URLhaus Database

You are currently viewing the URLhaus database entry for http://ists.co.nz/AdqWIzWm5VJQ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:37694
URL: http://ists.co.nz/AdqWIzWm5VJQ/
URL Status:Offline
Host: ists.co.nz
Date added:2018-08-01 16:11:58 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-08-01 16:25:23 UTC to abuse{at}umbrellar[dot]com)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-02DHL number - Freitag, 14:00-18:00 Uhr.docdoc 7279cba001e4a2e4801207619deecb4428f97a6ea20155cdf150d28451b6245aVirustotal results 35.00% Heodo
2018-08-01DHL - Donnerstag, 12:00-18:00 Uhr.docdoc 2319a95b214b2e31da0df544385bc07f647fa2ebcd2c3207eb6d620f683bbeacn/a Heodo
2018-08-01Tracking - Mittwoch, 12:00-17:00 Uhr.docdoc ad2b155c81a11b97e001138ae34af8aa3b3c9024c22c2d41980ef306bc4c2c27Virustotal results 31.67% Heodo
2018-08-01DHL Tracking - Mittwoch, 15:00-18:00 Uhr.docdoc ddfa667a6805bf8b9216feb8df15b1590c340914d7142aa142ecb858d117ba9bn/aHeodo