URLhaus Database

You are currently viewing the URLhaus database entry for http://www.l600.ru/sites/US/INVOICE-STATUS/012354 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:43748
URL: http://www.l600.ru/sites/US/INVOICE-STATUS/012354
URL Status:Offline
Host: www.l600.ru
Date added:2018-08-16 23:17:04 UTC
Last online:2018-09-10 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-08-16 23:21:05 UTC to abuse{at}rtcomm[dot]ru)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-18Statement as at 18.08.2018.docdoc db78b33143934e4f5dfbe4104ecb388b92f490f97ae5616b5ac3097fb24e1082Virustotal results 26.67% Heodo
2018-08-18Latest invoice - 517427.docdoc 3aa38ac0a248c94269436c137a18db920eee26ed3b65bea8979dc08f72d1c12dVirustotal results 25.00% Heodo
2018-08-18Month notice.docdoc b9d3cb69e6d91ad91ba15ba9bb5cce0f43e29de98ae524a94612e829a5cc1822Virustotal results 28.33% Heodo
2018-08-18Invoice Query.docdoc 987b7718ab13a4544b4dbf72c4d104c1f5167264b686c657239413da8ebb727bVirustotal results 25.00% Heodo
2018-08-18Customer No 1721115.docdoc 675bcc0d81696e4661fc4aae7310b85f0f82b4636116851f7402daee90cf001aVirustotal results 25.00% Heodo
2018-08-18Accounts - Invoice.docdoc 62e7df7fc67b12f92826314df862cb9752dfe4922c7d7aa78b19a22940ec9778Virustotal results 27.12% Heodo
2018-08-18Latest invoice - 159685.docdoc 4ff67c47b5626b9112817ec2f3eae29f6425cca59ba95dab90bf47f154747f80n/a Heodo
2018-08-17Latest invoice - 577880.docdoc 6f5f0dd15c6de0b64cccfae94c453553aba1baab6845b2d6af9a0d76842c40d8Virustotal results 25.42% Heodo
2018-08-17Inv. no. 98BKV51310.docdoc 500b5b69e515d684d7dddc8d259df07ae3e002f080bdb8695d14f1959ddc359cVirustotal results 25.00% Heodo
2018-08-17Final notice.docdoc 6c0ad95ff0ca60b5ea899f7aa3a42bde568073266c33f094f6d28ad509603a6cVirustotal results 23.33% Heodo
2018-08-17Review invoice required.docdoc 12da0a24594882ccd0f51f75f8fac6917ac56d1628fd42c80b76783c7fe4e8a0Virustotal results 38.33% Heodo
2018-08-17Statement as at 17.08.2018.docdoc 3caa11942157ed53f0fc8edbba2ea2a48af6cfc7870f743db73f99dc7459f191n/a Heodo
2018-08-17Invoice.docdoc 45d7a562e28bc0c462453f4c44cc7635f0e9fce97a88f10f8d1f967ca716210bVirustotal results 38.33% Heodo
2018-08-17Invoice # 14XZ81149.docdoc fdd9509a2e735536c4d293d91c17a7a265fcaaa8c9e9e0fe13382fcb2ccfc65bVirustotal results 40.00% Heodo
2018-08-17New invoice 851E54267.docdoc aaf2a53d588fdf5d645ff98010d451df0266495674af70ee51c8bbd2aa5f64d6n/a Heodo
2018-08-17Review invoice required.docdoc aeb1453408dd1d877ccd4ec68579568ed7fa636bfd8fad146b29511c63c528ffVirustotal results 31.67% Heodo
2018-08-17Billing Invoice - Job # 044936.docdoc cbd518e27760fdeabdff40871a60655176a5f19128ef1f2e929ea0861aed6002Virustotal results 30.00% Heodo
2018-08-17Invoice Confirmation 228245.docdoc 249012c3cd4ac855aabdd7ecbfe0bd46265a3dcbeea94f49af5bdd6801ec12abVirustotal results 30.51% Heodo
2018-08-16Invoice # 44IJ714216.docdoc 4ee63a502b47b5c88c9a93f3f3aaaf1497c31c6ba5680927fd3a609a89794e92Virustotal results 30.00% Heodo