URLhaus Database

You are currently viewing the URLhaus database entry for http://h-h-h.jp/wpp-app/DHL-number/En_us/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:36235
URL: http://h-h-h.jp/wpp-app/DHL-number/En_us/
URL Status:Offline
Host: h-h-h.jp
Date added:2018-07-26 13:07:22 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: ps66uk
Abuse complaint sent (?): Yes (2018-07-26 13:16:10 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-28DHL_2099854394.docdoc fcd3595dbf1229557ec9293a5c59c75cb4db527adc01693ab76644ee5cd7a44en/a Heodo
2018-07-28DHL_1939917257777.docdoc 057fcc05bfcbb356e8d4b5f23a6e1379079d77126d16400b8e2b3d2b5fc7175bn/a Heodo
2018-07-28DHL_Tracking_68175627988.docdoc 86f50c0f63c30225de5087972911d7eb13abeb2e082c7a9d84d62e12d36e18b9Virustotal results 33.33% Heodo
2018-07-28Tracking_096152955.docdoc fce6b65a809e6225e81ea09395187d766fcdc70c7285705295876bdade6d7725Virustotal results 30.00% Heodo
2018-07-28DHL_Express_85326574610822.docdoc 7d93925a3e1d53422ad39d96d6d8f3dda153432e77bdec61627294ccda81b3b6Virustotal results 32.20% Heodo
2018-07-28DHL_number_9285499076757.docdoc ea2bba38fa75338ef70e6eac08c55b12a0fe0407119514fa40955874a389ede7Virustotal results 31.67% Heodo
2018-07-28DHL_Tracking_58938220582511.docdoc 616d104acfd8bdb44d94a3636d058fa71c2e7c3d88b01ff4d207174636685f60Virustotal results 28.81% Heodo
2018-07-28DHL_Express_54152808490.docdoc 278037738145e80fa8d34d61fd3959b204da75ef3d63e56ed25e77e427a87533Virustotal results 26.67% Heodo
2018-07-28DHL_Express_572070681964.docdoc a1fbf1ea5dc832d6061073633e6309594f64cc58e87aa984f804d3a9701ab7f1Virustotal results 27.12% Heodo
2018-07-28Tracking_641071989502240.docdoc 6dce7c91395b80f9a57accf9207dcad66acad879fd7c87b24e556e230bef0eebVirustotal results 33.33% Heodo
2018-07-27DHL_number_888937203.docdoc 70a443507a066a00a017d8d8a589e3dc2c445f0c2b423dcbb33907d282abdbdcn/a Heodo
2018-07-27DHL_Express_26400989164340.docdoc ea5230d20a3ca83e35f494d9310551761a3c7052e10e353e017b69fcc8373928n/a Heodo
2018-07-27DHL_Tracking_5815377897103.docdoc 00fd8c30c2b05d4d7e4d910d881e8b7c6694478abda7eb3c4ba5917c8fd6e437Virustotal results 30.51% Heodo
2018-07-27DHL_Tracking_2123748.docdoc c5e72c01e9af1c8bdc1ac8196fd9d7264c3412d457ed5a3a940b19f031e50893n/a Heodo
2018-07-27DHL_219981524.docdoc 2b5ed4982597305d1c384a9863583bf5c84fd1cdd0b12fae4213adc66d50486bn/a Heodo
2018-07-27Tracking_4743134874889.docdoc f6f57dfd2a6ff59a9f8f34c8bcc6058ee58ff13bfdfa0152a91fc31b05cff68dVirustotal results 29.31% Heodo
2018-07-27DHL_Express_953602879832.docdoc ec38d89afa887d9880e7097a5c73479df06dd06402e6fbb17d637c9e94349f1bVirustotal results 27.12% Heodo
2018-07-27DHL_number_31276512060523.docdoc 50a1ce2d382bee5324259bc0f42ff454e04ae98e832ce122a110cf30fb93b209Virustotal results 32.20% Heodo
2018-07-27DHL_36969376881630.docdoc 8659f2f01f2f4addb9bcbd6f1feb58f7d0bcc511ba0188db05bba2173640d5can/a Heodo
2018-07-27DHL_Express_290845154472.docdoc c48bad5ccee9eca0d86313fb25c39913d55d6ec1000d66b98758365a999778ebVirustotal results 27.12% Heodo
2018-07-27DHL_337310843.docdoc 11e0b81e04e28b9749a6a8d0df35e4d5fc11528be5a54802958b1e3d8e954ab6Virustotal results 29.82% Heodo
2018-07-27DHL_number_63224756793.docdoc 351df39fa91ac1b92688ed7c52efce7541ec78cd5f070545d170927b6bee51a1Virustotal results 28.33% Heodo
2018-07-27DHL_number_659793305.docdoc cde212a61556b35461627f054f56be277c3a5203bddbcbe526742b4b849a5bb0Virustotal results 42.11% Heodo
2018-07-27DHL_Express_0175653697125.docdoc 06f3528100cd5d4ddc7f06d35d26918e30f723755e342f583d8bf5f791e8a21en/a Heodo
2018-07-27DHL_Tracking_751873939927.docdoc bbd808b9ae468f0fd7611ed28d9c32ff61116a64095ab2da02877b44b59966e3n/a Heodo
2018-07-27DHL_8007642.docdoc 6e99fd801a91014662c3606af72e677b21ef291a487861c576c1d19955699da7n/a Heodo
2018-07-27DHL_Express_3529915389731.docdoc 91ec3d555e8cd980bbc636147b9bacf94ce6e2ed736cf879e2d7d30693f182can/a Heodo
2018-07-27Tracking_2879625914.docdoc 183bcaf3b2bff3b5b01952769ff713036ba5ecdb34f579c7c8bcadb3ec4673d0Virustotal results 36.67% Heodo
2018-07-27DHL_Tracking_335264856.docdoc a04e6195e8b52db47e7e88401a4daa431ccdb00c959c3ecc2b26743ba47e97c6Virustotal results 38.60% Heodo
2018-07-26DHL_Express_44159625252.docdoc da949e88f8e20caff806d1c8201777571991a2701bdc2f3e44815d0e18ab948cVirustotal results 36.67% Heodo
2018-07-26DHL_Tracking_2917691.docdoc a8e856a69c9eb0074a418c67d575b91b49caea488574529a40e3b129cefde689Virustotal results 40.00% Heodo
2018-07-26Tracking_384203441.docdoc 8f0dae9f191c55289ab80783e68c0e03e97f391cd86ae283304555f20d8f2d31n/a Heodo
2018-07-26Tracking_0526492442656.docdoc 11f7710f8cabe988168078cd6ba83c2544d1d06c9a8a3583fabe164e87f7048bVirustotal results 39.66% Heodo
2018-07-26DHL_Tracking_42624608263441.docdoc 73d4c1dafc168a36218d215548bdcc87b0ecb667acaf685b044b680f4f678dcaVirustotal results 35.59% Heodo
2018-07-26DHL_Tracking_530115200.docdoc c77196231630b535ef5f0d46f78b7be22a27954daf395065b8f448829bcbbdffVirustotal results 35.59% Heodo
2018-07-26DHL_Express_62676880.docdoc a5fefbfa27d4704a6e5e9ee658587a63e1889d2baa74bdf7c6949a4027e2bf51Virustotal results 30.00% Heodo
2018-07-26DHL_Tracking_74027333207929.docdoc ae9906780f635486c8ad44c8e72767bcd2bbd5b5dc8c4ae021239584e9c4ffa5n/a Heodo
2018-07-26DHL_Tracking_831871389.docdoc f31b10a0262b339800fe10d224f275639679abd58a0114c643fef822c60a14ecVirustotal results 28.33% Heodo
2018-07-26DHL_Express_32684883.docdoc cae201c0186ce7a7772512776f9cc768861fd18c7ac96d1c65cbe72304e86b57Virustotal results 30.51% Heodo