URLhaus Database

You are currently viewing the URLhaus database entry for http://www.xnautomatic.com/gij0w/rjscom-ue1-478519/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303372
URL: http://www.xnautomatic.com/gij0w/rjscom-ue1-478519/
URL Status:Offline
Host: www.xnautomatic.com
Date added:2020-01-30 22:20:06 UTC
Last online:2020-02-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-30 22:22:03 UTC to mazhiqiang{at}yunify[dot]com)
Takedown time:19 days, 11 hours, 40 minutes Bad (down since 2020-02-19 10:02:54 UTC)
Tags:doc emotet link epoch3 GandCrab link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01invoice_ETF699_95369627.docdoc 970df6100d8375af169bb259df2c7bb1ad641294e34ed57dc3ad02a38371b4c7Virustotal results 36.51%Heodo
2020-02-01Invoice_DN6_195265.docdoc b225d3511dd0119fa72b7116c46dcc71459483e37ecfe6b8d33ddf8b304f69ecVirustotal results 35.48% Heodo
2020-02-01invoice-QQQ5_52929782.docdoc 068c0fa7ec2b72cc8c87bf99a725b7e44c8a49a5b8461358acd77d6186504229Virustotal results 35.94% Heodo
2020-01-31INVOICE-ZN4432_52239139.docdoc f0d28a1e8335c23501d77ef7d61978670eb8a6bf2a3ff5304952a22a6169e264Virustotal results 36.51% Heodo
2020-01-31INVOICE PCDT3_436881847.docdoc c1b4d23bd83fee4bbb478dda10da921ecc78eb510222a47bc7cbd7735730f810Virustotal results 31.67% Heodo
2020-01-31Invoice-E238_752875.docdoc 3f50f69467b1d9189acc782e1f88059f8d28905044f5ef7d851a765a4e363748Virustotal results 33.33% 
2020-01-31Inv-KI8_01156727.docdoc 557385e0fca72ec0e0cb78e4fa3878193ac984e8c59bb33353c6565695d6a1c3Virustotal results 31.25% Heodo
2020-01-31Invoice 4_531158205.docdoc a115ef55d711a5d427c34f3a137134300800b5222228f724ecdecb767aa5ea28Virustotal results 34.38% Heodo
2020-01-31invoice UFJE0_059780.docdoc 48aece09b58178b17b2a09cebbb26f2da0bc3e6140b65d86b642060ec00689e5Virustotal results 33.33% Heodo
2020-01-31INVOICE-GZTM8488_2003168.docdoc 2041559b24b2289ef8263b1c8335bd87424dc62061a72b4bfdd5525b98da6b54Virustotal results 28.57% Heodo
2020-01-31Inv HD65_37140982.docdoc e01b9d1ec39ab6b746fab54011b045e107974f3d979db52766632eec495d9b59Virustotal results 33.33% Heodo
2020-01-31Invoice-UGE633_4376011.docdoc 8e0afd2fa4abbe847f9ff21eb7ac55c920eb69a98ebf7d214cd28aa32d5a5eccVirustotal results 26.56% Heodo
2020-01-31INVOICE EUC784_0062332.docdoc 6fdc7cfb6df1cc8fa285d4b835fda141f246bc515b015593b6389ca4e0dbd5b9Virustotal results 21.88% Heodo
2020-01-31Invoice-A8_395194059.docdoc 6fd1cae5cdb47e68f0126cad08a0d7f3e427bf5bf3e2d8dedb5b4f74674eee9aVirustotal results 24.59% Heodo
2020-01-31invoice-RW5_6310479.docdoc b7240479fd2d092d581c72b25531ea78df9956fb2ea6457b82a34c9c45986bb6Virustotal results 20.31% Heodo
2020-01-31INVOICE DVTQ56_703547.docdoc 351944f1b5408cb7f023e5c428eb6683f1780f8d27dec005c66b5163cc26b397Virustotal results 20.63% Heodo
2020-01-31INVOICE_LYT264_157162.docdoc e37ea56013de3f5e376abe94907f943d3d382cac1855f56a3841694118a80c80Virustotal results 20.31% 
2020-01-31Inv CBO6_668028180.docdoc fc244aba71a46c59805f50c5e9bfbed39277b6c94199062748330ab074a89a11Virustotal results 20.31% Heodo
2020-01-31INVOICE-UJHC0214_961257564.docdoc 02d0fca16499272621f28342b9c41dfc3c6133eb9cc3d485b8334de09bc9825fVirustotal results 22.03% Heodo
2020-01-31invoice-HAL8090_14806406.docdoc 0af8d518c01ba62f4ab1797e291f6959f027008aa5899a8ef72a85cab4830de1Virustotal results 35.94% Heodo
2020-01-31INVOICE_UCW45_4888287.docdoc 813226187f75c12909c10d00dfafe96c916ad768979a68def760048753fdea9eVirustotal results 34.38% 
2020-01-31INVOICE-50_789325.docdoc d74b87f85b69bdff1d86ddfca587e4dd079798c98cf7dc80f9515e4d9ccdf8d9Virustotal results 33.33% Heodo
2020-01-31invoice UR5295_24828055.docdoc 5f956252e9f433a4b7675b2422ef016eac5627672a114bfafbc0c667a22db5ddVirustotal results 34.38% Heodo
2020-01-31invoice I01_4823604.docdoc 1c2d2dcc9e0140fd9e9055a697ec4c2c969590ba93a2f5ebf75bde37cc7ba0f1Virustotal results 33.87% 
2020-01-31Invoice 320_653715.docdoc 1092c9cc1b0dbf643c81898c30d3034b4db59f49a86de85ced39a5315ce4549eVirustotal results 35.94% 
2020-01-30Invoice-M7651_32887025.docdoc b93c176b25e95c8538cc6e80bf1dca7b57ab9a7fe306415caed9989f1c306dd3Virustotal results 33.87% Ransomware.GandCrab
2020-01-30INVOICE 9_1165848.docdoc 1803eedd37390563f52b9a4968d9d7b9a3e9c85ec7d838abb06766dda2058094Virustotal results 34.38%