URLhaus Database

You are currently viewing the URLhaus database entry for http://downinthecountry.com/PAY/ZFKW59545TQGHY/4173707/MP-VBHS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:39837
URL: http://downinthecountry.com/PAY/ZFKW59545TQGHY/4173707/MP-VBHS/
URL Status:Offline
Host: downinthecountry.com
Date added:2018-08-08 05:48:26 UTC
Last online:2018-09-17 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-08-08 05:57:06 UTC to abuse{at}turnkeyinternet[dot]net)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-08PAYMENT 83505APK.docdoc 69264f625af743b6e734581db044c5ebfb96652c0ff752985fe75b9b421f2e05Virustotal results 36.67% Heodo
2018-08-08WIRE 3552UPMAV.docdoc 7719ffce9acd3c3db888dc04273188fb87b1b3e5e1fafc65e8e47f61f56b254an/a Heodo
2018-08-08WIRE 6VZS Aug-08-2018.docdoc f548b38101a293d278ebdb65048018888719065ad3fd9f39681e5ce4a98e9ffdVirustotal results 36.07% Heodo
2018-08-08ACH 9BTK Aug-08-2018.docdoc ca90ee3ceb6b5f53c97e5621978522340940c65ff05b26248b391c4971d098a9Virustotal results 36.07% Heodo
2018-08-08ACH 127923NUX Aug-08-2018.docdoc 0140aa6cfbbc6676f2a53f5bb1758dca2b9463528b61b22779eef7a9187c9d54Virustotal results 32.79% Heodo
2018-08-08WIRE 086682IA Aug-08-2018.docdoc f53dd12de1dd67a2df6ca4e55c2d9b09793713252226d14f51fcc2bad785cc13n/a Heodo
2018-08-08PAY 272607OVWG Aug-08-2018.docdoc 318b72ee23afc45270ed759985852fc0b20be8bf9db5c1461fc19d12ad1f6cc5n/a Heodo
2018-08-08PAYMENT 99MV Aug-08-2018.docdoc 4608adb9fb21c032c61bb5856f69bf02259163d0eb4f2d8c9cf1764ac4b08d7en/a Heodo