URLhaus Database

You are currently viewing the URLhaus database entry for http://foffi.com/pdf/US/OVERDUE-ACCOUNT/Pay-Invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:37284
URL: http://foffi.com/pdf/US/OVERDUE-ACCOUNT/Pay-Invoice/
URL Status:Offline
Host: foffi.com
Date added:2018-07-31 19:15:59 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-07-31 19:27:27 UTC to abuse{at}athenixinc[dot]com,slindsey75_athenix{at}endurance[dot]com)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-01New Address and payment details.docdoc de444f72983e6cd06bfadcc7d132ddc5b0596dc7f96b465f2adb2742e9e61ac1Virustotal results 29.51% Heodo
2018-08-01Recent money transfer details.docdoc f313b259e60be8bd8977157adc404dbd66d2a98d1e2f523bb20a75213b0246c1Virustotal results 29.51% Heodo
2018-08-01My current address update.docdoc ce739e934059dbb9b627893094983cd6c6c8ba6ac433b9449154edf6fa922454Virustotal results 29.51% Heodo
2018-08-01Money transfer details.docdoc 81f1a5faaa792952e49c477f54c75beec7fd03d3a1c250db2b863ec2b669beeeVirustotal results 28.81% Heodo
2018-08-01Money transfer details.docdoc 6058d051958f4714dedd6557174103572f67b5836a4d5cd2c62ddb96e6337b28n/a Heodo
2018-08-01Details to update.docdoc 9551a0941f52e4f6b23c3451cc266e24e206fc74bc44f10c7b4bb41ad9ea0f9fn/a Heodo
2018-08-01Recent money transfer details.docdoc 6083231d07911aace3bd44aa0e6ff244da42bf5b844a68a241f1f801ce5cfac8Virustotal results 28.33% Heodo
2018-08-01Latest payment.docdoc 617bcd198922ae1b6385e5169d00357353f85cb020f6a42d6c6ad76e21d350f1Virustotal results 26.67% Heodo
2018-08-01Due balance paid.docdoc 4c724126ba4cec6b0c95367e9abca9ab89c60f721869313a428523bfacfc5068Virustotal results 23.33% Heodo
2018-07-31Payment details.docdoc 019c9283d85b63dd3f52ed9c23225d33815b661a80c10cf5a6edbbf98b70e0fbVirustotal results 29.51% Heodo
2018-07-31New Address and payment details.docdoc 7ab7134daa5c94ddec1ec844a5535db1377227d3694e408651c4844e146cfbf6Virustotal results 24.59% Heodo
2018-07-31Latest invoice with a new address to update.docdoc 48ded544503330697c352aff9f0867b17fa6942a8fd92282f9dea76fa72ed386Virustotal results 32.20% Heodo
2018-07-31Address and payment info.docdoc bda4aac71f0450be9f896ed430314e48789ce8d915c7f9ae723322d257f1a09cVirustotal results 32.79% Heodo
2018-07-31Address Update.docdoc dd14acd0768deedb4ead69e01b291572db73442d5fd388b915d71bcb5749c1f7Virustotal results 30.00% Heodo