URLhaus Database

You are currently viewing the URLhaus database entry for https://www.aistidafa.com/ar/cy8gh4k-payu-8166/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432803
URL: https://www.aistidafa.com/ar/cy8gh4k-payu-8166/
URL Status:Offline
Host: www.aistidafa.com
Date added:2020-08-14 04:17:04 UTC
Last online:2020-08-17 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-14 04:18:03 UTC to abuse{at}ripe[dot]net)
Takedown time:3 days, 15 hours, 23 minutes Bad (down since 2020-08-17 19:41:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15Invoice-K37-949042.docdoc b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421aVirustotal results 41.38%Heodo
2020-08-15INVOICE-QKVS27-7075145.docdoc 62832607fcefbef56ee871dd3ef7d35bb36d9b2837e62a50dc05ccac097c6b72Virustotal results 41.38%Heodo
2020-08-15invoice-UQ1-205244.docdoc 9b779c442f3460b404b04fd470d6529c0e3cc8e33a2879e274c11f72a1a8c356Virustotal results 40.68%Heodo
2020-08-15INVOICENE31457409263.docdoc 7eac275d360fda30d14d9fded388d7713439e0ef3eb5588f63341a4f6cc4f479Virustotal results 40.68%Heodo
2020-08-15Inv-YA064-700514039.docdoc 19b4201b455b36ccbd0e674b6028427d3d0494a20e5cc77b73f271081b812f29Virustotal results 40.35%Heodo
2020-08-15Invoice-K0440-660315599.docdoc 903b4b0dbf79ba01b1c8a324c887cf2e6e7ddff21d2cb2091ab77cbc6c13b467Virustotal results 40.68%Heodo
2020-08-15invoiceUKH6985050398.docdoc 6f7885a8876fa4d1cbc42c10aba9d34cb52a2965ef6b3927e8fd820da075660bn/aHeodo
2020-08-14invoice891271764763.docdoc 95cc5ce9259454f349e823d4c1e4c546a303dacfd17dd01c60af5f9dfb171cb6Virustotal results 36.21%Heodo
2020-08-14invoice-FYWJ993-051813.docdoc 91c79c2700e5e6e2b89cacab78340312b79127e8201a5d13ac61060f4d6160bcVirustotal results 37.29%Heodo
2020-08-14Inv-TIVT0-753598793.docdoc 3094c95131725d76223248c088e38463f85bca709c4b229e0e9c11814ddf672dVirustotal results 39.34%Heodo
2020-08-14Inv-G28-291451.docdoc 7d38ec42e6eb68452eba752c599430e99516bd8186f16dd2a57fe52e9d5a6d5aVirustotal results 30.51%Heodo
2020-08-14INVOICE-JRW3144-209392166.docdoc 992687ea5104d9edfd8bb61f97d9ffee393470c933c52a7a03678446db42bd64Virustotal results 31.67%Heodo
2020-08-14invoice-2781-75165049.docdoc 30a1ebc7ccadab73a1c6463cf44298031c3f083c146a97526e66aeb4f851e881Virustotal results 31.67%Heodo
2020-08-14INVOICE_SII4154_28825527.docdoc c2af257a8a40028722b621eec7a07631530b6ad0a75733f89eb70aad03b1e4b7Virustotal results 30.00%Heodo
2020-08-14Invoice E3407 403262.docdoc 936f0b1c957e1480cdba3c5cefac63730008c19b570d825bd0d6c6de85ca38b2Virustotal results 27.87%Heodo
2020-08-14invoice9529416537.docdoc a2cea9e0832fb379153f926fbb2d729495d30705dade851347f35fe2060519edVirustotal results 27.27%Heodo
2020-08-14INVOICE INTJ9 41208705.docdoc 6ab6bfb1af92d80a1d6d41f52257d7e1c85a2a18ccb782596f37d426ee600c24n/aHeodo
2020-08-14Inv ZWE0 210394240.docdoc 6805a810bcf466e80e587c1933e7d96d2e378735619324aa1ad6dc04d8173d68Virustotal results 26.67%Heodo
2020-08-14INVOICE267230946.docdoc 287b1c2cdc4b225da919062620fa3a273db58864387add5e91f642613c416075Virustotal results 25.00%Heodo
2020-08-14INVOICE_5_443799.docdoc 78933fecf248691aab0f40469c0dcd29e03ea9922aaf89b7cdc830b802cfa8a9Virustotal results 25.00%Heodo
2020-08-14Inv FZN669 9091112.docdoc 16551fc9c14cdf382cc5649b29fe015c8fade29c8165b9216226636d69bb2e22Virustotal results 25.00%Heodo
2020-08-14Invoice-0203-048161773.docdoc b580ef15f157d6c19b61810ddb5f085007685d55693d05cb54782cb52bac7e2bVirustotal results 24.14%Heodo
2020-08-14invoice_W8112_7975495.docdoc b491fec759260d8a1c9a3ae8ca946359d8abd506b683a71ee5a45fb91e170236Virustotal results 23.73%Heodo
2020-08-14Invoice-FLIO7406-936032.docdoc 2a7342691538ac359f25d6ccd05e6b81f64ea3dfb5fe8af5f23eb3f3425a056aVirustotal results 23.73%Heodo
2020-08-14Inv-J503-88727096.docdoc 101c35e8c776b8ae43e1a8703b8793462210ca7ed543c075d7fbe88796826773Virustotal results 24.59%Heodo
2020-08-14Inv-CCBE1695-260633017.docdoc f841c145c39f74c12260a67c686e4dde761614e633f204a3e68f47750f2e6d1fVirustotal results 24.59%Heodo
2020-08-14INVOICE-WNU6180-48936716.docdoc b873855abe6ecb687a4df753ed5f4882475ca551c53ffc20ef18b3c896115a91Virustotal results 23.73%Heodo
2020-08-14InvoiceSHJX1312675119.docdoc 538aec1c87a88d78a75a417c253579be5fa18cefce592109122505cf70f2eea9Virustotal results 40.68%Heodo
2020-08-14Invoice_RE0174_5806293.docdoc fb17807621969c33d345882ad5ae95cd5294c32509e13a6fe8ce1d317a5c3f4dVirustotal results 38.60% Heodo
2020-08-14Inv-Q7-9527885.docdoc 3132acbb0aa02f175f2e8bf589a53e732564cf73f1f003cb64c842ba52d3c889Virustotal results 41.67% Heodo
2020-08-14INVOICE-OPGR74-417992.docdoc 845f584a4b58e05f5eabb64041142baac8b97a971f88d4cb2544c4ac3af97a3aVirustotal results 40.00%Heodo
2020-08-14INVOICEWWKS95850822.docdoc 382eeb05e0b37509916697e88d5f58e00cfd17db07cf9b27240fd84aa4bcd26eVirustotal results 40.00%Heodo
2020-08-14invoice-IPCG083-586130328.docdoc 4156fe5a204dbbd2086b1c71f40ced2d03b723dfbbf218927b71ad2b2fb369c6Virustotal results 38.98%Heodo
2020-08-14INVOICE_B7_64986088.docdoc c257cd4e52104d35aad4c65319a54abf3cbea3929e1fd295bff5fe422409618eVirustotal results 38.98%Heodo