URLhaus Database

You are currently viewing the URLhaus database entry for http://cityclosetstorage.com/sites/En/Purchase/Order-2036369891/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:34706
URL: http://cityclosetstorage.com/sites/En/Purchase/Order-2036369891/
URL Status:Offline
Host: cityclosetstorage.com
Date added:2018-07-20 03:43:00 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-07-20 03:48:35 UTC to csabuse{at}liquidweb[dot]com)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-21AEQ545621668_2018_07_21.docdoc 782036adcbf3b7c0e2a478c2e63fa6f5dd0dd76144eb01884c9d0746ba0f8be9Virustotal results 25.00% Heodo
2018-07-21OQ078561_2018_07_21.docdoc d20b4b001311a2793586581dfb2f7a58b46a92626c796fd53afdb9688c4f222bVirustotal results 32.20% Heodo
2018-07-21JQ96558_2018_07_21.docdoc 8449b8b0faadcfab22485004ccc56e221ddf48083c8569741996115ef56452f2Virustotal results 25.42% Heodo
2018-07-20IP6577664240_2018_07_20.docdoc dc7fcb0ed935375f14b7735e53a1f42d07e2db43c7d863071e6c31a8f735f418n/a Heodo
2018-07-20VUP450055501_2018_07_20.docdoc 78b28c11eff63b22c58f5fede556b626ad6124bf1d6f26e7e0c8ef8920a62cacn/a Heodo
2018-07-20MTD527708816_2018_07_20.docdoc 3b989a9a60b40ee5295f0d66bf9400fb75634c9cdc72325db17dc986321403aaVirustotal results 27.12% Heodo
2018-07-20TDA89388533153_2018_07_20.docdoc ee74e5a1a06c6fa34ba5d7bf16dc5193f78ad6d8b4e143fe97ec4e9edb90ec68Virustotal results 25.00% Heodo
2018-07-20SYZ91417_2018_07_20.docdoc f2fcda5fae0579434edabdf820a8b4cfd20cb42bd5ed85eed93aaf40b1779e1bVirustotal results 25.00% Heodo