URLhaus Database

You are currently viewing the URLhaus database entry for http://detss.com/doc/US/Open-invoices/Invoice-07-25-18/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:36023
URL: http://detss.com/doc/US/Open-invoices/Invoice-07-25-18/
URL Status:Offline
Host: detss.com
Date added:2018-07-26 03:53:49 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-07-26 04:10:43 UTC to abuse{at}a2hosting[dot]com)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-30ETM6115455685685.docdoc c497cff4385c5816d1b3fc3fe535695f020060037392e0eb5ba295e8fa5d0b10Virustotal results 61.67% 
2018-07-27HS9988579503995.docdoc e556e5a424c04ffd17082f6e257dfb7ea558fbc4d24b8ae0704b9f5e51a3fcc0n/a Heodo
2018-07-26DON232506091218256.docdoc da949e88f8e20caff806d1c8201777571991a2701bdc2f3e44815d0e18ab948cVirustotal results 36.67% Heodo
2018-07-26NS984202838787.docdoc a8e856a69c9eb0074a418c67d575b91b49caea488574529a40e3b129cefde689Virustotal results 40.00% Heodo
2018-07-26OFI630707112742980.docdoc 775b96aa12728bfc5f6f68bf11d8ff34e252107d8f63440a471495e8ecd9f1f7n/a Heodo
2018-07-26WEA69330015517.docdoc ffc7944f16c06efdd23a4fb946eac1dd2b1a91f2d27b7cf24396a78713b17c5aVirustotal results 38.33% Heodo
2018-07-26(INV)WDD729194814.docdoc 400d6b89b8026f39de9c80b89aae66e49afebf153c8b5b9d480307ada0f4c428n/a Heodo
2018-07-26(INV)RC5818972278.docdoc 7ca6572429e9aeeedaeb810c5752f1ee4f300435eedb55efc6128a3c5cb40028n/a Heodo
2018-07-26(INV)QD8986627457.docdoc efd3a89995ffc2b3e9eb98777e41e2c41a9e88c3da8515fc085b8a14780071f3n/a Heodo
2018-07-26(INV)KMG160471544.docdoc b9ffd75bae3926e7f366f16e1b4f1d72adcbbb1e9cfbf19f9e217d9596db242an/a Heodo
2018-07-26DW680331769839503.docdoc eb6e7d17c007d64f9fb1ed96d50967a0ab3fceb1c53f39975aec92bd8d499632Virustotal results 30.00% Heodo
2018-07-26PE032329191973.docdoc cae201c0186ce7a7772512776f9cc768861fd18c7ac96d1c65cbe72304e86b57Virustotal results 30.51% Heodo
2018-07-26DXI73613650778716.docdoc 35a9ae4267c3e5ba26d82dcbea82605364d5c110779cc67d34616b9c1dc07452n/a Heodo
2018-07-26SNQ7739569140.docdoc 5728aa05ef3551aa19530c31280bb3ea3c1e3a5002a0d7ff73c0defedf6d5f13n/a Heodo
2018-07-26YN232522899.docdoc 056a4134212e57a50932041c6294b4b2ede287d700a2a0512136eacc155e64b5Virustotal results 31.03% Heodo