URLhaus Database

You are currently viewing the URLhaus database entry for http://avto-baki.ru/doc/En_us/Aug2018/Pay-Invoice which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:41750
URL: http://avto-baki.ru/doc/En_us/Aug2018/Pay-Invoice
URL Status:Offline
Host: avto-baki.ru
Date added:2018-08-13 17:41:15 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-08-13 17:46:29 UTC to abuse{at}best-hoster[dot]ru)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-10n/aunknown 548da4093681d819d1ce0600b7c6a3f0884f8d6151c700374ee162b49d9a420cVirustotal results 0.00% 
2018-08-15Invoice.docdoc f289c4d0a88e71a307c1b5bc1dbcae5a8710ec1848e1aa6f4e3691b92290fda0Virustotal results 29.31% Heodo
2018-08-15Invoice # 62A43887.docdoc 8c4ce35dda3d110f5e6e6bac50cfbb34751f5db03188170d1680144fcca1267cVirustotal results 31.67% Heodo
2018-08-15Customer No 5485083.docdoc 74198a4c0c4fbdc5bbac55bd0ce5b08a71c2c3188d1825cfbd08e67cb292cb05Virustotal results 31.03% Heodo
2018-08-15Accounts - Invoice.docdoc 1bc8843b448337bb7b472a5419b0581278435d2de3d7899b6584314350fb689en/a Heodo
2018-08-15Invoice Query.docdoc 72a9605fb3bb77cde5b3fb2d1355df6707e0fb3c7fe4d0ee20e561354234d15bVirustotal results 37.93% Heodo
2018-08-15Invoice Confirmation D07600.docdoc b3780348a997bf9644df511fc09819640396ae7b5934775a7dae92d1453b9f74n/a Heodo
2018-08-15Inv. no. 441241441.docdoc 23d5a27e14c1441567e38b6a14485082e88f56133f18d60a4d42e5ce9a60d743n/a Heodo
2018-08-15Review invoice required.docdoc c12e3138da25045d878e6c577cba65ed3b25e0100035fc9fcb2992da77ab8531Virustotal results 33.33% Heodo
2018-08-15Final notice.docdoc db0486e7fe13763954972e8b29e104d2b9b6f7070f4638d828b707a63c1ecf2bVirustotal results 35.00% Heodo
2018-08-15Invoice as at 15/08/2018.docdoc 78c8459629d6d186b8e344e1361540ea66dca3285057643cbfb8fe77a3440fbdVirustotal results 33.33% Heodo
2018-08-15Invoice Query.docdoc c9f4fdf390dfac51bd78635013c2129bf6edc1e81624a763dee822fb6ce92352n/a Heodo
2018-08-14Invoice as at 15/08/2018.docdoc 56da85225d571569da00e536b11453df3932984b2181103626ac3e238a79b31fVirustotal results 30.51% Heodo
2018-08-14Invoice.docdoc 5c6d9f00e6fcf35631b4b45573b5ef3523be605ddb1d3e34213838821686ff2dVirustotal results 26.67% Heodo
2018-08-14Invoice Confirmation 2C908889.docdoc 8530a37beafe6af4a5d606b34260d4a8a252c2b9b1129f858e45f84616dc0cf0Virustotal results 27.59% Heodo
2018-08-14Customer No 474207.docdoc c0a21837d92775f462c85dc71d1daf8220d6fb2006c4cc5cf18d21da2129bc36n/a Heodo
2018-08-14Latest invoice - 621313.docdoc 75c75abfb68fa9ad3ba70008aa74974e0125be70764678d86e51f1ca37d0d918n/a Heodo
2018-08-14Invoice.docdoc c12767f2f10800410a09fc779ad9ff4f2ea3ff27b52fcac37bcb4aa3df95b292Virustotal results 28.81% Heodo
2018-08-14Month notice.docdoc 200f9ce2b352f4cadc07b595bfd5687cd67a942892ea333eec4cf3fe2636874bVirustotal results 26.92% Heodo
2018-08-14Invoice Query.docdoc 52c2d15e600bf4ad4c7254e7e7b06537ef44894fc07a3691491ebd4aba97c450n/a Heodo
2018-08-14Invoice as at 14/08/2018.docdoc a23c7eef482794cc3bdada733cc9634ea6e0feb34b7e8671fd67dbfd9499f4dcVirustotal results 30.00% Heodo
2018-08-14Invoice.docdoc 20f4771fc95bb5e7d9a371334784a1f92b9b7f124f03daa095b429b370e0ae5bVirustotal results 31.67% Heodo
2018-08-14Final notice.docdoc aa010815ceb9eef32db89f57240949c1e13244b15f4607220d62ec77302232a2n/a Heodo
2018-08-14Inv. no. 87V2H9952.docdoc 39e7dd2506b539b18a3552bff726eaf7a1206e4b29fc85c5ca189fdb4344a4dbVirustotal results 28.81% Heodo
2018-08-14Invoice.docdoc 131dc89104afa262b7b2476df2a04ffb6085442115e61dda3ff669b6b3168af4Virustotal results 25.00% Heodo
2018-08-13Invoice # 7W6867336.docdoc 04f8b430ef0e919c513430b47b33a44f41f77ca56d8fe99fa7ff5b026125121eVirustotal results 25.00% Heodo
2018-08-13Billing Invoice - Job # 0249793.docdoc e1aad4875acddd1edd99ed628a9c1eae09b4f5a0fc74c4dc6fcfb903e65ef806Virustotal results 27.59% Heodo
2018-08-13Billing Invoice - Job # 327396.docdoc cac7f77847a620052e8fabcb2ed5f81c2b99d393b2da391cdc56eb43b971a816Virustotal results 25.42% Heodo
2018-08-13Inv. no. 0FLH759020.docdoc 351afc8cd4a99e2f8ab047c9c83a1ff6b7e0cf6266ad259213dd29dea3d050f9n/a Heodo
2018-08-13Invoice as at 13/08/2018.docdoc 1438f590ffcca094def32d733903b45b201c2ab97618909352b87f9d29c39724Virustotal results 26.67% Heodo