URLhaus Database

You are currently viewing the URLhaus database entry for http://3mandatesmedia.com/2tz-iuw5-38736/xbvar8va-s2-328692/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:302210
URL: http://3mandatesmedia.com/2tz-iuw5-38736/xbvar8va-s2-328692/
URL Status:Offline
Host: 3mandatesmedia.com
Date added:2020-01-30 06:02:56 UTC
Last online:2020-05-10 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-30 06:04:09 UTC to abuse{at}microsoft[dot]com)
Takedown time:3 months, 11 days, 10 hours, 4 minutes Bad (down since 2020-05-10 16:08:27 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01Inv_YFV18_9907062.docdoc 970df6100d8375af169bb259df2c7bb1ad641294e34ed57dc3ad02a38371b4c7Virustotal results 36.51%Heodo
2020-02-01invoice-730_03840016.docdoc 268b93c1742a7cb18681d7375d2a5c8e891d5a9e179c43d0a41ad67fbd4a0cc4Virustotal results 37.50% Heodo
2020-02-01invoice-CFMK9_55238320.docdoc 34814131cfbce6236ccc46528de3e16b4ec92bf30f74c61069f9139fe3a4df1fVirustotal results 36.51% Heodo
2020-01-31Inv HWEZ6613_489958317.docdoc df2f847e0ceb1e22def02c6e08603ca76a6c264b4bd09a2345040cd597e55d34Virustotal results 34.92% Heodo
2020-01-31invoice-ZQGV5_8463742.docdoc 37b09dc7cdaf548fb8ec04343f9c26c237ab87f2046d4cd84ece0808d38d99c3Virustotal results 32.26% Heodo
2020-01-31invoice-M5_579612.docdoc 95844f4f136d6f40bcfb49dbec7bf5a74bf6bfd460fbe68b5781251921d4f3d7Virustotal results 34.38% Heodo
2020-01-31Inv_8755_890811.docdoc 46df96b6d6abe3f84ce9afe8ccdb3aa9a9c04cdf51fe8ad27269496ad04ed9deVirustotal results 34.92% 
2020-01-31invoice-FF7_847029.docdoc 897dc97e808c47688c5b3059d5f3c26eab575728e2cef883e6ddd8243b6912d9Virustotal results 33.33% Heodo
2020-01-31INVOICE_BM541_1715246.docdoc 9316dafbf6a3e79e0e7d76104ba9c0df54ae0828bb5bf8b74896f549049770cbVirustotal results 34.92%
2020-01-31invoice-BWGG6_351213014.docdoc 034c5ce9cbef79644b17675c75923da56bd2ff3de86be9f7c6224618037ce448Virustotal results 20.63% 
2020-01-31Inv 961_94476856.docdoc facebe4f4fb11ff93ea3c94d04d02fea5330b7f8102855dd3766d5d579fe0e51Virustotal results 27.87% 
2020-01-31INVOICE-YCJ700_460771.docdoc 322bc97effba52663f35f592be159313057162f0b75287845c440a3971648cb7Virustotal results 23.73% Heodo
2020-01-31Invoice-JCI8143_404144678.docdoc b71b485d48a9f810fd8ebec5fe97b602fc643de53f6a293758662e3158f1ef43Virustotal results 22.58% Heodo
2020-01-31invoice-FGT7_31302626.docdoc a081d791c29c32e4d5663dd7bcb0b0be0014098b99bdeccbade93465ef27ef38Virustotal results 20.63% Heodo
2020-01-31Invoice-0534_93203570.docdoc 11b9cf9730c6ed1156037be7c84ed514d76300a4aed51c39c3a964f892c15b15Virustotal results 20.31% Heodo
2020-01-31INVOICE_PGW6_576073978.docdoc 6fd1cae5cdb47e68f0126cad08a0d7f3e427bf5bf3e2d8dedb5b4f74674eee9aVirustotal results 22.58% Heodo
2020-01-31Inv-3301_2469885.docdoc a9890b29941354d238ff12eddfc6773f5c173ef82fd83e37213178126b943534Virustotal results 34.92% Heodo
2020-01-31Inv-MYLN83_4297911.docdoc 14a9441a1babd407abc8b7adf58f116b1ece228986312fb3b6ade70f3c53522aVirustotal results 33.33% Heodo
2020-01-31Invoice-XBJ7_25482189.docdoc 5f956252e9f433a4b7675b2422ef016eac5627672a114bfafbc0c667a22db5ddVirustotal results 34.38% Heodo
2020-01-31INVOICE-LMCO6275_673273946.docdoc db29ff54d37ebd7694c5190fc3ddb0ceffd896c7ed43b3f4abb8ab28658ff955Virustotal results 36.51%
2020-01-31INVOICE-ZVHJ7586_12279760.docdoc 75c1a9abe81944742065299e4da5aec71b23df394635a7cd594b0bd980405870Virustotal results 35.48% 
2020-01-30invoice-HEN66_169228502.docdoc 095ae16ea2f042c2a67c760867b9e383168a9e69f35af9c53e3e42f118d8f087Virustotal results 34.38% 
2020-01-30INVOICE-60_5748751.docdoc 343861d1fd20a1d81dfe2015bacc7d3af7bce6b55515449f9053a6f15d6e4171Virustotal results 34.38% Heodo
2020-01-30Invoice-7_202512.docdoc 323766f53d2b388e82b8971edd88d09a3a400253519117b24772d1052d0cd03aVirustotal results 33.33% 
2020-01-30Invoice-A4903_100519.docdoc 7e5ebd7c5a8305e9f21d8cd9af58983623e040e0ce1e349d1e0ab7bf7b98b949Virustotal results 38.10% 
2020-01-30Invoice R422_797499.docdoc 02a48dbfe7db502e84f0c4b859dab8b9305eea30ae81465b6d8dc7121827e09cVirustotal results 38.10% Heodo
2020-01-30Inv Q4072_991081626.docdoc 4b48204ca4114875e5310a0cbf461d53232ece8466da7f4cfba62405eb3e9c58Virustotal results 34.92% Heodo
2020-01-30Invoice-7_09778056.docdoc d71b7c3a2a7f48bf8c4917a2c11a708f0bf450fdbb8fe1adfc262763b46debe3Virustotal results 30.65% Heodo
2020-01-30Invoice-6_6952560.docdoc f2e9c326af3805dac5bbef1535376beec58673651777c247938628e671f1b7cfVirustotal results 24.59% 
2020-01-30Invoice_WIOP7528_120527.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 26.23% Heodo