URLhaus Database

You are currently viewing the URLhaus database entry for http://www.epicmusicla.com/sites/En/INVOICE-STATUS/Invoice-57048/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:30913
URL: http://www.epicmusicla.com/sites/En/INVOICE-STATUS/Invoice-57048/
URL Status:Offline
Host: www.epicmusicla.com
Date added:2018-07-11 16:39:23 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-07-11 16:40:37 UTC to soc{at}sucuri[dot]net)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-13inv-SG-5920148.docdoc bf82411af4ed52c270050930c3bee33a983a87e0dba7ce9f3f98442f78254de9Virustotal results 40.68% Heodo
2018-07-13INVOICE-090-K-331220/1.docdoc e9e855fa46a7c0ddaf3cefc2dcb0219e0fd1dc9f7bb43f40545efca46b76ab71Virustotal results 32.20% Heodo
2018-07-12inv-2018-07-13.docdoc 3753a2b285370ec46642b60cb7c801542711d240a4e12984a7f1d798bc5cd31fVirustotal results 22.03% Heodo
2018-07-12invoice-LC-852612.docdoc cdbf2adf10c57d55263caae290227bb8560a2556ef5dd2b6bb2104930da10c96Virustotal results 22.03% Heodo
2018-07-12INVOICE-07382231/85.docdoc 45b41cba1d28cbaad9014000be33edefffea668799c0fa2e14e41643432b4c18Virustotal results 22.03% Heodo
2018-07-12inv-KV-989241.docdoc c3edc524c521abfbc6b205dfade64b4d24a5307f8abaea357c2964b6b44796a7Virustotal results 23.73% Heodo
2018-07-12invoice-2018-07-12.docdoc aeca1d91ad39e7855bd2b0b82ce72814340f1aeb4aa8a0596dae1e484a003f1cVirustotal results 23.73% Heodo
2018-07-12invoice-20180712-5727188.docdoc 854e0a13537eaeadb6b2be5d2569d2ad14bb47074231649befedc7ab4a8ee3eeVirustotal results 23.73% Heodo
2018-07-12INV-2018-07-12.docdoc e2515d4ccafe1a5f2dc2180dbd096ee3523de70d7fd38bc886ad09b0ac7a88cfVirustotal results 18.33% Heodo
2018-07-11inv-20180711-88677013.docdoc c02c8e4dc502303d14c993c97c7d74c95df30ccb605eb49f5444d9122a6d247cVirustotal results 22.41% Heodo
2018-07-11INV-0251790/5.docdoc 982d2695dd2e30560f71f668ffa2fc791604abd4ec45065603b68b77a8c03587Virustotal results 20.00% Heodo