URLhaus Database

You are currently viewing the URLhaus database entry for http://badeggdesign.com/cgi-bin/1u4da-ysy-303765/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427184
URL: http://badeggdesign.com/cgi-bin/1u4da-ysy-303765/
URL Status:Offline
Host: badeggdesign.com
Date added:2020-08-07 12:36:05 UTC
Last online:2022-09-11 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 12:38:06 UTC to abuse{at}turnkeyinternet[dot]net)
Takedown time:2 years, 1 months, 14 days, 21 hours, 36 minutes Bad (down since 2022-09-11 10:14:57 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17Inv-LH51-19988880.docdoc 1b2b399174aa5c19da227f93d2cb47a606afc583558cb5fdcceab7d27d1b5083Virustotal results 70.69% Heodo
2020-08-07InvOVN0768904262.docdoc 73b694ec455996bd7a0981da724a284e728e060e93368102b4e454ef16879b98Virustotal results 39.66% QuakBot
2020-08-07invoice 05 591831935.docdoc 96c2710133ec54c60394683f148a94ba31cda1182b21b8f0f3285d78c92c0336Virustotal results 35.48% Heodo
2020-08-07InvoiceLA15702604654.docdoc dd693242b7c4ea00e3edc941a1b92d17d7effee6af390cd0abda5da40e5f4367Virustotal results 36.67% QuakBot
2020-08-07Inv9686866912.docdoc 3d2f7bb83fc1e0ff00062b026e00645a1f25b5538f799fc47cb8f1878d8d9c39Virustotal results 35.48% QuakBot
2020-08-07Invoice-MAT05-6999324.docdoc bb196956c5e57876daf8c64828c2b0cff8f83fc540f7ff492ecd7632f8a235dcVirustotal results 36.07% QuakBot
2020-08-07Invoice-U3-471399.docdoc ebdda6969778acca315a17e1505c60c3ebbf9c13ca2b43a5092c7a32341f06acVirustotal results 29.51% Heodo
2020-08-07INVOICE-CBC207-114922930.docdoc a1d3c10648113856a54d5142939fddfc547781a277390386c2c66731226e65d7Virustotal results 31.67% Heodo
2020-08-07InvoiceGGL0374765060.docdoc cfabab6ffb980a446a83e4e44e6bd9a0f7d5eb5836628e4934ae4987f58ec211Virustotal results 29.03% QuakBot
2020-08-07Invoice-X4-96270161.docdoc ce9c9aa5b7aeaf8280a14d4bdca59c62624e14eeae978170acdb80a98ed185deVirustotal results 27.42% Heodo
2020-08-07Inv_A7_03846803.docdoc b0ca63e844878888dfd2c5e0ec67432ddbf00dd81de2f91d7b807308d942b84aVirustotal results 27.42% Heodo
2020-08-07Inv L9595 5048353.docdoc ab1f576293cc70428b0adcadcbb453c1525ff8bf2fa71d650e52b83ff4092f81Virustotal results 26.67% Heodo
2020-08-07INVOICE-9-60793537.docdoc 8dca57bd20cb1aad6ec1fa7527c59fac9aa9f278935d7eabade0ff47817bda58Virustotal results 25.42% Heodo
2020-08-07invoice-L2241-2714295.docdoc 25b3fd3062afb5148a7f9cd4d2008b1d5d8da6964e92d8e5f8e80af2032b4140Virustotal results 24.19% Heodo
2020-08-07Inv-JHCA6338-542585153.docdoc 0a4b53e2bf7608fe93c60618cf50a657598aa4fc95b947cc7fa7b8fb0331d561Virustotal results 25.81% Heodo
2020-08-07invoice 8058 767703665.docdoc ba3d741816e8594c6fa98c65de42f5b48e2cb5a3755cd01909d92f34060b5a1an/a Heodo