URLhaus Database

You are currently viewing the URLhaus database entry for https://aistidafa.com/ar/cy8gh4k-payu-8166/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:433141
URL: https://aistidafa.com/ar/cy8gh4k-payu-8166/
URL Status:Offline
Host: aistidafa.com
Date added:2020-08-14 11:40:08 UTC
Last online:2020-08-17 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-14 11:42:02 UTC to abuse{at}ripe[dot]net)
Takedown time:3 days, 7 hours, 59 minutes Bad (down since 2020-08-17 19:41:06 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15Invoice-K37-949042.docdoc b9d2bc9624f1e81b007fd1d89170294eb6eb29c779f83f4e75576a0fa3fa421aVirustotal results 41.38%Heodo
2020-08-15INVOICE-QKVS27-7075145.docdoc 62832607fcefbef56ee871dd3ef7d35bb36d9b2837e62a50dc05ccac097c6b72Virustotal results 41.38%Heodo
2020-08-15invoice-UQ1-205244.docdoc 9b779c442f3460b404b04fd470d6529c0e3cc8e33a2879e274c11f72a1a8c356Virustotal results 40.68%Heodo
2020-08-15INVOICENE31457409263.docdoc 7eac275d360fda30d14d9fded388d7713439e0ef3eb5588f63341a4f6cc4f479Virustotal results 40.68%Heodo
2020-08-15Inv-YA064-700514039.docdoc 19b4201b455b36ccbd0e674b6028427d3d0494a20e5cc77b73f271081b812f29Virustotal results 40.35%Heodo
2020-08-15Invoice-K0440-660315599.docdoc 903b4b0dbf79ba01b1c8a324c887cf2e6e7ddff21d2cb2091ab77cbc6c13b467Virustotal results 40.68%Heodo
2020-08-15invoiceUKH6985050398.docdoc 6f7885a8876fa4d1cbc42c10aba9d34cb52a2965ef6b3927e8fd820da075660bn/aHeodo
2020-08-14invoice891271764763.docdoc 95cc5ce9259454f349e823d4c1e4c546a303dacfd17dd01c60af5f9dfb171cb6Virustotal results 36.21%Heodo
2020-08-14Invoice-SBB1-783224016.docdoc f63cf892be860fdaa9344fa756d261c0d729aa1944f58cf75a780cb92b639f4aVirustotal results 37.29%Heodo
2020-08-14Inv-TIVT0-753598793.docdoc 3094c95131725d76223248c088e38463f85bca709c4b229e0e9c11814ddf672dVirustotal results 39.34%Heodo
2020-08-14Inv-G28-291451.docdoc 7d38ec42e6eb68452eba752c599430e99516bd8186f16dd2a57fe52e9d5a6d5aVirustotal results 30.51%Heodo
2020-08-14INVOICE-JRW3144-209392166.docdoc 992687ea5104d9edfd8bb61f97d9ffee393470c933c52a7a03678446db42bd64Virustotal results 31.67%Heodo
2020-08-14invoice-2781-75165049.docdoc 30a1ebc7ccadab73a1c6463cf44298031c3f083c146a97526e66aeb4f851e881Virustotal results 31.67%Heodo
2020-08-14INVOICE_SII4154_28825527.docdoc c2af257a8a40028722b621eec7a07631530b6ad0a75733f89eb70aad03b1e4b7Virustotal results 30.00%Heodo
2020-08-14Invoice E3407 403262.docdoc 936f0b1c957e1480cdba3c5cefac63730008c19b570d825bd0d6c6de85ca38b2Virustotal results 27.87%Heodo
2020-08-14invoice9529416537.docdoc a2cea9e0832fb379153f926fbb2d729495d30705dade851347f35fe2060519edVirustotal results 27.27%Heodo
2020-08-14Invoice-QSXH4-4134859.docdoc 104251c4ce5ddfa9732871b3478c81882c4e2544e2f2b615ee7e05a6c4c35b0cVirustotal results 26.67%Heodo
2020-08-14Inv ZWE0 210394240.docdoc 6805a810bcf466e80e587c1933e7d96d2e378735619324aa1ad6dc04d8173d68Virustotal results 26.67%Heodo
2020-08-14INVOICE267230946.docdoc 287b1c2cdc4b225da919062620fa3a273db58864387add5e91f642613c416075Virustotal results 25.00%Heodo
2020-08-14invoice_XOJ550_341982113.docdoc 7fd083f3133fd46bf7f6a70c043bcd84de058c8b12d8fc72e503b95851fcc20bVirustotal results 26.23%Heodo