URLhaus Database

You are currently viewing the URLhaus database entry for https://cosmilayplay.com/redescent/LLC/9m5utu31sm-00055/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437201
URL: https://cosmilayplay.com/redescent/LLC/9m5utu31sm-00055/
URL Status:Offline
Host: cosmilayplay.com
Date added:2020-08-20 11:05:23 UTC
Last online:2020-08-21 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-20 11:06:11 UTC to noc{at}interconnects[dot]net)
Takedown time:18 hours, 50 minutes Good (down since 2020-08-21 05:56:43 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20Inv. 089973.docdoc ae09a760faec9e5c8f9d147329271cb1fa3971b119943d8cc9e16ce71c8e5fd3Virustotal results 25.00%Heodo
2020-08-20I7 invoicing.docdoc e3b9adfab9f86293c439dc64a2392bdf6645cd200616eb185bc3c8fa23cb0839Virustotal results 24.14%Heodo
2020-08-20INV_57503.docdoc 722219128e30ae7a17fbcf0d24147c7713f628e28f3af2117130c95e0d75005dVirustotal results 22.03%Heodo
2020-08-20invoice.docdoc e443378d873265488a567b773f21b158d57af083c5cc445816d2614bab276bdbn/a Heodo
2020-08-20August invoice.docdoc fb7cec2bb2ac4c31c65e299f198a586f5c5918f975075467063f59d48d28844bVirustotal results 22.03%Heodo
2020-08-20P045 invoicing.docdoc b98c8587312b2674ec04ec4c3cccd572e53475f8c51922bf5418d51f07b006b5n/aHeodo
2020-08-20005599716.docdoc a30ffa09da50e6ffb80090c9fe05d7fb06d7d9731bc5846021dbf64334df1a63n/aHeodo