URLhaus Database

You are currently viewing the URLhaus database entry for http://daoisthealing.com/cgi-bin/ut/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427133
URL: http://daoisthealing.com/cgi-bin/ut/
URL Status:Offline
Host: daoisthealing.com
Date added:2020-08-07 11:11:04 UTC
Last online:2021-02-02 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 11:12:03 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:5 months, 29 days, 4 hours, 16 minutes Bad (down since 2021-02-02 15:28:28 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08INVOICE-6-2180629.docdoc 5d7f4b905c268a16b873261ceb5f2bca434dbaa45ad6c5b20a3d43091709ace2Virustotal results 39.66% QuakBot
2020-08-08INVOICE_D5931_5946420.docdoc f2ac567d25e6c1c3423309a6ee7158f3740d1f4b648a3d0b162b83cf1dd3b6b2Virustotal results 38.33% QuakBot
2020-08-08INVOICE-I523-51292871.docdoc 934e668c7d90204ad5578903490ce28fd0e338875fabd6a82a4789afac1f3062Virustotal results 38.71% Heodo
2020-08-08INVOICE OQNM96 189727500.docdoc b203ce9f83d385b987ff9b43259951280c34830fbba17c5263dcfa112ed1396dn/a QuakBot
2020-08-08INVOICEDOJN7641886760.docdoc c3d556b58967b1957a9c5b9e5465e6af4230e6f94ed8b1109d30445a86d2fb9fVirustotal results 40.00% QuakBot
2020-08-08invoice914651326.docdoc 4c353ef6b7ce0abc18d802dc5869a0c6bb88a63e31585b98f518d10fedb62428Virustotal results 39.34% Heodo
2020-08-08INVOICEJEJJ31425853.docdoc db215901595eb9e3359f679ea0018582715a7a540043a00d9417558895ffa6dan/a Heodo
2020-08-08INVOICE-98-4520182.docdoc c8451a4260d26137a6dc3200a2290e14f2210f03417e39e58ad95052ec6b0de7Virustotal results 39.34% Heodo
2020-08-08invoice JK3 1815531.docdoc 51d32641c97d78c53640cc9fec84f1b150eb754042a74ce028d92f70bcf7544an/a Heodo
2020-08-08invoice LA3 5694642.docdoc e2f4571846f5b8e17a5481779757851f78f2853f6734ce6ef4a92db0cd0c5de2Virustotal results 38.71% Heodo
2020-08-08INVOICE-DP0044-937498.docdoc b5b0dab6e7d7a2fc66a0947ad16fc1b6de4d68b73d5d071459ed06b18a96a8a0Virustotal results 38.33% Heodo
2020-08-08Inv5841501011.docdoc c9bdce375621af7dd83001e09e95fa17ae125b59423cda4a4499fb3f31fc1adeVirustotal results 40.98% Heodo
2020-08-08Inv_ZX4_928613.docdoc 8ee784204fc5d7cb096a234e69f593cb6807f74e01a2393e1d1f9a8e99f22b74Virustotal results 37.10% QuakBot
2020-08-07Invoice J5385 172065741.docdoc d91731a4dfcfb45b578cde0a57e35273bdc0eecf426e738a1f52a32e989c9fb9Virustotal results 37.29% Heodo
2020-08-07INVOICE 8090 58579299.docdoc 346b0ed5db257c2bf541ae37f57e3971a19bc69310811cbe7fa037768f2136a1Virustotal results 38.33% Heodo
2020-08-07invoice_JA1828_37512210.docdoc 847871d283f7c713a149c57d41ef65f78b7c7f808ba380b9e80f09fe48a837d6Virustotal results 35.48% QuakBot
2020-08-07Inv MWV223 82897129.docdoc 7ce67620298aa7d0fe5e7f2bab8e052f4a4ce937c3300c92875e33d7b466acc0Virustotal results 36.07% Heodo
2020-08-07Inv-7623-24649282.docdoc 6d9ffb2447adb083ad20788cb467c96a7f91b27d9a5a9eb35a13e2471d909b32n/a QuakBot
2020-08-07Inv N672 0023238.docdoc bb196956c5e57876daf8c64828c2b0cff8f83fc540f7ff492ecd7632f8a235dcVirustotal results 36.07% QuakBot
2020-08-07Inv NMJ8862 48770971.docdoc 5871ec926c8f2a5e608bbcc0aadc55520fcba58d418280c7f44449f8e88a3d41Virustotal results 32.79% Heodo
2020-08-07INVOICE-LF5472-205590286.docdoc 01415a0a9ffd595121b549de4447ea446137954484eaa2deda4b870f30782be5Virustotal results 33.33% Heodo
2020-08-07invoice_OXP162_93927017.docdoc 23f821e6c9ca56b683bf96dc9e8d6d19094c60ea1223073f466278f12a2745edVirustotal results 29.03% QuakBot
2020-08-07invoice-Z4-394584.docdoc 3a7e162433ba4372c7e49ee5cb6bd4afb23cde7bc0f19d39edc30aa22473994en/a Heodo
2020-08-07INVOICE_Z4_74107030.docdoc c2ecd3419f71d51acb56c7f02e685cdd46ec96514b459545a931768e2141ae58Virustotal results 27.42% Heodo
2020-08-07INVOICE-OUJ808-79428361.docdoc d0cf81816d667ed017c8fcff606f72dd98ccdbd4ab1c740d6e93822bdb303188Virustotal results 25.81% Heodo
2020-08-07Invoice-GQXW4079-9150274.docdoc 288bcc48727e2eed9e8b0c26b5c3e04a3856769d65bfd4065bba4a533237bf36n/a Heodo
2020-08-07Invoice GP765 999039722.docdoc f2f9d8844e0ea0472349e17048e353522a138927c4b88802535845aa231f0833Virustotal results 24.59% Heodo
2020-08-07INVOICE_VCX3_187212455.docdoc fe2a7c9ef45e330a03ae7d563a86ae6a60347ecb9b4cd212a55d9695dbc48f61n/a Heodo
2020-08-07Invoice-N66-5386633.docdoc d3c7b17eb10b73fa3e2c519f2e78fbf3d2fc0ceca12fa1eb7b6d2f2b550ee3ecVirustotal results 25.81% Heodo
2020-08-07InvQ387506336624.docdoc 78f72d01c44f3292fbce9a5d056c18b4d08b4fbd610353475be433fa225637f7Virustotal results 25.45%Heodo