URLhaus Database

You are currently viewing the URLhaus database entry for http://paulscomputing.com/CraigsMagicSquare/VQKNxPsU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429996
URL: http://paulscomputing.com/CraigsMagicSquare/VQKNxPsU/
URL Status:Offline
Host: paulscomputing.com
Date added:2020-08-12 07:09:54 UTC
Last online:2021-03-01 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 07:10:02 UTC to abuse{at}he[dot]net)
Takedown time:6 months, 21 days, 14 hours, 21 minutes Bad (down since 2021-03-01 21:31:37 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13invoice-MBVT452-91201974.docdoc 43b13b874d7ccbe6821d27e5a403e6415ece6d1972ad7409f6f294d1bce52112Virustotal results 26.67%Heodo
2020-08-13invoice_VM7273_7283637.docdoc dba9e4aa81f3eb4f83c14062d3f6223cca9018859b8f08a43f4d642edc871f02Virustotal results 25.00%Heodo
2020-08-13INVOICE-MXZV155-530354055.docdoc 46b21be022edbd1e3c421e00b0f0fb17b33ff686feb8309c819c817da38d7fe6Virustotal results 53.33%Heodo
2020-08-13Invoice-R02-0134398.docdoc de63eeb9f1015ea52b0e1a4d4698d706634a985366000085cfc06c5295b0d165Virustotal results 55.00%Heodo
2020-08-13invoice-GQVD25-468335024.docdoc 3d1521d09be3ee5bbbc9968469250a27e97da18cb8dc7ec8bd9d211bdb683830Virustotal results 53.33%Heodo
2020-08-13Inv_QEZI05_675108515.docdoc fddf4cab73e6e2ff5c40c7fee09d52d5eb903e6bd17ad77aa292c6ded707f394Virustotal results 55.00%Heodo
2020-08-13invoice 97 325754.docdoc bd379f0e0dcc9c8c75d70a99df9f95dc56d70fd92cbf446a21dcb7b22ded59f9Virustotal results 54.39%Heodo
2020-08-13invoice 97 325754.docdoc bd379f0e0dcc9c8c75d70a99df9f95dc56d70fd92cbf446a21dcb7b22ded59f9Virustotal results 53.33%Heodo
2020-08-13INVOICE-3962-774790.docdoc 97e52709f1f9169fb2a3d0cfc7852f811d067999ed1bdc700c6b66bc7dc23765Virustotal results 52.54%Heodo
2020-08-13InvV006052160.docdoc ee1f5c8ab512406824b28cd257477afae1af144286ddd585d142664b10b2ec77Virustotal results 50.85%Heodo
2020-08-12invoice-DAJ7551-1870562.docdoc b858572fbe695215c2aa6ade7ada24c980392ad2f5c9e3564d4e6446ef424383Virustotal results 51.67%Heodo
2020-08-12Inv-23-948157.docdoc 9b5d7e0c6ce7b00011f1c9fa7157bded3963629b18e4b79469bb62c84e80a312Virustotal results 51.67%Heodo
2020-08-12invoice-QEE7964-5314049.docdoc 92dfce0e83a09bacf5d1ce00c4ef5c7bd7c35bbb27742bc01060cb96511f8156Virustotal results 49.15%Heodo
2020-08-12Inv_7_877456.docdoc 27f5a6d1c03ee22b1c20250a5cf13fc46584715e452dc107d3f7263371a96809Virustotal results 48.33%Heodo
2020-08-12INVOICE 76 0814844.docdoc da25968d18d6c8ddfd6ffa940b4e0bc6809a5b1a224602f196ce7eb107578f88Virustotal results 50.00%Heodo
2020-08-12Invoice-N6-25900628.docdoc bb323d30961f8a99384ce2c530e33ec24e0c753db29d1aa629e8bc91ae0c1201Virustotal results 49.15%Heodo
2020-08-12InvEPGU394014245787.docdoc 0c7d085dc88b57e56819a0a9319e1aa089ad9851a0ea21137aab6309395ed039Virustotal results 49.15%Heodo
2020-08-12invoice-FQC7426-2406530.docdoc dcaa5f28e69731be4dd507c5b31f0594b585d516edbaef3db061890462c383d5Virustotal results 48.33%Heodo
2020-08-12Inv96241708.docdoc d1ce5170f24fdb09f187ca0e3e0f6e689fa2c73fc6953ff18ecc123bb8eed49cVirustotal results 50.00%Heodo
2020-08-12INVOICEM1291267097.docdoc 8dece36d7b6b2e3463f8af0b2f614e39f558d2d662cfe89148f6776b1956fd70Virustotal results 48.33%Heodo
2020-08-12INVOICEFD997582976.docdoc f2414110e5d69a3653a43f580b5a599f99245d0492065654a44a6d46529eed3eVirustotal results 45.00%Heodo
2020-08-12invoice_WW0576_367669893.docdoc 3ac3af554f63c5c308ab18407e4d3aa155f7a2ada7a3be3b6bda7eb71fde450cVirustotal results 47.46%Heodo
2020-08-12Invoice U5214 674829434.docdoc 73dbd3589e2d0ca8f9f663da4f527cb110e5e29ce81026ff99cb0a24048fabc5Virustotal results 39.66%Heodo
2020-08-12Invoice_EK9_678043146.docdoc 20e50da77ca08d7ca03abcb2a21fd6f48c65fa35b3e18df925e9d1571c55ee4aVirustotal results 35.00%Heodo
2020-08-12Invoice_IBR7_472382742.docdoc d87649ae95488494c207932376d0c23a9c4b33b1cc2482b7aacfdddfaf9565b5Virustotal results 31.67%Heodo
2020-08-12Inv-8765-81017331.docdoc 5acefebbcc9a92b556c6f81e212c7db449fe2692e8877039dd7b6a920f8e5172Virustotal results 31.67%Heodo
2020-08-12INVOICE-QNJ36-6793479.docdoc 449f416c3f2657eb8b2df9c66efefcffdaa3528103658aa9e8de03e9197a666bVirustotal results 30.51%Heodo
2020-08-12Inv-J890-522428.docdoc 439856b7e650b1e0aaf08f0cc6068e5a0a096c029409e92659c4dd84b802eaadVirustotal results 32.20%Heodo
2020-08-12Inv_1899_20837653.docdoc 04c3ee92415cfafc302333e952bebc0d791a327e3227b22689726ff4de2357acn/aHeodo
2020-08-12invoice_JKT6949_9960730.docdoc f03c7d0d70435e0776be04c92e918456dca44144b09ac5b8e65a6269352e5e31Virustotal results 29.51%Heodo
2020-08-12Inv-NLUZ539-9530520.docdoc ba509a28def7c42418eb07fad9b3b9a48c8fa178ec6896c528ef6be0d80d93ean/aHeodo
2020-08-12InvGBF326174021.docdoc c0e57e90696fc7fc36202118e5d6bae3f85e480418d0f675369f61cd46850d5en/aHeodo
2020-08-12INVOICE-K7-76684704.docdoc 5c7a94ddcac5463f2e4ac7a23c60db15d0e5afb75700a346058936c24b461ac2Virustotal results 30.00%Heodo
2020-08-12invoice-BZPF5-711488.docdoc 2a97e9e0f718dd008bb234ef4503db810e7a2b4746ba6ae4cdef8951afa50d69Virustotal results 28.07%Heodo
2020-08-12InvCFZ77789507922.docdoc a7e3cd5c8c2cecc05432a46669c2f384a349f3a0cdbbd052d139215cd8ff457cVirustotal results 27.12%Heodo
2020-08-12invoice-CCIG074-2263955.docdoc aa93187017f9056d5cdc98302b5c41c322d54bdf3ce694c30d598140c4ab8ed6Virustotal results 29.31%Heodo
2020-08-12invoice B29 6724803.docdoc 280a50d04d643f96dc80e164116696ae77cf1e300a8b123d73f49078f304b9d4Virustotal results 29.31%Heodo
2020-08-12InvoiceAO074133525857.docdoc 32750365d68890d9071db244c4b3534a22dc90130e47ca9dfb21d81277678528Virustotal results 28.33%Heodo
2020-08-12Invoice-AHV4-75171359.docdoc 3878a507270346a9cb72ef10f715fea30a403ceb12326e565fcf4e03abb874edVirustotal results 27.12%Heodo
2020-08-12INVOICE-V5-16924988.docdoc b2e84b419102a803cc105b79ebf6eff76cd48550ff90fc089831be23ce838288Virustotal results 29.31%Heodo