URLhaus Database

You are currently viewing the URLhaus database entry for http://josegene.com/theme/lGnxON/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431837
URL: http://josegene.com/theme/lGnxON/
URL Status:Offline
Host: josegene.com
Date added:2020-08-13 11:43:21 UTC
Last online:2021-06-04 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 11:44:03 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:9 months, 24 days, 22 hours, 17 minutes Bad (down since 2021-06-04 10:01:43 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14INVOICEV046880928256.docdoc 0a113fe937499c36099951c617841d7ac21c77a953e277ce6ee04023944a1ebfVirustotal results 40.00%Heodo
2020-08-14Invoice-698-54666366.docdoc 3d8831fa48eda1b1975a84cde54f8775ceecc95fa6ae4278a9ee533cf37d9d8fVirustotal results 38.98%Heodo
2020-08-14INVOICE VDZ188 6333987.docdoc 8b725e5a090dcb30815c5df978e72af9a04372b9fda6729678004e9bdd617ce6Virustotal results 38.33%Heodo
2020-08-14invoice ZA2 05126212.docdoc 2da551517d3d24f3485bb7c1edd4dc79031582d5cc3f4066169ecdbe26b4df18Virustotal results 36.67%Heodo
2020-08-14InvAVG24711745634.docdoc ebfd94ac1cb7510d9b3fe2de38c88bb88d64956d0c6eb93aceebee8ea83ac763Virustotal results 37.93%Heodo
2020-08-14Invoice ZVI3 197290027.docdoc 4398bc31070f761b318b30f297d363b006ed9e84c6af0aa45ad140f57e7c1529Virustotal results 37.29%Heodo
2020-08-14INVOICE_XCZ1805_686961682.docdoc e8516c23d1aec8faadd52ae68fd240339940d05f4a1db7c56afdbec1eb5de0f6Virustotal results 37.70%Heodo
2020-08-14INVOICE RMG0 62160755.docdoc f9d386ef77ac7b75fa5d24fedcf07b054c6e35682826e1a38a6e908dc8c77e10Virustotal results 36.67%Heodo
2020-08-13Inv_692_74993415.docdoc 2f955001e3dac3ecffeb44a715528d697945545d1093516a8b07523859e79d82Virustotal results 36.67%Heodo
2020-08-13INVOICE GSKM39 001088.docdoc 5f082300c48965f84f8c991027f6081c4397825021b74021b253c7fc7e9dd5b3Virustotal results 35.00%Heodo
2020-08-13Inv-XXY4469-871764165.docdoc a9828c026e45fa8a82d75ec9ad78970c1e5664d13306a3b4e5b501450fa97e9eVirustotal results 36.67%Heodo
2020-08-13Inv_114_020155.docdoc e1ac6201887f008a8beef8eca74076739b93dacf2d0d366f3329ca55dbc3c827Virustotal results 36.07%Heodo
2020-08-13invoice-SPFW2-987698256.docdoc ab444b6b4e01751a504bcbe5bfafccb6c73c5a8f0a83102badfdfa7f0d061be7Virustotal results 35.00%Heodo
2020-08-13Invoice J8013 5919865.docdoc 49d66f1859784a289e46f5690a521c15cb397cb29ad8db6882806c03628a4b97Virustotal results 35.59%Heodo
2020-08-13invoice-46-817169.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13invoiceXQ882701262.docdoc 76430c64d6d3cd144fb33a546e278e5558d3ae2083365596b14840bdde404b2eVirustotal results 35.59%Heodo
2020-08-13invoice_55_032659367.docdoc 894dfe7d84439530c0f7bdca76e92f6d9ff10fe2121e0ff8decfea3153f5e91fVirustotal results 35.00%Heodo
2020-08-13InvoiceG067617960596.docdoc 13c5ae01cdc3cf5c65ba0aa57e43e885848516ba544fdc422e8c16122b98481aVirustotal results 32.20%Heodo
2020-08-13Inv-FVS440-54105938.docdoc b38d736d513ae70545b3d388dbbf8e9e327be6276a22fb4e10422991f08dd1d7n/aHeodo
2020-08-13InvZXC06562159707.docdoc 55260af4daec42317640803be79c9cb42f198db5c6194b7346c7c95c610f70f7Virustotal results 32.79%Heodo
2020-08-13INVOICE F14 97131312.docdoc 56af09db56d209f8011606b414163770dd7581a225f2a5ea8c16eb6be6afd035Virustotal results 30.00%Heodo
2020-08-13Inv 4880 1036906.docdoc e72282cf5896d2a6649446f6023b34c7d71ba08f5be3bb0def9185fa742c3deaVirustotal results 30.00%Heodo
2020-08-13invoice 84 927207.docdoc b4bb0ed99478a7910267de0a8b83d95d21e41f8104509a278fd52affedaeb887Virustotal results 28.33%Heodo
2020-08-13invoice-76-6419761.docdoc 002e4e23a241c1fa930bf374dd4e1c871a0f19a6abb1fe7e34e0a7dd479a0744Virustotal results 28.33%Heodo
2020-08-13invoiceU7936987802.docdoc 938e03ff3d361fa26c00218160d0ef65786280283d80678e729a73ea503e0d95Virustotal results 28.33%Heodo
2020-08-13Inv_NS1_783108.docdoc 52c981dcee0a9c0bc80ec192b453e8af6b01ced6cb3187645687ad0fd1b13221Virustotal results 27.87%Heodo
2020-08-13INVOICE QV1 41427476.docdoc 06166b3489e6b1ba8b3b7abbedf9fa72a55fc82e560c856df36cc781c2470e4bVirustotal results 26.67%Heodo
2020-08-13INVOICE-PXPB2-064412.docdoc eeb469414b6509fdd0d204f306b29d55021e2de94608991794b5f59c2add1e07Virustotal results 26.67%Heodo
2020-08-13INVOICE-U4999-36181396.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13Invoice-TIBX760-692229489.docdoc d2cc4f61f498dbddde048bbb918416d73f063a0bb46c960ab7fd6fe671ed9bd1Virustotal results 25.42%Heodo
2020-08-13invoice-MGB7-288309.docdoc 549d4559782f6c11783867db78579ca723c90e7e4399b952fa14de9aa84d1bceVirustotal results 26.67%Heodo