URLhaus Database

You are currently viewing the URLhaus database entry for http://watersdesigns.com/lucaswaters.com/oxx0yod3uj-0911/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437458
URL: http://watersdesigns.com/lucaswaters.com/oxx0yod3uj-0911/
URL Status:Offline
Host: watersdesigns.com
Date added:2020-08-20 20:12:14 UTC
Last online:2020-08-27 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-20 20:14:02 UTC to abuse{at}liquidweb[dot]com)
Takedown time:6 days, 16 hours, 14 minutes Bad (down since 2020-08-27 12:28:49 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-22Inv. 0589473.docdoc d264878eae29d3da022f38e67a38560346ba42cbb6dbebbf0e6c852c666fb1acn/aHeodo
2020-08-22QMP-080120 HEYT-082220.docdoc 6f6e1037eabcdd4495abaec04471ac97398c57eb88493b324e2d89ad9bd7af08n/aHeodo
2020-08-22INV #9626 FOR PO #004522059.docdoc 564105a864ba17349c0c70d8c11883b4edaf7b9f653bc074d57ec92e33923d61Virustotal results 36.21%Heodo
2020-08-22P0841528586JC.docdoc 5d343c4cc60ceae7c55758376842b90845f6d3dd1d7ab8fd2bed44ee745bf527Virustotal results 37.93%Heodo
2020-08-22Invoice 0617825.docdoc 88fafca4b3195bc1843721aa1d78221a5d05be8d88f43ceb0e85aab917c67a43Virustotal results 36.21%Heodo
2020-08-22Payment.docdoc b199113c89d1f14f205054c9a7cce7b661199224054e035b6f5044205dc27cf8n/aHeodo
2020-08-21invoice #08808.docdoc d09a4703239b8dd258d5174bc65647fa6b951cecfcb7c2f9c46a29a061a7a769Virustotal results 36.84%Heodo
2020-08-21INV #00500966 FOR PO #856369412.docdoc 31ef2257cdb7b9006892fb9754673511beaf648f6c3a899b9bff3031310a9acfVirustotal results 37.50%Heodo
2020-08-21O-080120 DHYX-082220.docdoc c7abec97a993780d8d6bdd8fbc2a7c77bb49fdd61e57637ac36ecefc9f748350Virustotal results 35.59%Heodo
2020-08-21Inv. 006343048.docdoc 2d4370eba117c88617870ab941572195d2facde4eb4e1d768507d37840812da2Virustotal results 33.33%Heodo
2020-08-21INV #0739 FOR PO #20006032266.docdoc e5c9f8c0ccfa47835d30be512636ad1b0e40d75587d5a309f586b67796aae5cdVirustotal results 33.33%Heodo
2020-08-21invoice #805571.docdoc df8d09457a129b57c4740b237ac226b0e0245d035dc20930563bab681e98e8c9n/aHeodo
2020-08-21invoice #0077.docdoc 43057d3c74a6fbe3be2660879e861ae3d0b2118866abb1e3fe8bc169c526d957Virustotal results 32.76%Heodo
2020-08-21PO# 08222020.docdoc 214116ae52ad96af88fa41e0ea271fecb493e2afbc403bc3ca2c184ffd03d996Virustotal results 32.76%Heodo
2020-08-21Inv. 077193088.docdoc d594bcea91f0259160c0122a56ad8ec4a7896173295fb3b2c197781cb1bbfddcn/aHeodo
2020-08-21form.docdoc 83e013279f45dc89d5efc3717634b746a611baee472756272e91e1673d8fc3efVirustotal results 32.14%Heodo
2020-08-21form.docdoc b99da0701a16d0df2895790bf84db62ee0da6b42fa8ea0c2a5b103a131d98f13n/aHeodo
2020-08-21INV_3981.docdoc 2722912646668099c2c0bca95e61e654df8a201fd127ecb8ae5d6ba79299768fVirustotal results 25.42%Heodo
2020-08-21INV_4080.docdoc 43638c344ac4a446af722c229682fee9a8434923ce1cf6dd1a19bd2a0fc78c21Virustotal results 25.86%Heodo
2020-08-21Inv. 003434507730.docdoc ed0a6eec86f44151f9815362fdc3c778a7f176378e582bfaf012098d9b98454cVirustotal results 25.86%Heodo
2020-08-21form.docdoc 9c3f81236f7fcb19d6e1304ad6c89255461a66f783e372f62c8fc93fa4bfcd8eVirustotal results 25.86%Heodo
2020-08-21invoice.docdoc fa793702b351ab1f22fa5ff1d20c7f6bf822bd6954f637389577767a163275bdVirustotal results 25.86%Heodo
2020-08-21invoice #39468.docdoc cafc557261c0f9e0e43f24e43efbf14505b54d38271152c48e4a6dd3279769c7n/aHeodo
2020-08-21August Invoice.docdoc 78a36b1f41b0c09c31d6bc4665036ff311e872b98404bb726312e26f0d559803n/aHeodo
2020-08-2109769879.docdoc c6c8fb9bb0d155bb4fe8b4b7904de586efbf5c79f49877313b380b848ad12da1Virustotal results 27.12%Heodo
2020-08-21form.docdoc fa73c7c4709f00943c0995e1c8b64edce7bd0443e3a2fa1c4940c978d35fa794Virustotal results 23.33%Heodo
2020-08-21invoice.docdoc 2ce951fdd23668dc604d3edaaa4e54fa607e9bdf62e6d471a60ec5671ac4b9a3Virustotal results 22.81%Heodo
2020-08-21Invoice.docdoc 1b0e2d810c06da0602e0fdc4a558ebf38c6fe9c8d2caf30fbbb4d364dcafcde8Virustotal results 22.81%Heodo
2020-08-21form.docdoc abedafc5e19de68937c53f7be30c1b392975062ba9a11d34a991ca703cd3c578n/aHeodo
2020-08-21Electronic form.docdoc c50a12add2e3c75f860f563d042901761cb7ec0a2f4fa64ddc37c1dbbef8bbcan/aHeodo
2020-08-21August invoice.docdoc 69eab92915bca8074c0e4c4a14a6d4532a6d4162923b7c51799ae872c647ee21Virustotal results 21.05%Heodo
2020-08-21invoice.docdoc ddfe19c0868dbcc62ac11535a2524a1e0abf358fb590402aab5e2e1b08622d10Virustotal results 20.69%Heodo
2020-08-21Electronic form.docdoc 6f69eecc69ca89716c536b2effc57f04fe5739e38fcb08dcce20d16efa1d382eVirustotal results 20.69%Heodo
2020-08-21August invoice.docdoc 119ea90f9ae4392e35ad517dbab4465ac0f0ae12cb58b0e85f007e105bb91036Virustotal results 21.05%Heodo
2020-08-21PO# 08212020.docdoc 4da5e980866878da930be670800361fd6b9b6ec73983dd60cdba9eb29bd09ab6Virustotal results 22.03%Heodo
2020-08-21invoice #83204.docdoc 911b82b7e7f4b3e7d11029d69ecb024c9070715bc97aee8a642c26b596891971Virustotal results 20.34%Heodo
2020-08-21invoice #15169.docdoc 6bfe2a94bb14cb68d7ac4a146d4ebd2ece1cacec94b5260c9d59be8816a63601Virustotal results 20.69%Heodo
2020-08-21August Invoice.docdoc 7b92a86dabe99c11df1d176607cf155dba7ed15763592e1525e8c003d12a7e98n/aHeodo
2020-08-21Invoice 01626393.docdoc 07b8ea4707cf879ec39049e4126b2ce65bbdf0914091702bd83ba9235453f631n/aHeodo
2020-08-21PO# 08212020.docdoc 13d2079b2caabbd56dc776517810d9dbf355138869ff3030314e9f4905e68192Virustotal results 18.64%Heodo
2020-08-21August Invoice.docdoc 0d9f1f173fd3806d10312760c50f85b6fa23b65193732358ef675b670c84f5eeVirustotal results 21.67%Heodo
2020-08-21Electronic form.docdoc e194c7cc8ffedeb69d1b752e312fd6605be5ae9f49e9b652a38246d0c865dab2Virustotal results 18.97%Heodo
2020-08-21Inv_3705.docdoc 97b387cc7ac53574e95b7d09f100821989778d4fc076acebf7b546f24b500280Virustotal results 18.97%Heodo
2020-08-21Invoice.docdoc 3d0173175bbc0f83d9a5a2b8324c817f6a433756949f63691ec5374d82859a6fVirustotal results 18.33%Heodo
2020-08-21Invoice.docdoc 394c97133b4d81514504f55b62d339ee9f96ef1e33e3e5e348219975abc2aff2n/aHeodo
2020-08-21Invoice #6343.docdoc 5e37f5354f96cd177c761ca52c57c90a54d60875be3c4f6ce46dcdc0c5ee9884Virustotal results 18.97%Heodo
2020-08-21Payment status.docdoc 56e0e49883a186240907a045e8933efbbaa016d71dec86c1ae477064db00a160Virustotal results 18.33%Heodo
2020-08-210186137.docdoc ad61f377cd0d259cfabac17a4a874cd5dbd88b076e00680d5fb1d31706816ca7n/aHeodo
2020-08-21Electronic form.docdoc f18c5d3941f1fe1232a82e045cba9ab62b797025b1b7b5477a19a08b9b3fcae0n/aHeodo
2020-08-20INV_79730.docdoc ed8f3cd480b6fef9996f65e02cc1cb3d295447728fd009032ac3838d32e01f37Virustotal results 33.33%Heodo
2020-08-20PO# 08212020.docdoc 9c2952185499dfb564607790c299bf8a01a0bd16d64484be1812bfc88c5f5a06n/aHeodo
2020-08-20TE079 invoicing.docdoc 73edfc2aba2a5e763fb0b40b55a4695a6d9e6f0069b17e693c982385b150b4c7n/aHeodo
2020-08-20form.docdoc 4e132ba6d019767be2f8156e367e5c0f60ee91db33f3517c525d22cace8bfa9bn/aHeodo
2020-08-20Inv_552984.docdoc 5f721fa567c8707cbefd2292d75f13cbe60f70a768b9a902547ae56d954a7b81n/aHeodo
2020-08-20Invoice.docdoc 15614f9fe6b5fc4c1239cce9d4f1a1ea18ae400b60efba8c76023d4e9cad758cn/aHeodo
2020-08-20ZW00657 invoicing.docdoc 0c9bdaf25bc6465c491f19c920faa56544188ae9d41c7a0905bda06a835b6ec4n/aHeodo
2020-08-20PO# 08202020.docdoc cebba9744c9ee76ef1e0f3bf6b9a25b081f21938c99d50c784877808a7760ec2Virustotal results 30.51%Heodo