URLhaus Database

You are currently viewing the URLhaus database entry for https://designthinkinginschools.com/5znc4/attachments/attachments/9850/pnzr336d-000365/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:444903
URL: https://designthinkinginschools.com/5znc4/attachments/attachments/9850/pnzr336d-000365/
URL Status:Offline
Host: designthinkinginschools.com
Date added:2020-08-27 02:11:14 UTC
Last online:2020-08-27 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-27 02:12:02 UTC to abuse{at}rackspace[dot]com)
Takedown time:19 hours, 7 minutes Good (down since 2020-08-27 21:19:40 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27Payment status.docdoc c87ff4601214eab29d1318e621dac4a0ae69e9f3ec301f4126b4dfff0a947572Virustotal results 32.20%Heodo
2020-08-27Electronic form.docdoc 5bf845e70cde6a5112d1aec081e98995bc8494ce31682762bad07ec7c92a2889n/aHeodo
2020-08-27Invoice 08096576.docdoc 2d49046fc064b91ca9ac6b885536752ac075d5f370afc9d43148a0d79c4cfa51Virustotal results 32.76%Heodo
2020-08-27form.docdoc 545691b412ebad37c821720382a253d79c13e01fd207f6545c6e7e12bccda994Virustotal results 30.51%Heodo
2020-08-27PO# 08272020.docdoc 70bc2a3ce1968437f2a3dbb114e000c23bc3882e53d4b963cf326ff03b84487dVirustotal results 28.81%Heodo
2020-08-27August invoice.docdoc 7dc0a6093d70ccee91389c1ad23fb90c465444cb47b4af89f487c4769fc039d9n/aHeodo
2020-08-27Electronic form.docdoc 1653613e54e13601c4799c80c854d900b5b794b6f042130935272db8d6d1e2dfn/aHeodo
2020-08-27August Invoice.docdoc 842b433e1fc26b5e7e972fb6ef675ef6997cc2b8cd9311fb2f330707cad0dc0aVirustotal results 28.33%Heodo
2020-08-27Payment.docdoc 50910a1746d08448bbe4453475ccbb09c9f2380766c2b9357d5e343212636102n/aHeodo
2020-08-27Inv_728991.docdoc 3655157b27b8b084443564d11a050740b1e72edf7bb35e9b2cc619eb795c52acn/aHeodo
2020-08-27Payment.docdoc 46708b3e324abd5c337910c83e84ce92a571c91a385f0bd417af825e5d38ad53Virustotal results 27.59%Heodo
2020-08-27INV #09920 FOR PO #0805960219.docdoc 52619ff393616193f81714ef0f313f3e78f4bf34f0841bf1351fd864f0df17e0Virustotal results 27.59%Heodo
2020-08-27C9286678661BV.docdoc 2e31c7b64974a192985f4fbddb6d92fcdb1878c74e159d430a97e8ba0611aeebVirustotal results 27.59%Heodo
2020-08-27PO# 08272020.docdoc 08531c896c900816e373957872ce7e55db50203fd681019719dca8fc27882b40Virustotal results 28.81%Heodo
2020-08-27Electronic form.docdoc a9bd74574df38d6a8e51cb22d26dd85383aa10a3d8e4f8ff2a7ef30663b77aeaVirustotal results 28.81%Heodo
2020-08-27INV #00740 FOR PO #0056429768068.docdoc 8961b61c4631b8c84367078e44fc1066f57830e0bc0622af1de7769f82e6442eVirustotal results 28.07%Heodo
2020-08-27Form - Aug 27, 2020.docdoc f663b206e32202cdb2b7fe26738d009a4c1fb76352cb8e9a46bd1a7bc6060bb3Virustotal results 27.59%Heodo
2020-08-27Form - Aug 27, 2020.docdoc 2bae2742fb283aa2f35ef1722797919ff00e34f7e1868ca7841fc5baafdefe96Virustotal results 44.83%Heodo
2020-08-270422819.docdoc 021d2338b8a706fbd77f04cf43db3bf9dea03a1afff732ece042614c35e369edVirustotal results 44.07%Heodo
2020-08-27Payment.docdoc 518cef1391f1fd9cabab66c2c32f6ee1428a399147f181ff433baefecb0e8c45Virustotal results 42.86%Heodo
2020-08-27invoices 8396 & 1519.docdoc 11f958d598c4e1b0b0978b6e9d9ea6f5e1a8fa34f1af035d657f13b04bb128ben/aHeodo
2020-08-27INV_595393.docdoc 469ac8a418f2dbb4e433d022cc757fe2ddb270878b4c7ab13ebf4f8a316c30e6Virustotal results 41.38%Heodo
2020-08-27Electronic form.docdoc dbfbc13ff098e5c8ed87a620e5e73f075dc9ac85963d50111843d28ea929a4d1Virustotal results 41.38%Heodo
2020-08-27INV #498 FOR PO #0050702139443.docdoc a7de5e7039339ecbff062dcb58d75a469ea8240a5f7d1549f67e69e56443865cVirustotal results 38.98%Heodo
2020-08-27Inv. 0005402.docdoc b87a064c66cdd9719e97ee49c21b6435c4f769164c1195b5d14cf15b9dc81a19Virustotal results 31.58%Heodo
2020-08-27Electronic form.docdoc e45a7277159aac8916096aa45b400cdd23c26f876fb6a1753d95e1119c352259Virustotal results 31.03%Heodo
2020-08-27invoice.docdoc f92eeeee023f763c255c41615d314bdd95628f511d7650771f8bbe9ef73742b9Virustotal results 32.14%Heodo
2020-08-27Invoice 00208281.docdoc 30eca983aa11aacf8a9a26d81949e7cb8863cfaca266ce52df6dfc9c61d44300Virustotal results 31.58%Heodo