URLhaus Database

You are currently viewing the URLhaus database entry for https://winnerswin.us/ysrkcp/iwio1aty-oh1a-20061/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:430584
URL: https://winnerswin.us/ysrkcp/iwio1aty-oh1a-20061/
URL Status:Offline
Host: winnerswin.us
Date added:2020-08-12 15:55:50 UTC
Last online:2020-08-12 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002865119 created on 2020-08-12 15:56:10 UTC)
Takedown time:6 hours, 57 minutes Good (down since 2020-08-12 22:53:23 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12invoice_P45_180444.docdoc fb474008a44d536948b71f933bfc0289e7779352c43c4d62f0b3dff8f0ae478dVirustotal results 49.15%Heodo
2020-08-12INVOICE_370_81851221.docdoc 27f5a6d1c03ee22b1c20250a5cf13fc46584715e452dc107d3f7263371a96809Virustotal results 48.33%Heodo
2020-08-12invoice-1584-47328142.docdoc da25968d18d6c8ddfd6ffa940b4e0bc6809a5b1a224602f196ce7eb107578f88n/aHeodo
2020-08-12invoice_718_236678637.docdoc 0c7d085dc88b57e56819a0a9319e1aa089ad9851a0ea21137aab6309395ed039Virustotal results 49.15%Heodo
2020-08-12Invoice E97 7103453.docdoc dcaa5f28e69731be4dd507c5b31f0594b585d516edbaef3db061890462c383d5Virustotal results 48.33%Heodo
2020-08-12Invoice-SGG4-25856226.docdoc d1ce5170f24fdb09f187ca0e3e0f6e689fa2c73fc6953ff18ecc123bb8eed49cVirustotal results 50.00%Heodo
2020-08-12INVOICE_F1241_319136.docdoc bbf084bcd83d08a6693798f851e3af34cc7c303afb235c8c25fe237ec00315cbVirustotal results 48.33%Heodo
2020-08-12INVOICEH273059776409.docdoc 7cb03d988c912a877410fe03d55bdc4a5379a95e91ff6497875a139105f2cfdan/aHeodo
2020-08-12invoice98279158381.docdoc cd110e81c2ab80786c6b50fa2f567bd93e1471529d849677f100974715c14621n/aHeodo
2020-08-12INVOICE-CQK53-2505391.docdoc 37a1c85950d3e91662ed4137488030ffcec13adad6f9b2f3eea1de01a756b260Virustotal results 41.67%Heodo
2020-08-12INVOICE-S6103-0061955.docdoc 73dbd3589e2d0ca8f9f663da4f527cb110e5e29ce81026ff99cb0a24048fabc5n/aHeodo
2020-08-12Invoice-N129-620926.docdoc b2699f3cd54b6953a3eb9e1812890cf40563699a96776cfacd8f81288e962e11Virustotal results 31.67%Heodo