URLhaus Database

You are currently viewing the URLhaus database entry for https://www.cebucoolstuff.com/image/ERNUjg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431313
URL: https://www.cebucoolstuff.com/image/ERNUjg/
URL Status:Offline
Host: www.cebucoolstuff.com
Date added:2020-08-12 22:25:14 UTC
Last online:2020-11-09 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 22:26:02 UTC to abuse{at}syn[dot]one)
Takedown time:2 months, 28 days, 22 hours, 27 minutes Bad (down since 2020-11-09 20:53:33 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19Invoice718473735.docdoc 505a42acf4e4f40f5b3faa924a4ce617ffbaa08a4207f027bd3481ead780ea09Virustotal results 59.32%Heodo
2020-08-14invoice-UL6-18556946.docdoc bef80c676faefc196703bfb61cf9459a8d09946d366edffa5810dcf3345f927eVirustotal results 38.98%Heodo
2020-08-14INVOICE_Y1_401845.docdoc dbc3f242e959a4c3398cc0676dacb940b4253a18f4a2be2d3a1aebb7c1f62d74Virustotal results 39.34%Heodo
2020-08-14InvCO3739074784.docdoc 854fcd9b34f74cfd7956a1bfd5de137afaa0c79aa3e1e80ccc4f87410e0e6159Virustotal results 40.00%Heodo
2020-08-14INVOICE-GED536-169040267.docdoc d77766273a903661def8286676499fd3cf8f2a337cd8fa867e5788e5509db0e6Virustotal results 40.00%Heodo
2020-08-14Inv-E2-9333622.docdoc 8b725e5a090dcb30815c5df978e72af9a04372b9fda6729678004e9bdd617ce6Virustotal results 38.33%Heodo
2020-08-14invoice_BCX6_54011173.docdoc f740ad05fe75e146443ce0776602fc5828a534f28e1e2f34a1d785083de85bd1Virustotal results 38.60%Heodo
2020-08-14INVOICE-ED1486-169888235.docdoc 167459762dfa748a07ae8e4d2479e9733ad4d66e0d833453daa2038e833efa29n/aHeodo
2020-08-14invoice-H887-904005.docdoc 3c0a2f5c58b9874a2167dd0d6cf544f4ebeaa0fac9dc4d375d41f80cb8dffc83Virustotal results 37.70%Heodo
2020-08-14Invoice_K672_76664114.docdoc 60f8488fdb7df1654b540cffa5a6b15006c90ab03e4cfbc618d7594c813c252dVirustotal results 36.67%Heodo
2020-08-14INVOICE-ZNQ5196-091693988.docdoc 2879a9d705300779c0269f3a6847fb725a3564c7ae27f44226fe17f422474ca3Virustotal results 36.67%Heodo
2020-08-14Inv80800049978.docdoc 532d6be9513e3dea9cfb7040d4e2b0878429f90b84e8c3229ba775ff99dcfbbcVirustotal results 37.29%Heodo
2020-08-13Inv-XE7967-84735277.docdoc 3c2103ec1e6af0ce039524d58d70a4ced5e2845549def894d03f836978afa09dVirustotal results 38.98%Heodo
2020-08-13Inv2117219179.docdoc 3eb6b088630e12b4b89f3af4f5b1366626605adddd5d7d447d1b4b8246d305bcVirustotal results 36.67%Heodo
2020-08-13Invoice_GO716_4825623.docdoc 88d310c1de24f5a780b5269aeff8f47a6715c4fcc531df6ad2e8b2fce834773bVirustotal results 35.00%Heodo
2020-08-13invoice-FHP652-731155.docdoc e1ac6201887f008a8beef8eca74076739b93dacf2d0d366f3329ca55dbc3c827Virustotal results 36.07%Heodo
2020-08-13InvMJDO3408863.docdoc 0dd2a96118f23f2fec5549ff2bbfbda83f954a2522474688ae8db5a35a84942dVirustotal results 35.00%Heodo
2020-08-13invoice_JU7_3896406.docdoc 5afd28f4c27929a5271720ade77b26422b7596600473f76d9aca778869203bacVirustotal results 36.21%Heodo
2020-08-13invoice_6349_552905327.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13Inv-N197-7789915.docdoc efd5ba3aef6a5b7efdf02bba779391cf010ad01d68be10642219e412a940797fVirustotal results 36.21%Heodo
2020-08-13Inv_8_625347519.docdoc bb480394e0201866ae43a5b60c1ec371e3dd37a01e922a8dd5ff68d8cb325f3eVirustotal results 38.33%Heodo
2020-08-13Invoice-AYCR522-2429357.docdoc 914f075f63c72c28b526dd4ec4fe89554283220e19930bc7a071e25d5e0dd256Virustotal results 37.50%Heodo
2020-08-13invoice-A7-717458.docdoc 17c0ad7fe3012db3c5ada59ba1d21436aa344ab57a37ce699684f8bbead66de0Virustotal results 33.33%Heodo
2020-08-13invoice-YL14-88388362.docdoc ecab54e301b452142ecc261b2329b5603222fdd66c4785aaee3b0a1e54373879Virustotal results 32.79%Heodo
2020-08-13Inv_HKM37_306486.docdoc 88face3f5c64a159d93d81009170415aa7ef5b594d942b26c795d458d5a4dfd9Virustotal results 32.20%Heodo
2020-08-13InvoicePZD11392891473.docdoc 53012447056c43d98e67bc063b1016fc1330216796dcc7c1eaed32a4aa02b45cVirustotal results 31.67%Heodo
2020-08-13Invoice1457127119321.docdoc f01b78ca95efc7717c3d0f03f4d904cbbb4d3c5dc0ce87e33fd19acde30cf5d5Virustotal results 28.33%Heodo
2020-08-13Invoice_YJBR9266_509030046.docdoc 002e4e23a241c1fa930bf374dd4e1c871a0f19a6abb1fe7e34e0a7dd479a0744Virustotal results 28.33%Heodo
2020-08-13Invoice-2830-755864.docdoc 43911a79aeb74fd3a33a725d3ccbb05e5e86c849166f578f3404711fa0bf5b42n/aHeodo
2020-08-13Invoice_DDK82_724084.docdoc bd24e35406ae73f24ce2429c9c4f8b1badc523308a416c6125179767a924e4d3Virustotal results 28.33%Heodo
2020-08-13invoice_FUR24_887253.docdoc ec1d8db770842d2aa815d796d9ca7b59b1a84ffb342060081768bdecf7025cbfn/aHeodo
2020-08-13Invoice_2710_470412287.docdoc 0788345123fc7f3460c0083d4673ef0ffa96d196986939471d1b13ab63dd5b71Virustotal results 25.42%Heodo
2020-08-13invoiceQ1382197948.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13Inv-ISI95-219365.docdoc 86c0cc8d6327a374689e50a0d8bc139919ce31d297cce113a4e93bd78b8cd8a0Virustotal results 26.67%Heodo
2020-08-13Invoice-VVHN613-0860613.docdoc 776396c0aa0fac10eb849a713ca7927a00cd7aa654be032e870fa7cbe3076078Virustotal results 26.67%Heodo
2020-08-13Invoice_43_1619094.docdoc d22eb2573f777153ddd035f4b8ba8b83c452f150ee71bb9e2dc95a0036794c46Virustotal results 25.86%Heodo
2020-08-13Inv-7672-8113352.docdoc e9fe379c503723a5883c5b4b3e4227a3a35c0fd4cec4716f859a2f981f6eb732Virustotal results 26.23%Heodo
2020-08-13Inv-763-6896507.docdoc 24fe0e4704e8906e4819aaf88915317509beef8a6bd0abc3c4933cd0d75b7084Virustotal results 26.67%Heodo
2020-08-13Inv SK25 13888052.docdoc 620d84fae4b584f528eb0044177ac950380d8c41d764dc1615871a80ecdc4ae7Virustotal results 25.00%Heodo
2020-08-13Invoice-TKFR5415-42684615.docdoc 0cab070d00fe082504fdc13ea0398dee0f4dd71f4d3b296c8de086abde57a87dVirustotal results 25.00%Heodo
2020-08-13Invoice-B9170-23239929.docdoc b6e322f9859749fc8f883d8e46bd164f9b3b406ab9978f5c1daa1ad43325d492Virustotal results 27.12%Heodo
2020-08-13INVOICE_44_617327004.docdoc e1b7a11726c385bcad71dfe791b165802cc625ceaf2f1550a5a10f5f222ea90dVirustotal results 51.67%Heodo
2020-08-13INVOICE MXL172 238812.docdoc 10531f315432369a9c0706bc00ac1405445316044a9ec07b03de6606a6a9f9fbVirustotal results 55.00%Heodo
2020-08-13invoice RRR6 1242328.docdoc 04f398e872a21555e613068343a42ae713930a96f16f079aba07a4434b800180Virustotal results 54.24%Heodo
2020-08-13Inv-612-9505203.docdoc fddf4cab73e6e2ff5c40c7fee09d52d5eb903e6bd17ad77aa292c6ded707f394Virustotal results 55.00%Heodo
2020-08-13Invoice_H765_4469757.docdoc 015990746f332cc1ad898d46ef3de53f4ffc95d723ccd19bea5fc12b95f86b47n/aHeodo
2020-08-13Inv-BVV4237-287357.docdoc 97e52709f1f9169fb2a3d0cfc7852f811d067999ed1bdc700c6b66bc7dc23765Virustotal results 52.54%Heodo
2020-08-13Inv_IWBQ55_597430509.docdoc ee1f5c8ab512406824b28cd257477afae1af144286ddd585d142664b10b2ec77Virustotal results 50.85%Heodo
2020-08-12INVOICEIGM97930932925.docdoc b858572fbe695215c2aa6ade7ada24c980392ad2f5c9e3564d4e6446ef424383Virustotal results 51.67%Heodo
2020-08-12INVOICEM6766905080.docdoc 9b5d7e0c6ce7b00011f1c9fa7157bded3963629b18e4b79469bb62c84e80a312Virustotal results 51.67%Heodo
2020-08-12INVOICE 2 97787468.docdoc 0142e67cedc1565568304304b17edd520644a742fcaf93c6fe3fe8b2fb6476b0Virustotal results 50.00%Heodo