URLhaus Database

You are currently viewing the URLhaus database entry for http://icreatewebsites.in/cgi-bin/cdf-dk-437/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415573
URL: http://icreatewebsites.in/cgi-bin/cdf-dk-437/
URL Status:Offline
Host: icreatewebsites.in
Date added:2020-07-20 22:22:39 UTC
Last online:2020-07-23 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-20 22:24:03 UTC to dcundiff{at}a2hosting[dot]com)
Takedown time:2 days, 2 hours, 10 minutes Poor (down since 2020-07-23 00:34:38 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22INVOICE-CZU77_45501971.docdoc 7ee1b548ad88bdfbae29e66d5a1e9fa8da71ab726c3baca04e3167bf544c87c3Virustotal results 47.54% Heodo
2020-07-22invoice-PSRC705_40835215.docdoc 26f3e277ea85db3dec692fde12c546a1d30d7a4e69ea6058d44afd3d5007af5fVirustotal results 47.46% 
2020-07-22INVOICE-KHW075_004664.docdoc 8f693cea85026bd7f34d4c5d2684885ec3c54c17bdf61287ee946216b42d6d5dVirustotal results 46.67% Heodo
2020-07-22Invoice U505_3680604.docdoc 9b8dc501b406401274f8cba9add694dbc728a2d170abfa181a86851ad8392beaVirustotal results 47.46% 
2020-07-22Inv 7_509851.docdoc 917e149c839d6cd0a4a68b4a9618a808b51b1edb3c526720c7939e845b81cc86Virustotal results 46.67% Heodo
2020-07-22invoice RFCQ6_7311362.docdoc 24304c4c69d49a1abbdaf4a07d9608111ae8486bd48eee061e6bb29f4943f543Virustotal results 45.00% 
2020-07-22invoice_O964_9002072.docdoc 4713ef31d9799b4d35e8444bfbc38699633d2b3faf9e3dbf730badcba5ee7e96Virustotal results 45.00% Heodo
2020-07-22Invoice-M9455_162573904.docdoc d1c90cc9ec1794107bee8f0ebeb6f3b8ee5e6b53f03c6cc5bc5e3abc4d8d9808Virustotal results 43.40% Heodo
2020-07-22Invoice_PD5_689930.docdoc 8aaea2227bcc24ea490c2eb6d0ab20fee60990d4c9e86fbf7b2b9d669d2c2629Virustotal results 45.00% Heodo
2020-07-22Inv-49_10565952.docdoc fc1debcb793c565585455c8097ba1c4bf4974b0397e75f35b01b560453c2905bVirustotal results 45.00% Heodo
2020-07-22Invoice-IJ860_19447179.docdoc 7539282f4f0c66d15a1f0a187603a10acc563a6c6377feefd7464f2152c00df4Virustotal results 45.00% 
2020-07-22INVOICE RPJX3678_689396557.docdoc 9973d428ca2bd355d338f94e5af2a40b617d1ae01abd66c2b6d4b314441ed30aVirustotal results 44.26% 
2020-07-22Invoice-S426_556833.docdoc 258f9d2af4d45fe37fcef78b658df80d39e1ab3c05690a9ebc5fdcf288a1aca4Virustotal results 45.00%Heodo
2020-07-22Inv-XKGI0_102507616.docdoc aac371031d0d22362aa3a7828807e86eae8dceaabc379008b463c3557bb42832Virustotal results 43.33% Heodo
2020-07-22Inv-RY026_225443.docdoc d822481ba99034d0c590309b06c5da4f82a5130baef12467350c5eff0a0e89dfVirustotal results 40.00% 
2020-07-22Invoice-Z6_458373688.docdoc 9f61c634155e4c4c25cda79ab4da536afe7bfeeb879754985ea6bb196ee0272dVirustotal results 38.33% Heodo
2020-07-22INVOICE NFVR67_249600.docdoc 45ae92bcea06bc3e5c6dd6873e5191cb56af6ad91edab7a11fc87e0a62ccd4d2Virustotal results 37.29% 
2020-07-22Invoice-G7281_3587012.docdoc ff44b1d144fb3343d7d7580652077fadeb72bcac55733df8fad986203c3e15a4Virustotal results 35.00% 
2020-07-22invoice-X6392_1343215.docdoc 8bf0f63918707260860836fd1bae7c3366cd110c8a1299c064475020d837311bVirustotal results 35.00% 
2020-07-22invoice 4_951078979.docdoc 4362e6ba330f2fd89b96c0a2bd7407ca83f5c6678f765731244788aa490160cdVirustotal results 32.79% 
2020-07-22Inv_AND419_388914575.docdoc 595c40c85c80044dbfd9608613744dd68bcc0b2fbbf8517599d0c78eee6ad99eVirustotal results 30.36% 
2020-07-22Invoice-07_87978189.docdoc 02c7fd8ed2ff395eb8c7eb3caca1e0cec299f4db7480e6d19829069ce541bc7dVirustotal results 27.42%ZLoader
2020-07-22invoice-D3131_2955705.docdoc 0f2039a528f454dc85d45347c05e3deeed35f371d829ed160143b2cda326accbVirustotal results 26.67% ZLoader
2020-07-22invoice-JWNO632_302268997.docdoc 639bdf650ed2329ccbe33f471cc8e6e8e24bc3a1147d446ff0ce5ea0e28ae9ebVirustotal results 28.33% 
2020-07-22INVOICE EEP46_3351271.docdoc 982b974a8a615a1e12c407d581f14151a8e9ba50cff41bd400e8be525e66b506Virustotal results 26.67% 
2020-07-22INVOICE-F60_132645.docdoc 4a77f876b6d9a044b69944ac284abd8838dfac4208cdefc8de51907727421d46Virustotal results 25.81% ZLoader
2020-07-22INVOICE-DFDW52_447692.docdoc e7af4a6f667a4edbd224f0b3c1358fcc307b4f67688529201e0c1c9a91560f64n/a ZLoader
2020-07-22Inv_EVC4372_182698.docdoc ebec7284e20fdc5a633b8f505fd018ebfdb512a595eaf179e5d77b60d33970b8n/a 
2020-07-22Invoice_RLGB1367_144176.docdoc 6475e70afc346103957694beb826b2eefdb2850c9939c91d6b514ce9e1cd32a4Virustotal results 26.23% Heodo
2020-07-22INVOICE-9_303274127.docdoc 2a1b48f3aaada9451e14e735699dc6910a2df66a18b4f4497c7f4f6f159c8296Virustotal results 26.67% ZLoader
2020-07-22Inv-ZUAG2704_7614717.docdoc 85f96e5cf282786ef803c7c7886284d3225a9daeecc04ce3b8e5bbd143a3e0abVirustotal results 25.81% 
2020-07-22invoice-U230_7594904.docdoc 7476dba24b28d2a074d7e75aea79591f98fbb95b065c91870b5a8198ab615f19Virustotal results 26.23% 
2020-07-22Invoice VAP1328_717422956.docdoc 8cafecab78eb955d85ec99123092085c12c6f94ab003097360fd6bb694cec236Virustotal results 27.12% Heodo
2020-07-21INVOICE-BU451_382295603.docdoc 43025670822df6a6ae1ba1f56baae65c0d563c0c12410244aeb8fb166be9f737Virustotal results 26.23% ZLoader
2020-07-21Inv W057_876571.docdoc 3652eb3092729d00e19aef9cc79250a566fd59c1bbce7a173c742dc9c75f920cVirustotal results 26.23% 
2020-07-21INVOICE-6_254084324.docdoc bdebdf81b9c2645e41964a4d14720c68258ea89382b1cee103369b6fb9a77103Virustotal results 26.23% ZLoader
2020-07-21Invoice B7145_7441829.docdoc 88b555290b53e0369600411c472821ad9907eb147dc87e60164918aa85adc3c3Virustotal results 27.12% 
2020-07-21Inv-8577_601330.docdoc 9e2fa2ec0c3818292f9a10539ef4bdcda848df84a8e0223cae2f28f82360a11fVirustotal results 25.81% ZLoader
2020-07-21Invoice-92_215193.docdoc 747095882ee4fedcb2d7306fbda6bcc5b792e877d427b855d80a0fdf5db073a2n/a ZLoader
2020-07-21INVOICE_J4_080056.docdoc 2bf992bac6895328fca415aeeee4f89aff347608e709524ad9a2f549b007dae3Virustotal results 26.23% ZLoader
2020-07-21invoice RBZ294_485578312.docdoc 72a76d3c5a30ccf7584528d7bd29ac47062d468d56a417063c19573496089d56Virustotal results 25.86% ZLoader
2020-07-21Inv-QQNE7935_41419562.docdoc 97af910f93ee8e736e135660fd84b888bdcc82c809ef30af7cac06da62907994Virustotal results 26.23% ZLoader
2020-07-21Inv-H92_524432222.docdoc 3363f1375d1705778c34f83818742724c75fa3c3b13bc2fc131fd95b2d03c8c8Virustotal results 25.81% 
2020-07-21Inv 4_88650157.docdoc 69f98944d3760e294ea601defa72bf8b0ac0c8105267a560426f3c2f3888aff3Virustotal results 24.59%ZLoader
2020-07-21INVOICE-XQYM0766_566863608.docdoc d00a595a3e71c743fc04ec4a2ba0eaab9fe1d76d7b018423fc5cece4e4a62a29Virustotal results 31.15% Heodo
2020-07-21invoice_I39_4093967.docdoc 9bd09fd88355a1b20c3268d29be2308057a659c4b96c85a618409ec4b57bd45fVirustotal results 31.67% 
2020-07-21INVOICE-MEMS578_1086312.docdoc a96e572969f83e205956bc1076df5193a717705c9123bd19bae210f34502c309Virustotal results 31.15% 
2020-07-21INVOICE-RPOO7_963056996.docdoc 33c53ca7807a817b61ed5b3a0a7e0ffe44059f5aac7475b14df784384aba5308Virustotal results 29.03% Heodo
2020-07-21Invoice UNX9142_244938366.docdoc 5dd07737bc4bcd586aa9a89cdc86f5222873447eaaf558d404f31e3fb459f437Virustotal results 30.65% Heodo
2020-07-21Invoice-JK156_3468995.docdoc 4de9b5d8be922ee6f95a85aa378d4b78596a0df19e25a0388096ba0831feebb4Virustotal results 29.03% Heodo
2020-07-21Inv 5378_083060.docdoc bdf6b8a3ab43c2e8091f591a913040c789e38a80e2f57d9dde2c5f0cdd9d7fe6n/a Heodo
2020-07-21invoice-NCMO027_421223.docdoc a15083f68d55c92228c997e26d8596bb25b5cf8129f45e98d3c78ded130081f9Virustotal results 27.87% Heodo
2020-07-21Inv XUV67_13408705.docdoc be14def968a7a7ba9caaac07b0784bf90fcc93c6917657fa2aae18ebc3813563Virustotal results 28.33%Heodo
2020-07-21Invoice LBYJ245_07921763.docdoc 05b1f0822783aa9419a3b13424fb6d31e224e8dad2c84ace8cafa7c1b42a1f3eVirustotal results 28.33% Heodo
2020-07-21Inv-L45_5931773.docdoc 0392ead1e27d50c2ef2f5e29a23c1dedb44cb59a82a87bb8380920056eaab899Virustotal results 28.33% 
2020-07-21invoice-KX3_583199776.docdoc 75c9115e924a7b2ea6b2565e7d48407cbcdf06ffd452bcb6834bb821185b2272Virustotal results 26.23% Heodo
2020-07-21invoice-PPGF256_776072751.docdoc 692c3606f5b32a2200f1ec78d8764604def5e99ca282474046d78500e09fb91aVirustotal results 26.23% 
2020-07-21INVOICE-DKT9272_940301806.docdoc bcc004820abd0f210285b3aa58c625f0a00187f4f545313a553b4a40ec68b6baVirustotal results 26.67% 
2020-07-21INVOICE 379_882716543.docdoc 8f32874205c29ff499e75943e0f6c9b298417cca9166bee485e13f791d6cc4c3Virustotal results 26.67%Heodo
2020-07-21Invoice-J847_4427044.docdoc f46d92d4440678792e72b414df3ccbe066766a4b486ea3c25c767d8c297335b0Virustotal results 26.67% Heodo
2020-07-21Invoice_CLF62_7804486.docdoc c809bea4eab861ed271e8d1688b261c33747782ac6756d644edf6889ba745c88Virustotal results 28.33% 
2020-07-21INVOICE-UVR529_028096.docdoc aa31041b4dcd03e3ad1818d6ca5ac597b999aa6725212a9dfecec97c68100a27Virustotal results 26.67% 
2020-07-21INVOICE-FE217_80798674.docdoc 969b9fcc13e520a48a60d7e65714c495c99ac1a90075aef31a7486070b8bb171Virustotal results 26.23% Heodo
2020-07-21Invoice-9412_9467039.docdoc 6a474d19ec3d28962de1668764ca03da5b762d1d6a949bdf78910db1a1bd1bc9Virustotal results 25.00% Heodo
2020-07-21Invoice ILQC42_3549410.docdoc 2c45f3ecfe38e8675ea0ae2db824e82e654e82aaac7dcb957df5b0b95034730fn/a Heodo
2020-07-21Inv-VFLO620_12693289.docdoc f37d602c2d14ef7dade7cd13740d744939c846704065c8d20367a677ce0ad095Virustotal results 22.95% 
2020-07-20invoice-3869_07823607.docdoc 3c0e8951e374e27090d6efc7467ef799707435854555513cfaa11fafc14799bdVirustotal results 27.42% 
2020-07-20invoice 119_741431.docdoc 06dcac5c1abbea3cbaf474c29241fc5a22ba1b118295444fb13112d459ac7031Virustotal results 27.42% 
2020-07-20invoice EME17_0167306.docdoc 94138f0acca7af8063b8a4feed6e2c6ef4ea4096d6a5d743af80adaf9774afdfVirustotal results 27.87% Heodo
2020-07-20Invoice-UX61_5879696.docdoc 322485b1de923041bba661e8e8fc440c6a747a2634cf9890d75920bdce1fa27aVirustotal results 25.81% Heodo