URLhaus Database

You are currently viewing the URLhaus database entry for http://www.l600.ru/sites/US/INVOICE-STATUS/012354/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:44172
URL: http://www.l600.ru/sites/US/INVOICE-STATUS/012354/
URL Status:Offline
Host: www.l600.ru
Date added:2018-08-18 04:49:04 UTC
Last online:2018-09-10 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-09-07 11:47:12 UTC to abuse{at}rtcomm[dot]ru)
Takedown time:3 days, 4 hours, 33 minutes Bad (down since 2018-09-10 16:20:28 UTC)
Tags:doc heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-18Statement as at 18.08.2018.docdoc db78b33143934e4f5dfbe4104ecb388b92f490f97ae5616b5ac3097fb24e1082Virustotal results 26.67% Heodo
2018-08-18Latest invoice - 517427.docdoc 3aa38ac0a248c94269436c137a18db920eee26ed3b65bea8979dc08f72d1c12dVirustotal results 25.00% Heodo
2018-08-18Invoice Confirmation ZI635609.docdoc 31fc0494c40e707a95f6ba25a3f2c82c47b38a9462d571d01bbd02d49ca484d7Virustotal results 30.00% Heodo
2018-08-18Invoice Confirmation ZI635609.docdoc 31fc0494c40e707a95f6ba25a3f2c82c47b38a9462d571d01bbd02d49ca484d7Virustotal results 30.00% Heodo
2018-08-18Invoice Query.docdoc 987b7718ab13a4544b4dbf72c4d104c1f5167264b686c657239413da8ebb727bVirustotal results 25.00% Heodo
2018-08-18Invoice.docdoc 8498bc836becd0f3a758820fbf7d65cb0a049f2f66eb6c31c3a96c27aae7ec9eVirustotal results 25.00% Heodo