URLhaus Database

You are currently viewing the URLhaus database entry for http://ewingconsulting.com/solutions/yM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427264
URL: http://ewingconsulting.com/solutions/yM/
URL Status:Offline
Host: ewingconsulting.com
Date added:2020-08-07 15:23:43 UTC
Last online:2020-08-25 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 15:24:02 UTC to abuse{at}servercentral[dot]com)
Takedown time:17 days, 22 hours, 45 minutes Bad (down since 2020-08-25 14:09:03 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-25INVOICE-HLGZ078-7196799.docdoc d91731a4dfcfb45b578cde0a57e35273bdc0eecf426e738a1f52a32e989c9fb9Virustotal results 69.49% Heodo
2020-08-07Invoice52498497604.docdoc a4b97280b1cceda62816b36b8b40327eea965a74334cd171eeca03b3158d3177Virustotal results 37.29% QuakBot
2020-08-07invoice_DTXU707_252780.docdoc 522dfd2bd5983277254467284eb5cb1ae79a0957444adbd473462cfee3599c4dVirustotal results 37.70% Heodo
2020-08-07Inv_RZ941_727322510.docdoc 1647229d0a492df5ee794a4a799c66da98a76da48e6accede91ddb08a694be01Virustotal results 36.07% Heodo
2020-08-07INVOICE-59-691999.docdoc e8035bcb217908bb414bb819f5f71f6745ab19ee1348c122ced77fff342930d5Virustotal results 34.43% QuakBot
2020-08-07Inv-D07-059294475.docdoc 85baeb78ec5f334107e9ade0e037843b94d82a7e1920bc38a3019d6e13e3e021Virustotal results 37.70% Heodo
2020-08-07invoice BMG4 9367129.docdoc 66762226f0f7bab8acf658aaf69557223a227f9225671446d93e502b6d221fd0Virustotal results 30.65% QuakBot
2020-08-07invoice-P1-831748951.docdoc a1d3c10648113856a54d5142939fddfc547781a277390386c2c66731226e65d7Virustotal results 31.67% Heodo
2020-08-07INVOICE-H4617-087987.docdoc 23f821e6c9ca56b683bf96dc9e8d6d19094c60ea1223073f466278f12a2745edVirustotal results 29.03% QuakBot
2020-08-07Inv-8-51319625.docdoc 2232504c5ac6d12d0c0acc9590c5957289d5177e41c502d10797f7bfcf436fe4Virustotal results 27.42% Heodo
2020-08-07Inv-UTV1-307461.docdoc fa8a6f126144c62f8ad30022984be3cebc79be53eab0d9e250fc6d1c91d1d620Virustotal results 24.19% Heodo