URLhaus Database

You are currently viewing the URLhaus database entry for http://www.click4amassage.com/ypu/protected_zone/interior_profile/pTdRIb_Gbkt9000/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307635
URL: http://www.click4amassage.com/ypu/protected_zone/interior_profile/pTdRIb_Gbkt9000/
URL Status:Offline
Host: www.click4amassage.com
Date added:2020-02-04 09:12:34 UTC
Last online:2020-03-07 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 09:14:02 UTC to csabuse{at}liquidweb[dot]com)
Takedown time:1 month, 2 days, 12 hours, 5 minutes Bad (down since 2020-03-07 21:19:59 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-04List-MAR6898.docmdocx 3614f2f4d4f091637741fa897fbdd19777a1e2553610f8e497f1a15c01a31757Virustotal results 34.92% Heodo
2020-02-04Mes 2020_02_04 98018.docdoc 167323f590c8eea01e897581a3de8e00606c176ff6518fd3ac0a3d64dd2e7d9aVirustotal results 36.07% 
2020-02-04doc-08810.docmdocx b71394268acf3acca757143450d5ccc9030bb60cd3e5e9e3245f81fa1b63e757n/a 
2020-02-04list 20200204.rtfdocx 66fbfabc52fac899652f0e490be589ec3d3c5d3cf233ca24171ab6d8ff55a50dVirustotal results 34.92% Heodo
2020-02-04File-GSF431073.rtfdocx 29d71c405f029109b5b6a5eb51f5f957a706b5130105c3abd7e3e97cccc66c2dVirustotal results 36.67% Heodo
2020-02-04Dat 20200204 F181.docmdocx 283d9f82e7d67f60c681e0fc131777310fb598d7421d47ba38ccccd2618ed297n/a