URLhaus Database

You are currently viewing the URLhaus database entry for http://clicksbyayush.com/wp-content/MKC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:302103
URL: http://clicksbyayush.com/wp-content/MKC/
URL Status:Offline
Host: clicksbyayush.com
Date added:2020-01-30 03:50:05 UTC
Last online:2020-01-30 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-30 03:50:06 UTC to abuse{at}godaddy[dot]com)
Takedown time:19 hours, 40 minutes Good (down since 2020-01-30 23:30:40 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-30Invoice-XH4_165152909.docdoc 344ec62beaa38421243bae13fa80d39d7457a5c8a11c3347366c3e638d1326e0Virustotal results 33.87% Heodo
2020-01-30INVOICE-IU1747_964817.docdoc 18679279d06463ba2ca553b32ba509a6cb62381bda5381ab82d862beb91da074n/a 
2020-01-30invoice KW80_059829379.docdoc 0cd2361c959ed9e7e67f305e10241dac8c04cf6aa8816a02fa0ecd57f3b8e66eVirustotal results 35.00% 
2020-01-30invoice-Y128_3987916.docdoc 2e05dae96f07956982b9edba6d64d8668b4ff90f56d548ce2ef2feee40a6e6d5Virustotal results 39.06% Heodo
2020-01-30INVOICE JQCM4_603379747.docdoc 4b8c920544a36d2b2fe8e35aafddad4a1052e8cced8e159cf4b9753d1c1a82eeVirustotal results 38.71% Heodo
2020-01-30INVOICE_LP802_06456268.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30Invoice_8_732251815.docdoc 35b7d39e8f33f3118f3d205355b739038483d471119ac6d7712d92ad982c756fn/a Heodo
2020-01-30INVOICE INB0624_142847.docdoc 9440498706f2d925d78ed85c677ee615fe3fdf05c7188cf59cadf543e59e0c32Virustotal results 32.81% Heodo
2020-01-30invoice-PDT604_91989600.docdoc d204a8808c41d9dbf3ad604139c838f916986ce563143b7e41b33c85d22d5973n/a 
2020-01-30Invoice-5605_229779371.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 26.23% Heodo