URLhaus Database

You are currently viewing the URLhaus database entry for http://cyberantics.net/progress/v8ujg-m9l-302441/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429652
URL: http://cyberantics.net/progress/v8ujg-m9l-302441/
URL Status:Offline
Host: cyberantics.net
Date added:2020-08-11 19:44:04 UTC
Last online:2020-08-12 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-11 19:46:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:6 hours, 43 minutes Good (down since 2020-08-12 02:29:06 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12Invoice_AO223_7157567.docdoc 252a44229413353042efc9846e4521a6c230832832d0d7efd0bb8b2677026afbVirustotal results 53.45%Heodo
2020-08-12Invoice-YXMP86-957164416.docdoc 8e282ef570d12f5e1cce05e717449fa995042a179640c3d603856110e779be54n/aHeodo
2020-08-12INVOICEBAJM73617576.docdoc 1f79b6bd2f0ea2810cdc8c4673b7393f918b727517f5f47b1bb275af3d5e8a31Virustotal results 51.67%Heodo
2020-08-11invoice P1 01471343.docdoc ac1bd9010c2ce0ab643beaa92a00c1d342b013f58e2099bc3c85e584b8a92107Virustotal results 50.00%Heodo
2020-08-11INVOICE-EWNB6262-007552.docdoc 98891f34f0962ebc73b8be9c5a37aa21ad42fea2d08629bcbf84ff00595fe02cVirustotal results 50.00%Heodo
2020-08-11Inv A7 7144509.docdoc 855f271178a061c154a5feed625773d8a02e960340dff7e0e0aedfefd40c2873Virustotal results 50.00%Heodo
2020-08-11Inv_DV3265_2296537.docdoc d73d3d4008607aa85da7da86d829db51efb32444af68f33a88a957c15e3dc7cbVirustotal results 50.85%Heodo
2020-08-11INVOICE-F32-8530284.docdoc ba9a8497f8d62ce6e51e23f89f045998e57f187f7b8b9ff3168e5289d1758e80Virustotal results 50.00%Heodo
2020-08-11Invoice FWI3 172364.docdoc baa7ec55d76e7be67f654211832accb7b7352442fefbadd3a4047e63adcc24c1Virustotal results 50.82%Heodo
2020-08-11invoice-HIW9338-325287.docdoc b8b0ac3e831b2c1da81ca4dcc7f32ba26a362ccac9c83fb89eda121ef805c395Virustotal results 48.33%Heodo
2020-08-11Inv-U5-5192933.docdoc 4ce8a32a7d3405a784a5a896b2faeb1ae1c73f9201af0716bffd10fb59e38ad9Virustotal results 47.46%Heodo
2020-08-11Invoice_C08_167844.docdoc cb5234b6061bbdf400ee2833eaeba7a4f39a5d883194f1c0bf3c317267799d27Virustotal results 45.00%Heodo