URLhaus Database

You are currently viewing the URLhaus database entry for https://thewishes4u.com/h6y/oQlvFZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308586
URL: https://thewishes4u.com/h6y/oQlvFZ/
URL Status:Offline
Host: thewishes4u.com
Date added:2020-02-05 01:30:05 UTC
Last online:2020-02-07 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 01:32:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 6 hours, 15 minutes Poor (down since 2020-02-07 07:47:29 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07Invoice-AA718_26344590.docdoc da55d54edd3021ebaf41530e1ec8dd18fb5541bb09c3cc9d10c88e9da0351409Virustotal results 32.79% 
2020-02-07INVOICE-RKU7_7430198.docdoc fabe5daadc59a858e5152921d00a9134c5f3202570daf8fa151f214455e84879n/a Heodo
2020-02-06Inv F975_482133968.docdoc 092cafc5eaeb0e2d80004cf333e8e2d5898f25562f86323a3b31cbc1ec7b5d7aVirustotal results 29.51% Heodo
2020-02-06INVOICE_T6468_763859642.docdoc 0d52884323396c99de2994a867ebe7ccb325a7a33a6ae3317f4290517232a3edn/a Heodo
2020-02-06INVOICE-QA268_812772607.docdoc 4a24444820e9cbd0c73e0d97f291e4679d283f5c6fd44db547c58a37d62b4b83Virustotal results 29.03% Heodo
2020-02-06Inv IAKC89_5334735.docdoc af68f95640411edf06350ddc5f697fa63501dad1a427026652ba7a411e87c258n/a Heodo
2020-02-06invoice-EFQC9993_82740993.docdoc 08a17a2ca774e5d63d00d6347ab8569354e6fc33b9e65cd55db64f088125e77fn/a Heodo
2020-02-06Invoice-31_9189084.docdoc 72cf0e1c89a577b94531a7723c3d176dfd37839c0b19bc7878c49945f7dd7339n/a Heodo
2020-02-06Invoice ZZXJ018_57367966.docdoc 81fae48623d822ab3081546ad2888a2ecb9c1c93e996888dd154be91b9d8ff74n/a 
2020-02-06invoice-DC57_679054.docdoc 515c3515f3728002f957e469f6d30be479f3db347968856134e1f0287ad0438eVirustotal results 24.19% Heodo
2020-02-06INVOICE-QF81_88000187.docdoc e10f7b95c27f399f5a1a28c5e94c61bc47ffb9f8bd9ab3bb562cf27be6460e88Virustotal results 26.23% Heodo
2020-02-06INVOICE-CZS9_2188817.docdoc d8a98e712d6775091bbcdbe1e2b1ed30135d7fcb59a9ec4ce71bd80823438c5aVirustotal results 23.33% 
2020-02-06Invoice 6_00863861.docdoc 7ad99b709d5c3d50453570493936ede1000d65e4f2d8223627a41c8faeb71b65Virustotal results 23.33% Heodo
2020-02-06invoice XCD76_263252218.docdoc b0568d9ff726c394e4b6a7b7a59c6dcccfff57c4d618bb531c30dc3ffa5aaeedn/a Heodo
2020-02-06Inv EK7_466948725.docdoc c137f96ad20933f15cbd33dd13a59de4aa1b0e84ba2d9ffeca8835eb21d271e8n/a Heodo
2020-02-06Inv-Z02_3309041.docdoc 12368c93f93b5feac92d01c7f620337dcbaab18dc50b27dfe2a50ebae513d355n/a 
2020-02-06invoice-IXGC1_139873371.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06Inv D5414_710562259.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06INVOICE-SA4_38784337.docdoc 7bfbdbf8dda70b20e5d40d50d878d970a765a65fc39e856fb26e8c525a4a45e1n/a Heodo
2020-02-06Invoice-QKUT232_574742043.docdoc 90250acf44f763164182f91d1d9e734ea442e491965e1c3883ed40fea09f0d2fn/a Heodo
2020-02-06Inv-KY4353_41262090.docdoc 955266fef242bce6acb2e20a60ae98fcbe68846f196fbbabfe5304bf7c56aacbn/a Heodo
2020-02-05INVOICE_DQ7_7343166.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05invoice-C49_05247560.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05Inv-G45_538021.docdoc 4152d52f1411482170163f5c1a548319cf7bf6b6e3b95a2d5dce87a21ef76708Virustotal results 26.23% 
2020-02-05Inv RSDD7_7511978.docdoc 0730eae02471503c7ab9c5f470a916f7f1578c78676c2c401ecd562214e25d37n/a Heodo
2020-02-05Invoice_MAEF9_202167158.docdoc bac64a981e3fddb119868ac4b6c14005db9b3c64f608849911d6c08947267dcan/a Heodo
2020-02-05invoice-F059_813013171.docdoc 86dcab95611cd3f691824d94d3910ca546323de58d60f9b04d0b7959d2759a75n/a Heodo
2020-02-05Invoice LQ7040_35322065.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05invoice-066_46725718.docdoc 927609b9f9efb576a2233015595d50cfecd6d736c6fda23e8742330c6051e64cVirustotal results 25.81% Heodo
2020-02-05Inv-KLBD3_64898187.docdoc 3d86715a18dc19cdf1364d58ff7deee2c387cde502de5b43166a7c0d98b2a24an/a Heodo
2020-02-05Inv_YART6825_422969.docdoc dc0402b2e8b444ac6695dd0686b697822b5c339fb556f63aaf4cb4dce9354572Virustotal results 27.12% Heodo
2020-02-05Inv-M11_674899085.docdoc fa5927f2181dbeaef9cab75616169a02fe02b41df92e598cabad444619c3befcVirustotal results 26.23% Heodo
2020-02-05Invoice B232_185218.docdoc 6e6b6b51d4a9dd7f74e82c53490f95ead4a4d2a9a4adb06f1cbd991bc2b225a7Virustotal results 33.33% Heodo
2020-02-05INVOICE RPS0489_264721.docdoc 4cdac2f4d63304355834be949d3daa22b6de9607436c0f5cbe758f86c05c5b72Virustotal results 33.33% Heodo
2020-02-05INVOICE_ZB4_3154533.docdoc b376816250d05683e509c36b70c10c82f78198b2daef4ff81ff5ff8515932429Virustotal results 33.33% Heodo
2020-02-05Inv_RBX7_061195.docdoc b9d42e016bb94271c9d10c7c68d438ead1f0078d3b0fe039da3166ed9f29432eVirustotal results 41.27% Heodo
2020-02-05Inv-SOR92_3408238.docdoc 4887e700c4997ddaab9733c0dc0696a27e93eb2c02e2839119c077c2b92fd2d6Virustotal results 34.92% 
2020-02-05Invoice T850_492652.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 45.00% Heodo