890889.docdoc 829a7809009f98e48474acb1055638a301574dc66340f546a4f96029e8a6cb9aVirustotal results 29.03% Heodo
2020-01-29Inv-066_921996.docdoc 0e7d6a780c7dedc2d2625158cde219a2df7eb7b37a509c810644085e1781eb12Virustotal results 29.69% Heodo
2020-01-29INVOICE-QRCP81_972278.docdoc d965b7c533614e4ad1f1a9090edd5e83a4f4aae50a67b1ab1158ceaa31cfe7c0Virustotal results 29.03% Heodo
2020-01-29Invoice-YZD5_96382402.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29Inv 2_124027.docdoc 3be00db967f63065494037f5de7659deb23f83c948d103057222421fc50cc775Virustotal results 28.57% Heodo
2020-01-29invoice_A4082_16770285.docdoc ae350e475f5f34203313d523d6a5b8eec86357ef06ca6c9cc222d2c353506387Virustotal results 26.23% 
2020-01-29Inv_ODIY54_874896.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29invoice-4_76893015.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29Inv-EVQ4_312984.docdoc b9b47debd4d9fb932401d580847e8c3f82b770c5163dbc7d405aefb5cc704a1bVirustotal results 31.75% 
2020-01-29Invoice-YWMJ915_87999537.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice-Q39_4980689.docdoc c135f36d3346699e6d2bf9f5f5f638fd9475c0b12144a15a0652b8f1ebb25c12Virustotal results 40.62% Heodo
2020-01-29invoice-FLRP048_989410.docdoc cba1c3070f76e1a2705afee16bd987b6a8ffa45900cab8cf3b307f60a7b89ac9Virustotal results 49.21% Heodo