URLhaus Database

You are currently viewing the URLhaus database entry for http://ists.co.nz/AdqWIzWm5VJQ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:37570
URL: http://ists.co.nz/AdqWIzWm5VJQ
URL Status:Offline
Host: ists.co.nz
Date added:2018-08-01 07:08:24 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-08-01 07:20:11 UTC to abuse{at}umbrellar[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-02DHL number - Freitag, 14:00-18:00 Uhr.docdoc 7279cba001e4a2e4801207619deecb4428f97a6ea20155cdf150d28451b6245aVirustotal results 35.00% Heodo
2018-08-02DHL - Donnerstag, 12:00-18:00 Uhr.docdoc 2319a95b214b2e31da0df544385bc07f647fa2ebcd2c3207eb6d620f683bbeacVirustotal results 33.33% Heodo
2018-08-01Tracking - Donnerstag, 14:00-18:00 Uhr.docdoc b4674d7517fb56452ec55797fec4d54070d64ee12e300045361ee4bef0c7886aVirustotal results 34.43% Heodo
2018-08-01Tracking - Mittwoch, 12:00-17:00 Uhr.docdoc ad2b155c81a11b97e001138ae34af8aa3b3c9024c22c2d41980ef306bc4c2c27Virustotal results 31.67% Heodo
2018-08-01DHL Tracking - Mittwoch, 11:00-17:00 Uhr.docdoc 9542804050ef41c9dd2e7a99d467f368b294e996e91c9d67b6fd3936b878fb5dVirustotal results 29.51% Heodo
2018-08-01DHL - Mittwoch, 13:00-17:00 Uhr.docdoc 008a87bd055202a54ec27d4c5c58d976941f376613fc81f0ecea4ae07b4495f2Virustotal results 30.00% Heodo
2018-08-01DHL - Mittwoch, 11:00-18:00 Uhr.docdoc ce739e934059dbb9b627893094983cd6c6c8ba6ac433b9449154edf6fa922454Virustotal results 29.51% Heodo
2018-08-01DHL Express - Mittwoch, 11:00-19:00 Uhr.docdoc 6083231d07911aace3bd44aa0e6ff244da42bf5b844a68a241f1f801ce5cfac8Virustotal results 35.59% Heodo