URLhaus Database

You are currently viewing the URLhaus database entry for http://mobilezona.by.parkingby.icu/cgi-bin/js2c4-etm-404527/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307631
URL: http://mobilezona.by.parkingby.icu/cgi-bin/js2c4-etm-404527/
URL Status:Offline
Host: mobilezona.by.parkingby.icu
Date added:2020-02-04 09:07:33 UTC
Last online:2020-02-23 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 09:08:19 UTC to abuse{at}parking[dot]by)
Takedown time:18 days, 23 hours, 16 minutes Bad (down since 2020-02-23 08:24:50 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06INVOICE_305_70829761.docdoc 0da1c4614f4062912e1ace2d0af04cc233211955ad031821bfd0670c6cdb20a4Virustotal results 22.95% Heodo
2020-02-06Invoice-770_1733276.docdoc fd7c8c6cf457d1d127ee24d40ea990ccae1f8f8e8c648e61c760124a04dd4941Virustotal results 22.95% Heodo
2020-02-06invoice-BQ53_1274398.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06Invoice_MY9_57061447.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06invoice-0_9752277.docdoc 9eca08bea00fec73f8bdc769abf28f857d39de7d922c4d0dfd4017dc5981d2b0Virustotal results 33.33% Heodo
2020-02-06Invoice-3_080586.docdoc c7b6f46f5a55f557c829d3a1e6d171b7fc2577517bd72b3219b805304f56a2fdVirustotal results 33.33% 
2020-02-06Invoice-4186_80440317.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05Inv-XPWA10_599490.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05invoice-L58_125050.docdoc 10f919530c917ae446dda34a70e6c51343f7cd00368b4fc1078c909c80df7d22Virustotal results 26.23% Heodo
2020-02-05INVOICE-TINB8989_8219426.docdoc 4152d52f1411482170163f5c1a548319cf7bf6b6e3b95a2d5dce87a21ef76708n/a 
2020-02-05Invoice-518_7740915.docdoc 2201a4749f541a2cf40d8fd07f63be119f50b2e5e4068fb16c5c4387e81d01f0Virustotal results 26.23% Heodo
2020-02-05Inv-SBP5555_359161445.docdoc 8dc01e779aa14fa6b5e6df7f2cad4edbfa0f3cb078f9022861e1676032329056Virustotal results 26.67% Heodo
2020-02-05Inv-SR7_34936255.docdoc 0a08433407c65f82bc84c43209ef3109f4df03990c2deaf2304e626beaa40d3dVirustotal results 25.00% Heodo
2020-02-05Inv-C87_7837149.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05Inv_YDX3293_865596.docdoc 28d1b238f050e82f7e6bcc571b0ece1a23309e7cf54fd2eb77d1d79a021fbd8fVirustotal results 27.12% 
2020-02-05invoice 6339_286916.docdoc 3d86715a18dc19cdf1364d58ff7deee2c387cde502de5b43166a7c0d98b2a24an/a Heodo
2020-02-05Invoice-04_87794118.docdoc dc0402b2e8b444ac6695dd0686b697822b5c339fb556f63aaf4cb4dce9354572Virustotal results 27.12% Heodo
2020-02-05Invoice GW4_931446.docdoc 9c0d8eb2c0e899f1f31e9de7017aaff6d70980005e812ac41b19aca4a6bd6514Virustotal results 26.23% Heodo
2020-02-05INVOICE-2203_134851830.docdoc cd7205a871273f045d8ee2a8621fcd7dd7778e062e3598507c21ffb656752721Virustotal results 33.33% Heodo
2020-02-05Invoice_I0_6266183.docdoc 4cdac2f4d63304355834be949d3daa22b6de9607436c0f5cbe758f86c05c5b72Virustotal results 33.33% Heodo
2020-02-05Invoice_EAWE0599_7107903.docdoc 251634753472a0f5fffce161c8c997b7ff91e76ec48b414e29737b4dc5b747e8Virustotal results 32.26% 
2020-02-05invoice_PRSX2519_276581.docdoc b9d42e016bb94271c9d10c7c68d438ead1f0078d3b0fe039da3166ed9f29432eVirustotal results 41.27% Heodo
2020-02-05INVOICE 677_640797855.docdoc 25d98e7b0341be2da85f8fbbe279863673a1b0744c9773c8f6bcaa0c0666c935Virustotal results 34.92% Heodo
2020-02-05INVOICE_JG70_4147107.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04Invoice 5_1529921.docdoc d0787010e140c3d4c833ba70fcd573e0eb42df65c29756cf65d0239b4374f915Virustotal results 33.33% Heodo
2020-02-04INVOICE KW7379_45405636.docdoc 52950a710af26f233ca1d8c57b23f9cd3d0da7046cc64f13467497b06b01b85eVirustotal results 33.33% Heodo
2020-02-04invoice-BF97_75640185.docdoc 41aea47e36728ef17f91fb0ed0239001ef742699f4e187e54d4e107680725a5eVirustotal results 34.43% Heodo
2020-02-04Invoice_417_567331463.docdoc e9289bd5ee4b42bfb14ef6ea40e133e5d9aa64ccbc59e99487f875cf21186131n/a Heodo
2020-02-04invoice-M710_392936077.docdoc defe55c9dc26d0ae8ff07ac7bfa3e4b03c672b69761fa507e15b5715ead2abc4Virustotal results 33.87% Heodo
2020-02-04INVOICE-JKLF07_3221814.docdoc b4c3990e73035881f982534ee5ccc3a30f80b58c625e28b6f68067c223589fc1Virustotal results 31.75% Heodo
2020-02-04INVOICE-P0_09073692.docdoc 40c57139f9fe475f5e06542c48aac3476cd943f3530f73ef44a60db380bf9e04Virustotal results 38.10% Heodo
2020-02-04invoice PDEK49_9669454.docdoc 904f34e3a638e5d981f17dc0728844c41378c8b8ee1f9bb7e85b614af0478739Virustotal results 39.34% Heodo
2020-02-04invoice-VLMJ5_2466294.docdoc 037d4b4e3114c4bed54d121c315def14912451fdea53cb7c1350ed4cba0b0043n/a Heodo
2020-02-04Invoice-OZS5_233629541.docdoc 90c26b84456ef49591e93a848e25f662c833cfe38dd5576c91c6e1f1aa1518ebVirustotal results 38.10% Heodo
2020-02-04Invoice-FCR5546_458978.docdoc 6f7d7c660fb2da82804d9229672b0c7bfca1e4809ede91f9002cdb7be3a4f123n/a Heodo
2020-02-04Inv-VK39_276205.docdoc 4a43eba382c637b47a46612a58b26dc621ac320d97a5ebaed2c9def69a4a34e3Virustotal results 37.10% Heodo
2020-02-04Inv PHV7_92661346.docdoc 8e66d9957e16b357616a30285cc04951088836af1778c63ca72ed2f7f0b48f41Virustotal results 33.87% Heodo
2020-02-04Inv 932_8344258.docdoc afe31791fd85a56e44bdc5261af1e3c237392614029d439e9421a09d348bc389Virustotal results 34.92% 
2020-02-04Invoice-4_22021160.docdoc 346a0ec90411bebf390879a2e88016d491a6745185c0386c40fc18fb2e9497d8Virustotal results 32.26% Heodo