URLhaus Database

You are currently viewing the URLhaus database entry for http://demellowandco.com/cgi-bin/vsxvE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420642
URL: http://demellowandco.com/cgi-bin/vsxvE/
URL Status:Offline
Host: demellowandco.com
Date added:2020-07-28 12:16:04 UTC
Last online:2020-07-29 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 12:18:02 UTC to abuse{at}ukwsd[dot]com)
Takedown time:17 hours, 10 minutes Good (down since 2020-07-29 05:28:40 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29Estimate.docdoc b2eeddd5041eedee7e49fe10f67bbf0e658f7636ccfd952737bb3938777ba2aaVirustotal results 45.00% Heodo
2020-07-29Inv.docdoc a4e941731ea6004cc9cf3198d9af9fe064ee77a13f1f9b78de69450a34d43722n/a Heodo
2020-07-29Fatura.docdoc e275f7f70b358d8bfad421c59333f98e86002da3fe2e9afe4079641717342f3an/a Heodo
2020-07-29Fatura.docdoc 3907087a305c59e991dc3d51ccf7fbd846bdf7218ff00d228ec92dcbf2fbfa3fVirustotal results 40.98% Heodo
2020-07-29Inv U09032495.docdoc e63d32f5ad42cb868addb8ab5910d52dcdf4fd0938f94c24d04167806a13df8fn/a Heodo
2020-07-29Inv.docdoc c20b895c419f49ac8e3d870abf913bfdd03570857ad269d48b42425f190f8c9bn/a Heodo
2020-07-29Estimativa.docdoc 8caad6920379901e4d096cca5f10d76e8ead6ea3a4ee106ebed0cdf9b07a1bf6n/a Heodo
2020-07-29fatura.docdoc 6fb8a90bd031c21d70ab8922bcd7854a8de25576c3cdd885e5137f8760acbad4n/a Heodo
2020-07-29Invoice 0491905.docdoc aff7f094be9e1ac438ba8fe670fe1e8d512a6dae1d7e289eac74c1d745266349Virustotal results 40.98% Heodo
2020-07-29FATURA 04512.docdoc ab70b9d9a0b0c05df3feeffcede8b732964d9ea5f11532cbb899380d17253baeVirustotal results 40.98% Heodo
2020-07-29Invoice.docdoc 0c8994f002b6ec33997f0a40220902be5b471b2317389458824ff10d7f16a2abn/a Heodo
2020-07-29Inv.docdoc 467b7a8dbff8460d6aefd737df08ca47cbe03f7b5f964c8dd0bce215319882b4n/a Heodo
2020-07-28INVOICE X06343216.docdoc 04abc34f8660da49cfcb4daa11b45febf492755f28739bb02b2e00e51e3965e3Virustotal results 42.37% Heodo
2020-07-28Invoice BV0308.docdoc 2500e2bf1ee4be15c6ba67badbce47df2e8c4910ae6d70956ea26631afd4bd8cn/a Heodo
2020-07-28INVOICE.docdoc 66f1fb5542ac9c7943dab8cfbf1dea1fe42a40ae78832089a49f7034e3b833daVirustotal results 45.16% Heodo
2020-07-28Inv.docdoc 95a1a5424adf5b9b6a73d12c786ae850dc40a4b7603d0b8c7863e47f7f724f9bVirustotal results 43.55% Heodo
2020-07-28Inv 01973862.docdoc 88d3d8a15ed2c7edca25b788fb0c85eaad6c085c6b2e98a45362663326638ae3n/a Heodo
2020-07-28INVOICE T0660.docdoc 598a8daedb218279d20cb8759624e3f136836989072aac66bcf0eb916b1bbf26Virustotal results 44.26% Heodo
2020-07-28Invoice WQ0404.docdoc d8a8f601fb7868b6495b8e4c97b8f7fa3748c8f3aaee3ffdf975200d70b49ff6Virustotal results 43.55% Heodo
2020-07-28fatura I0919.docdoc 1c1841baff08804539ba328b9f63e6ec39abab9afc6bdc70904eca138a993247n/a Heodo
2020-07-28Invoice.docdoc c61820249fb8e9e6d4e20f466c9eb023334d37138f66b001e5b2221392fb7eedVirustotal results 40.32% Heodo
2020-07-28FATURA 04664.docdoc 6ffa8618b9b0315ef9559c3d83f1fb565280997766353723a4db9ee951d0c21cVirustotal results 38.71% Heodo
2020-07-28fatura J099159.docdoc 0d6509971fffd58a9e5e8ccb95d1c35a5db8b51d08e03866b63dcc2a5556c1bdVirustotal results 38.71% Heodo
2020-07-28Fatura 06736695.docdoc 25e12758f5837d2de012b1df34c4e8e72fa0a90075d040f92d97bb65c641690bVirustotal results 40.32% Heodo
2020-07-28Invoice 0073754.docdoc fb5c853a6405f26b08c948c62839ca8b738c93cb82885c471d06199a5fc991edVirustotal results 41.67% Heodo
2020-07-28fatura.docdoc 9f93a52e0305156143b2994eebbb6bb1298eab091d7dc6f48d4b9a5cb3a13ae9Virustotal results 39.34% Heodo
2020-07-28Fatura.docdoc b2a50e342d521e424f1a64b354514cc9fb86aa58abbc79ce09bcea7addeb914eVirustotal results 39.34% Heodo
2020-07-28INVOICE.docdoc 594bfa87e215f468df55756deddc3a5d50f0041a59886de81b364bb44a8da22fn/a Heodo
2020-07-28Estimativa.docdoc 54171a3ad4b125dc2795767c4e783e474bddf5f973b21bfaad94b3d15057b763Virustotal results 41.67% Heodo
2020-07-28FATURA.docdoc a9fa2e424cac8c5dac01e962a644fc3df563f59332a69ff2be98f077040ccea2Virustotal results 38.98% Heodo