URLhaus Database

You are currently viewing the URLhaus database entry for http://www.dii.com.pk/tests/ezcku7-q1tjw-0018/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:421528
URL: http://www.dii.com.pk/tests/ezcku7-q1tjw-0018/
URL Status:Offline
Host: www.dii.com.pk
Date added:2020-07-29 16:09:07 UTC
Last online:2020-07-31 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-29 16:10:02 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:2 days, 4 hours, 47 minutes Poor (down since 2020-07-31 20:57:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-30INVOICE-I8-415063366.docdoc edffc299063e343351d529e84129e771c7c6e2b1894d86ebc91c78d0bad815c8Virustotal results 45.16%Heodo
2020-07-30invoice-T07_084850.docdoc c9014beaea9142158349ccc46c86a73d289d55d17cfa3c02669b26b00aa9faa3n/a Heodo
2020-07-30InvIB957-8003373.docdoc 55d0bd650e90d7bfb5b9af758688a4006db13679c53d8197e81f03701fbf52f1Virustotal results 45.16% Heodo
2020-07-30invoice-PQ72-672782.docdoc 0cfa9d40b08e00ae686376bd8a2c6f038a0bdb6ad27e953b94f1b1643cf54d5bVirustotal results 45.90% Heodo
2020-07-30Inv_VU12 12412715.docdoc d5a5e07b856fa95bb954729db5a02b3415dd89b0be6048cc7d0e3f0a8afd89f7Virustotal results 46.67% Heodo
2020-07-30Inv-TT3 277733.docdoc 412fb57e72ba6ac81ae2808528e48e74eff28cccc8244172b6755b864b86b3fcVirustotal results 45.90% Heodo
2020-07-30INVOICEELW69-928522.docdoc 28ad746a87c186873fd8d644a8ca704b9768959c1d8cc780bbd1e4fcec07256cVirustotal results 45.00%Heodo
2020-07-30Inv-YSE8291_96994893.docdoc e039f53c75e931e700cbcafe41ac39dfd4673929f7f2cf333a2f722272fd240fn/a Heodo
2020-07-30INVOICE_OS2-84363979.docdoc cf7363d569abe51412e602a505dbb2d3604aaf97ee7c71db42e66b09224dce54Virustotal results 44.26%Heodo
2020-07-30InvSLOD6-085187.docdoc db24098d6bd41dec460588297f00255c409f745bbe32faaf2cb6476fd44ee504Virustotal results 44.26% Heodo
2020-07-30Invoice-QQ6_0787181.docdoc 72244c8748d1f0b37e10ef8b0f5be0624ea7ac975aa1214281b4f326e6b2f4b2n/a Heodo
2020-07-29InvUF914-47475045.docdoc 9682cb3fed20b168899452201908168de9b2c2d82530d7227a4474b8b2587eb8Virustotal results 43.55%Heodo
2020-07-29Invoice VO067-8231387.docdoc 40a19219a853bbc60201d4cd4fc226bcdda0966f87f05dda562d113d65c8ce67Virustotal results 43.55% Heodo
2020-07-29Invoice BKJF2816{:REGEX:.docdoc 81d3e8f15ad09342186fbe8b601f63c809fd415ee1c5cb4b739fb3ab7a47b99dVirustotal results 43.55% Heodo
2020-07-29INVOICE-JRD3926-793523143.docdoc b6eb1c7760e06c0bf914bc6f8d26d4aa98a1d859d71fed9d6712db95af81f5f0n/a Heodo
2020-07-29Inv-HPCQ9021{:REGEX:.docdoc bab24985fa20dca7f015976c0212909f59429d181ee874074692fa835b0f604cVirustotal results 36.67% Heodo
2020-07-29InvoiceUV3 021232263.docdoc b56882372e147eff336dc2f949fd0a17aff2966fac9c0f13c28a58e43e2d1aadVirustotal results 36.07% Heodo
2020-07-29INVOICEMLCI92-01648422.docdoc 0538723c17579616d35fe643f326b6b5b81319f1e5081079bef5cfc6cc2eefc3Virustotal results 36.07% Heodo
2020-07-29Inv WXN35-45180618.docdoc 42d013d9cce79a7e86da79f6dd3d25b04f8460636e45c85ec23d1a962173f389Virustotal results 35.48% Heodo
2020-07-29INVOICE AQC452-1609528.docdoc 4ece79e02379040355a4ff12f9b622c675a9910c6f10d98c393b790dc0c9536bVirustotal results 36.67% Heodo
2020-07-29InvoiceW541-637927400.docdoc 9031e6db6e2296c8de8b8f71f6e03e3251e9b3497acb57e52ef2a1a1a6b646e1Virustotal results 36.07% Heodo
2020-07-29invoice G20 706292.docdoc c9908873e05408d13895e8545fd5b9e3eb95032f5e363086b19e6a14a8ed7075Virustotal results 35.48% Heodo
2020-07-29invoice F464_69950994.docdoc ef939c6757486356eebfdc09af29303c9ac05ba4e54bc6f98ca1206664792a81n/a Heodo
2020-07-29INVOICE_ZU9334 9641206.docdoc cbf7197df6cd966772e966e4e8a67f74d1b090ade41e58f80f706a071ac64286Virustotal results 36.07% Heodo
2020-07-29invoice UD56-599414947.docdoc a19deec65bef4fe1030b463be94b414c4b4b1bad207acfc2fd8df6bb5bbbefdbVirustotal results 35.48%Heodo
2020-07-29Inv-61-7662331.docdoc c65c81e1a76fdf4122271da9b47b9b45e0a45519719f468e7539eba8ab8f9d5fVirustotal results 35.00% Heodo
2020-07-29invoice822{:REGEX:.docdoc aebd20f5f33a243e226932532fcb08c7f948d679ac4c6df277aebcc4f0571894Virustotal results 36.07% Heodo
2020-07-29INVOICE HEFX4526{:REGEX:.docdoc 1506ac2044400ad8ef962e4a6869f6691adf13c46c27733f26bd8eede6136244Virustotal results 36.67% Heodo
2020-07-29invoiceIL9873-60785886.docdoc 1b23e6893b349fd94640f1425a5ffebe9b61b4d3e21ad8f8ab5117384f0ffc0dVirustotal results 36.07% Heodo
2020-07-29invoice 43-802710897.docdoc 66101af9345cb4f58a1380f463086cc56c8b653f617e9b6f264bdafff2889bf3Virustotal results 33.87% Heodo
2020-07-29Invoice_TZV037-2670008.docdoc 2f455cc6268ecdade0ca6fffc1663cc0afd5ba64feef4dcad85b6d26f5a6de40Virustotal results 33.90% Heodo
2020-07-29invoice_9724 240887750.docdoc 5e4915b311bd06915e5e10b171fa82cd29d5e308771a468a0d28bfc9c9731540Virustotal results 34.43% Heodo
2020-07-29INVOICE QRD5-001243143.docdoc 6ecb72b433b635a49ee2f82737cec4103d08d18e988b42d36bd1b35d175ef612Virustotal results 33.87%Heodo
2020-07-29Inv0159-713156.docdoc dbded8e451e9740df257c4a168a1086dd06b873e47b78f5f7114501a175f9905Virustotal results 33.87% Heodo
2020-07-29Inv-GBNO21_06384260.docdoc 4dbfbd8a057e49274bd92c01fa9680f9b478eaf207fa1c55aeb36d7879a35b27Virustotal results 33.87% Heodo
2020-07-29INVOICE-BCL15{:REGEX:.docdoc 55337d60343cfb054dce4ebe8314c3a3644688477b04dc77ac4488120e8540b8Virustotal results 34.43% Heodo
2020-07-29Inv-ER2-49981619.docdoc a8ada6c6517543d91ffaca84f3e1e4fdeec35aef369f41275138b8d3eadc68ecn/a Heodo