URLhaus Database

You are currently viewing the URLhaus database entry for http://dimakesra.com/mywo6y/ACFuEfSe/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:416218
URL: http://dimakesra.com/mywo6y/ACFuEfSe/
URL Status:Offline
Host: dimakesra.com
Date added:2020-07-21 18:57:24 UTC
Last online:2020-07-28 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-21 18:58:20 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)
Takedown time:7 days, 1 hours, 31 minutes Bad (down since 2020-07-28 20:29:26 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22INVOICE-SSFH604_3435745.docdoc 02c7fd8ed2ff395eb8c7eb3caca1e0cec299f4db7480e6d19829069ce541bc7dVirustotal results 27.42%ZLoader
2020-07-22Invoice-AA26_12787004.docdoc 17848a980123cfbb8869e7859b37b1f0e06e992a2ad751fde0a355d4eb377920Virustotal results 29.51% ZLoader
2020-07-22Inv-MCQ6781_53486334.docdoc 639bdf650ed2329ccbe33f471cc8e6e8e24bc3a1147d446ff0ce5ea0e28ae9ebVirustotal results 28.33% 
2020-07-22invoice-4411_607532.docdoc 57bbc36f8aa8cb407d0c50ca951d626555bce1bece1b524d00d0b0d5aa3257fbn/a ZLoader
2020-07-22INVOICE_69_3315047.docdoc e7edf63be003d87056435fd147d04f6930e07f08dc6534bdfdb3913f4cbbd59cn/a ZLoader
2020-07-22Inv-IJWO3496_7198808.docdoc 4a77f876b6d9a044b69944ac284abd8838dfac4208cdefc8de51907727421d46n/a ZLoader
2020-07-22INVOICE P7973_974781253.docdoc 64904286f139771314584f5ebf505208623b941f9fbc7c36e5039edcf595d9e8n/a 
2020-07-22invoice_SNP62_6319516.docdoc 59ea049ff3ab24d93029a5395073975931ffb768537ca09e45fa6bf34af34accVirustotal results 26.67% 
2020-07-22Inv-IV052_288825576.docdoc 40b8fbc9e4135de9d65f33366f01bddb05cfca61799ce403b30c092fcb421725Virustotal results 26.67% 
2020-07-22Invoice-IBL9615_373216.docdoc 6475e70afc346103957694beb826b2eefdb2850c9939c91d6b514ce9e1cd32a4n/a Heodo
2020-07-22INVOICE-WX1_93311140.docdoc 85f96e5cf282786ef803c7c7886284d3225a9daeecc04ce3b8e5bbd143a3e0abVirustotal results 25.81% 
2020-07-22Invoice CBCP7245_506026967.docdoc 7476dba24b28d2a074d7e75aea79591f98fbb95b065c91870b5a8198ab615f19Virustotal results 26.23% 
2020-07-22Inv_0_91739453.docdoc ee7974d011582b83c0464f15d86e55b3306961023b16ed3c195c6c1953ea5835n/aZLoader
2020-07-21Invoice-402_199758909.docdoc d1fe2bcc5439caf2963c2bcf85af9c8b8d4451abbc4675be82a33bf97ca81f18n/aHeodo
2020-07-21Invoice 52_8829293.docdoc 599ef65639238b841a852f756d71b9d44c5e02b6d151b6941b95c94b5e8eaf64n/a ZLoader
2020-07-21invoice D4_558922599.docdoc 112aa4be04d85780875343365b40f2fe9351e69dd4756d26a01f923251e17a49Virustotal results 25.81% 
2020-07-21Invoice 8346_6188485.docdoc bdebdf81b9c2645e41964a4d14720c68258ea89382b1cee103369b6fb9a77103Virustotal results 26.23% ZLoader
2020-07-21INVOICE_R12_666815859.docdoc d9238e5af649fe7ea0572f9699144985895a4c4576ebb77e0e198ea5120f4c20n/a 
2020-07-21invoice_GV980_887578.docdoc 9c3f1dbdddf1aea861852243a66b3795d0cbf86a1ee36fb372505a839db31540Virustotal results 26.23% ZLoader
2020-07-21INVOICE-8021_92243996.docdoc 3bebcaf546b7a6b80b7d94610fb02a2577fdd1331ef3ed8f118677d029e2132dVirustotal results 26.23% 
2020-07-21invoice-NUM95_537410374.docdoc b4e3c557317004de4b83d941a7dbd81648b8383245a1b95806b736eda61b53baVirustotal results 25.81% ZLoader
2020-07-21INVOICE 5172_341811.docdoc 9f9d6e57c9e3398ca955952e4fcf58321a7f235e18eaafe6aab3b3ddd4e88c7cn/a ZLoader
2020-07-21INVOICE-WQDG0_8656358.docdoc 72a76d3c5a30ccf7584528d7bd29ac47062d468d56a417063c19573496089d56Virustotal results 25.86% ZLoader
2020-07-21Inv-PQEE318_6225715.docdoc 5a8f4a7b9da36a38084e054525e4d5d471070b15f958a1118eaea6f7be429767n/a ZLoader
2020-07-21INVOICE-OAP054_429803.docdoc eac069c2098e2a08afb43c1f5aae5878d557e5cef94096cefa93bbe0d04c236bn/a 
2020-07-21Invoice_WVZR998_371321.docdoc 837bbc0f0c83b6a6837640d6ecda9c348ffd06a81fa4b87c7ebfc7df59b1a690Virustotal results 26.23% ZLoader
2020-07-21INVOICE_S65_495480397.docdoc fcb7d57d53fe5854649e2b62386272c124701478061110c83cb947a4fc0dd3c4Virustotal results 30.65% Heodo
2020-07-21INVOICE_S65_495480397.docdoc fcb7d57d53fe5854649e2b62386272c124701478061110c83cb947a4fc0dd3c4Virustotal results 30.65% Heodo
2020-07-21invoice_Y576_08701926.docdoc d00a595a3e71c743fc04ec4a2ba0eaab9fe1d76d7b018423fc5cece4e4a62a29n/a Heodo
2020-07-21Invoice-J828_706040.docdoc a96e572969f83e205956bc1076df5193a717705c9123bd19bae210f34502c309Virustotal results 31.15% 
2020-07-21Inv_NJT5877_99215199.docdoc 9ed17331261676ac56f81432fd0de1293bdc48863867eac50012dff696d69439Virustotal results 29.51% Heodo