URLhaus Database

You are currently viewing the URLhaus database entry for https://mizuhosi.com/hana-sc/jfGRrOG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429521
URL: https://mizuhosi.com/hana-sc/jfGRrOG/
URL Status:Offline
Host: mizuhosi.com
Date added:2020-08-11 15:42:11 UTC
Last online:2020-08-12 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-11 15:44:07 UTC to ipadmin{at}liquidweb[dot]com)
Takedown time:1 day, 2 hours, 31 minutes Poor (down since 2020-08-12 18:15:53 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12invoice-WVEJ165-2766643.docdoc a7e3cd5c8c2cecc05432a46669c2f384a349f3a0cdbbd052d139215cd8ff457cVirustotal results 27.12%Heodo
2020-08-12Inv023813789.docdoc 58edf47f141b8c219872bbd283da43f0565980ce3872b0d0233932201921f12dVirustotal results 30.36%Heodo
2020-08-12invoice1221222.docdoc 5dfd8adbb8d673fd2033888682dc9ee31b2fc93010125edad2f9924f4d6fc41dVirustotal results 27.87%Heodo
2020-08-12INVOICEPPJ89553905079.docdoc fea443cdac59dd7f98d2141afd162ad736f49936f906f5ec5ed88ac95b63ad91Virustotal results 28.33%Heodo
2020-08-12Inv-D51-00594838.docdoc 7d5c79687a896c7e7d01ee6aa991e9c864d4fccd2f64fff2916322ee1371bbc3Virustotal results 28.33%Heodo
2020-08-12INVOICE_CO29_5557868.docdoc d8c9580c0c9f2bb8a4e50b71b6bf047c9a5aa42f2fbc76b4315fc8b2bd90fef1Virustotal results 27.59%Heodo
2020-08-12Invoice_UTZC4_045707.docdoc 2f20ed3e86d25bee2fc86cfef8577a1392ff6573b368c48c7611b7215f15323eVirustotal results 53.33%Heodo
2020-08-12Invoice-2-05708620.docdoc c594321ad25c0a0e2cbd28d850bd14056f97b05472ef3fc60aeaf17e43cc95c0Virustotal results 51.67%Heodo
2020-08-12INVOICE-S0210-75997111.docdoc a2b1d13fc111d276dc837aa2c6e155e9aa2944ec66d9133932b1f183cbecad32Virustotal results 52.46%Heodo
2020-08-12InvRROC396555639625.docdoc de3e75a70100e3ecf0015c869943c8c67ec15e70f7105d34fd9452677b60e0ffVirustotal results 51.67%Heodo
2020-08-12invoice-D6-5696028.docdoc f187d66fdb939f8dba5144cee441601671652077d4b7f795a6d0a5ce18e0fc50Virustotal results 51.67%Heodo
2020-08-12INVOICE-TA760-477209.docdoc 5ed47d47ebc0597edf84ae0658438eff8b3241ae47a071fffd0144e1c074d560Virustotal results 52.54%Heodo
2020-08-12Invoice_HQR309_0994586.docdoc c57f8830d597b05f0dbf9031092be52ed1ce11f9f75f530bfd698f46f624901an/aHeodo
2020-08-12Inv-DRM020-277780466.docdoc 252a44229413353042efc9846e4521a6c230832832d0d7efd0bb8b2677026afbVirustotal results 53.45%Heodo
2020-08-12invoice-C7-333317835.docdoc 6e9b1ad824b0bc35792a2ec92fabb0456af70c654e99e5f6d0067903f3c771ceVirustotal results 52.54%Heodo
2020-08-12Inv_ZN3348_0117893.docdoc 1f79b6bd2f0ea2810cdc8c4673b7393f918b727517f5f47b1bb275af3d5e8a31Virustotal results 51.67%Heodo
2020-08-11Invoice_717_029952875.docdoc ba44f106713979944843774380c0f9975db8ac9c9e7bea15df6b1523729f8e8fVirustotal results 50.00%Heodo
2020-08-11Invoice-YZZW4122-546956058.docdoc 98891f34f0962ebc73b8be9c5a37aa21ad42fea2d08629bcbf84ff00595fe02cVirustotal results 50.00%Heodo
2020-08-11INVOICE-CN3747-70180840.docdoc 994db52aefaf0bc495521d0b5b29b59aa7e5c5aa4d6bc221e2808f21247cf19aVirustotal results 51.67%Heodo
2020-08-11invoice-077-0264193.docdoc cbb857ef4e6a3fd6c97835111cd57faa9a633931718e00486d9d6ab47dbc88c0Virustotal results 51.72%Heodo
2020-08-11invoiceN28093740856.docdoc 98c981a420851abdca6108f1264153f000a93d4efb36a2df630d0fb91c63aaean/aHeodo
2020-08-11INVOICE5494808106.docdoc 2bacd46747f03d8facae64c50de4987098ced5cb35fefb1aa711829179d83d9fVirustotal results 47.54%Heodo
2020-08-11INVOICE_YEY79_150742.docdoc 755d66932d3f5cb9fcbb81109887c722976a7510bafb70bdd08f2cbe31e85780Virustotal results 46.67%Heodo
2020-08-11Invoice 75 766928380.docdoc afae9a58f094ad2820f5d92fbf12b243f4f7db992916f2e6893329b9db28ccc2Virustotal results 45.76%Heodo
2020-08-11Inv2246007390.docdoc 817c56d92830d2748b635b8968f63071adf48becf5ee6dd13346636f1eccf08bVirustotal results 37.70%Heodo
2020-08-11INVOICE-Z5327-281220.docdoc ede2cc2f4a614a18e35882b7e97c84dd7af65a7473b27ff28fab5de1fa31b080Virustotal results 38.33%Heodo
2020-08-11invoice 1216 060282.docdoc 037ac6663cc663afedeb54cc2424400903cff00417fd70e5ad9b648a50eeae83n/aHeodo
2020-08-11Invoice J60 601658408.docdoc 2737dd41ebe5d0e7552c8958f281b719c377de9d83a1eda32169e55d51524552Virustotal results 38.98%Heodo
2020-08-11invoice-U900-916848557.docdoc 5d6ee55a76b2af864622bf0ad7469af81f6ba3694891a5492fec13a0bd84b2feVirustotal results 36.67%Heodo
2020-08-11Inv-E3194-2341398.docdoc 70a726919b0c5a17e38584cf3948fe775e56c0927430ada9bfdcb609da988b9fn/aHeodo
2020-08-11Inv-PC57-08879711.docdoc 7e21f61db763425c9b1e2b322994e9bb78f37c1bc67c045dd79c60e4f1be48c9Virustotal results 31.15%Heodo
2020-08-11invoice-D5865-598452.docdoc 914abd85dec0d71dc282fe97279075ef7229f967f7723b24b40694d34702b721n/a Heodo