URLhaus Database

You are currently viewing the URLhaus database entry for http://antislash.fr/icones/add/css/payment/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431275
URL: http://antislash.fr/icones/add/css/payment/
URL Status:Offline
Host: antislash.fr
Date added:2020-08-12 21:09:33 UTC
Last online:2020-08-13 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-12 21:10:03 UTC to abuse{at}ovh[dot]net)
Takedown time:15 hours, 0 minutes Good (down since 2020-08-13 12:10:56 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13DOC_2600842933624458627649.docdoc 0c4015de45653ee2f8fc6e338461a2377e14139b1ff879df5a2fe1d3c200a15eVirustotal results 28.33%Heodo
2020-08-13J_09239734.docdoc 33dcad34dd7bf732f89c6d54880f01b2f952fd6f08f89062109af185e73d0e22Virustotal results 27.12%Heodo
2020-08-13PO_08132020EX.docdoc 57077fbea2ccbc5464be5b94b7e01a59f4b28e6658a7a432645380f6413e8a00Virustotal results 27.12%Heodo
2020-08-1357419399804893870.docdoc 3f9f641892bac263ede86f11632b4a6498dcc2b94b13727c5dc8c8c594e0f608Virustotal results 27.59%Heodo
2020-08-1324608812.docdoc 30aceb60d6841a0f444bf36dbf53b021d32f7c1494c42f2c8600c6ea1b84909eVirustotal results 26.67%Heodo
2020-08-13DOC_II6238760920YS.docdoc 1ac4188f22c717e76b493881ab12ef60e719cb86d2e5289f743b42b338cb5b96Virustotal results 27.12%Heodo
2020-08-13QOT_THRQE6PDYH.docdoc 9806f54f8d2769646e6a9caee3f1c15a1b47f781be6eef64c390d6e9ee867bd4Virustotal results 26.67%Heodo
2020-08-13INV_14763471.docdoc fdd5654b78c6c5c23b4f6c6502eb69701c87c65ad4bd2d121046db883154d863Virustotal results 27.12%Heodo
2020-08-13PO_08132020EX.docdoc ba510b5a0f97430a09efbd12acbb4c1be869e71e678adf5fa0b5498fb477068eVirustotal results 28.33%Heodo
2020-08-13INV_16609588.docdoc f3288815441008b2291c6b17d597d58fe606f7475c4641bacba49ad56c1b1142n/aHeodo
2020-08-13INV_31436924933403272431751.docdoc 5d05496cf28924d44375333ce8c68c5919abc9cc35ba4e8c9a35d02ea07cf5c0n/aHeodo
2020-08-13Q_PO_08132020EX.docdoc 0938a3eb8d86fa634cbaa1f643bd2c6cafcdacba202e4683cf7245705bd11fb3Virustotal results 53.33%Heodo
2020-08-13NB_XE6075692663YE.docdoc c2bb5e128810c06abd15ad3ef0bc95622c20da154ca500892972305c94feabedVirustotal results 52.54%Heodo
2020-08-13X_ZA3873470977BZ.docdoc 294dc4d0897b43e65d8e7c4ab761281fae2d7ff62a16dd47e9b7731019ed0c21Virustotal results 53.33%Heodo
2020-08-13Y_ZFT_080120_DCM_081320.docdoc 2ec1025c3a44b35de74853b22998ea439d6eb5f0d92d9065256692f0deadcbd9Virustotal results 51.67%Heodo
2020-08-12WNL_080120_MUN_081320.docdoc a9af06ae735677ec282b4a66f7bc85a343dc7c71491658673fed6150e05ef3c5Virustotal results 50.85%Heodo
2020-08-1218600160194529630025.docdoc e9bbc3d987e57144a6554ea1c30a527af2db5a40b2c12e9fa6b28a79ea2afb3aVirustotal results 49.15%Heodo
2020-08-12FILE_THTCDA3T.docdoc 77b30bd340e5190b08a7d94df99aa81a4aed0b89711a543fa9f87bb83fe3a72fVirustotal results 50.00%Heodo
2020-08-12PO_08132020EX.docdoc 82731bed2f8975cba99daa1653d3d4f132897f11940e17776809a911ea03a0d9n/aHeodo