URLhaus Database

You are currently viewing the URLhaus database entry for http://digipro.com.tw/gold99.com.tw/ty-8ej-60/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422070
URL: http://digipro.com.tw/gold99.com.tw/ty-8ej-60/
URL Status:Offline
Host: digipro.com.tw
Date added:2020-07-30 15:59:36 UTC
Last online:2020-08-03 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 16:00:03 UTC to abuse{at}quadranet[dot]com)
Takedown time:3 days, 22 hours, 34 minutes Bad (down since 2020-08-03 14:34:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01Inv_F4232_551534.docdoc 56916942bc59a1ae0cc030beaf907b54631390e0a5fa7d75bce1f120df88d843Virustotal results 52.46%Heodo
2020-07-31Inv HJG843 206803435.docdoc ec21525a8852265e8892193f896c9002e6f4a525c42e980120cdfce6e8ab3d9fVirustotal results 49.15%Heodo
2020-07-31Inv HJG843 206803435.docdoc ec21525a8852265e8892193f896c9002e6f4a525c42e980120cdfce6e8ab3d9fVirustotal results 49.15%Heodo
2020-07-31Invoice_X26_4603984.docdoc 955df219d60bd853070b3b3202dffdc5458ac8fed8c076c8c8076baf06348236Virustotal results 46.67% Heodo
2020-07-31Inv EO11 143962394.docdoc 991fefb51ab6ff987891d3156610be49073ac26a760411d94ff209425c7af854Virustotal results 47.54% Heodo
2020-07-31Invoice-821-64525375.docdoc 329ee2c468d88dcf1fbfeecc4f4cd304e2f5bab2e86ac85a7577f4e02f0f7067Virustotal results 48.28% Heodo
2020-07-31invoice-LU8-079215122.docdoc 1bbf1c280e0399776065e6c00e7ccc32e3dd3657069cf5d5f27ccda9a1e53d69Virustotal results 46.77% Heodo
2020-07-31Invoice W8720 518129871.docdoc 4cb3ccb083a74daebfaa6b646b8294f70cebbba4515d8798b52a41cccde1c7a4Virustotal results 47.46% Heodo
2020-07-31Inv_099_999883.docdoc 99b43c6e14bfddc98c87cb9dc35cd89b59a2797e8893f5005eb0868226027f35Virustotal results 46.55% Heodo
2020-07-31invoice TTGM3 289241527.docdoc bdfb558047f777f0a0fb66e81bab1d2eefe9a0041a72d203b52456717f30a594Virustotal results 44.26% Heodo
2020-07-31Invoice_NGH51_153840687.docdoc eb06e5d66d21212c7eb73e44c67b0748a034545ff7a5127eba4ca016692e4786n/a Heodo
2020-07-31Inv-DU38-23887432.docdoc b6437e7882339828ef75527bacda816301bc6b0ecbbcaaf400f830755039670fn/a Heodo
2020-07-31Invoice-WTV0-064557220.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 51.67%Heodo
2020-07-30Invoice-WORH5212 857819855.docdoc 5a1d1b56cb562585cb92395ba78f4b2eabe9a5b1792cda8e8f28455fc11a3464Virustotal results 47.46% Heodo
2020-07-30invoice-Y54 8383678.docdoc 89e20dbcc8e8d14df0055e98cfd6bf380fa8cde12d9cbc1045ed4a521c08496bVirustotal results 42.37% Heodo