URLhaus Database

You are currently viewing the URLhaus database entry for http://www.myboxsi.com/-/balance/zshqt7fhhd8k/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417869
URL: http://www.myboxsi.com/-/balance/zshqt7fhhd8k/
URL Status:Offline
Host: www.myboxsi.com
Date added:2020-07-22 16:00:26 UTC
Last online:2020-07-22 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002824299 created on 2020-07-22 16:02:07 UTC)
Takedown time:2 hours, 22 minutes Good (down since 2020-07-22 18:24:36 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22DOC_NC8029939621VH.docdoc a82109f8fbf62524daee674feca6fa72a4c3641450c09a4b381995bf61dda662Virustotal results 38.33% 
2020-07-22DOC_PO_07222020EX.docdoc 25737bcaa6c0c46693fcd5eef40857305f06e0527275a7135f1ec1c2505102ccVirustotal results 37.29%Heodo
2020-07-22Z_40661078.docdoc 6ee52218b54636db8edf7833738f921c320966b59f82e84047628cd124d5bb62Virustotal results 37.10% Heodo
2020-07-22RK0592529404AE.docdoc 218a9eeb52984bfb956e887df5190845197214a6819f3d2c448ca8e6fba15bf0Virustotal results 38.33% 
2020-07-22REP_C2IPUNUS6RKJ08OD.docdoc 0c133bcd327858b979c14422ac2623c0efef1dabc588f2e775e58049bacf093eVirustotal results 38.33%Heodo
2020-07-2245150608122.docdoc fffcf5e69d6c606f32e426b42e007fc3dc07d3b83544748104e2a6abc3863f39n/a 
2020-07-22U_11932882319684.docdoc 71fc59c792baaf787bf4536e969036e4e2aff0ce6f9f8319ee51515bedbd7488Virustotal results 45.90% Heodo
2020-07-22K_4070868137081111722.docdoc 7e7aa30ca5690996f1a10f67cfb4dc964e5abc8b9ebb860ae6c3c770ff551894n/a Heodo