URLhaus Database

You are currently viewing the URLhaus database entry for http://ingridkaslik.com/doc/US_us/Client/Invoice-04361 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:34881
URL: http://ingridkaslik.com/doc/US_us/Client/Invoice-04361
URL Status:Offline
Host: ingridkaslik.com
Date added:2018-07-21 08:10:33 UTC
Last online:2018-09-12 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-07-21 08:18:34 UTC to abuse{at}cldr[dot]eu)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-22GX7239923_2018_07_22.docdoc 9eb5ebf4950818df9294072543535ab5bf97a9af906b2c14909a7c79445250cfVirustotal results 32.79% Heodo
2018-07-22QJN5843966933_2018_07_22.docdoc 9997faff082088963c088eedcfe40c5490a43a26af763637a376fd7f18e0412fVirustotal results 40.00% Heodo
2018-07-22JF45908326964_2018_07_22.docdoc 40e9ab1442e4898fb42dd0bba0169296ae3df946183aa351ad32d2e658282e63n/a Heodo
2018-07-21SAT3646843175_2018_07_22.docdoc 67165d9b0b0017a2ce12791473747dfbd8c7c1d1c44b8433435aba27191c54ffVirustotal results 26.67% Heodo
2018-07-21ZV724005440_2018_07_22.docdoc c0477a0b70020f3ff6bacb0265a07081475e65044a933faeebcc3ba877c2ac86Virustotal results 31.67% Heodo
2018-07-21UG363394850_2018_07_22.docdoc 641a94c17cafa4fc2ed228a1a15cd3649c07078736a842f727d243c7e4b40c68Virustotal results 30.00% 
2018-07-21OLW84450432_2018_07_22.docdoc cdd3e74470aa580761be378c71dd16e5c6ca6b203de8afc446f7c9ff5b66ccbaVirustotal results 40.68% Heodo
2018-07-21ARX187002_2018_07_21.docdoc e602ef67f887d7406fb2fef027c03631a37b75df84eb5d380b74ec051a568754Virustotal results 27.12% Heodo
2018-07-21FXK11540_2018_07_21.docdoc 782036adcbf3b7c0e2a478c2e63fa6f5dd0dd76144eb01884c9d0746ba0f8be9Virustotal results 25.00% Heodo
2018-07-21MAT098004433272_2018_07_21.docdoc 6a3b7d3f133edc8cf0315305c2ee3619ac0d878fcbc314cd1349d71a340646eeVirustotal results 47.46% Heodo
2018-07-21XO70232347925_2018_07_21.docdoc 8449b8b0faadcfab22485004ccc56e221ddf48083c8569741996115ef56452f2Virustotal results 25.42% Heodo
2018-07-21MIV3310690543_2018_07_21.docdoc bbf87644e0ffcb36d8553e4ea33c33df9e6b48e3e92a452e969dc6a8feec8e32n/a Heodo
2018-07-21WRL856353132_2018_07_21.docdoc 02e8fa08eed92f4546cda6239ff0d52753864dfefd97795abb8ee8e3cd09ead3Virustotal results 31.58% Heodo
2018-07-21DRM732344611_2018_07_21.docdoc 05953e5d43777dbe3a973b4b310b5d57e909b09ca12470ef8b86bc2345a1cc62Virustotal results 31.03% Heodo
2018-07-21AG74412912349_2018_07_21.docdoc 25dc7d8c8e8880651752382dd3bd8bb32d363bbc5b4d75b8f8ca91105ff4d509Virustotal results 28.33% Heodo
2018-07-21HCY845597596076_2018_07_21.docdoc d91c31eb9a5705c5f02de259bf377d12608bc9f889e3fa3a59ae291f7f11a515Virustotal results 28.81% Heodo
2018-07-21SG2481235_2018_07_21.docdoc 6080a6c68c8ce3f9aec42f36cae49b4bb86d6cdfd871da118ac81bb176313539Virustotal results 26.23% Heodo
2018-07-21VZ03891875_2018_07_21.docdoc b3293eb381e85d8bbdb10d71f75324f0f71488d2fe05babbe7e3265814df15ceVirustotal results 27.59% Heodo