URLhaus Database

You are currently viewing the URLhaus database entry for https://simpsonz.com/wp-content/payment/5raa59744e95/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445589
URL: https://simpsonz.com/wp-content/payment/5raa59744e95/
URL Status:Offline
Host: simpsonz.com
Date added:2020-08-28 00:15:12 UTC
Last online:2020-11-02 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-28 00:16:02 UTC to abuse{at}makut[dot]investments)
Takedown time:2 months, 6 days, 21 hours, 52 minutes Bad (down since 2020-11-02 22:08:42 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-2907224021.docdoc 238b6400e34d00a9c7c67b646fe7cdf3facc453f47632bfa9c8dac3aa1a40779Virustotal results 52.54%Heodo
2020-08-29PO_08292020EX.docdoc 242de608bdf2c6fbfa037537be866bf7558858fc240142c606115e86bd28a941Virustotal results 44.07%Heodo
2020-08-29DOC_41439659.docdoc b39ab4983136519b6249443c1c9f1a89b7c1e83cd17ec40748745b41268741dcVirustotal results 49.15%Heodo
2020-08-29INV_ZEL_080120_NBM_082920.docdoc ab465edf58b50037bd4c7da09e85cf87e5a83e9301a3b75a761b682142dfdfd0Virustotal results 51.72%Heodo
2020-08-29INV_XS6895120319AC.docdoc 13df7d0cf9c4f67e22eb093ff92b70f61fe8e5c61d1afb6c933fee76f2525abeVirustotal results 50.85%Heodo
2020-08-29FILE_583351329.docdoc 933af4898a9ce638e04dbcf02e075e9f7eecf02ab22cebc4488517cd415e1c71Virustotal results 32.20%Heodo
2020-08-28FILE_PO_08292020EX.docdoc a9b6317d17337bd970e7e72e373ff364eb613b443f84bb159a9daab32918e979Virustotal results 29.31%Heodo
2020-08-28KS4398960956JC.docdoc f5d308b615528818047b9010074fd219d6248ce43aff167bcc0bbb56a6d45504Virustotal results 28.81%Heodo
2020-08-28PMH_080120_OOR_082920.docdoc aef46f7e71936aca8da4fff081f587fe6293f09dac7b27fc70f372088eff86f5n/aHeodo
2020-08-28QJS_080120_CBE_082920.docdoc 167504fd75c887fa1e091030f6f8899e57917c86c6e455c8f7fe99b378bb5f71Virustotal results 26.32%Heodo
2020-08-28L_PO_08282020EX.docdoc 3a81d48dd27d252c1d0dbbbe11a02671bc68c7b1970611a1bde4bcf3beaea556Virustotal results 29.31%Heodo
2020-08-2856807351.docdoc fb2ffb3aa6e2a0f7a272c7bae05e700460c73f88daef8b34d0ae4332116d3ee2n/aHeodo
2020-08-28INV_35902107.docdoc 5332fb0050d2e914d7bad1f7ee68a30aec6cf4afb47db5fbad43cdc3cb500209Virustotal results 28.57%Heodo
2020-08-28BAL_O4S5NGK7EC.docdoc e189a7569815651cf514dcabf42ee4991cc49f7653402684fbf55db8353f7908Virustotal results 29.31%Heodo
2020-08-28W_13942160.docdoc 6fbd2c25ee2b04cb72eb490fce1e341a1f979db4bf955017dbe72a235026c8d5n/a Heodo
2020-08-28YN8624921731NG.docdoc ebbbf1104be5c5f4f000285e72aa802cdac327750e71a35a101e4ecac224d1d2Virustotal results 28.07%Heodo
2020-08-28REP_WAD_080120_IUC_082820.docdoc 8797e3b7bd75e1a64682db33af0c11c05bceaa46303559eb2e042d368542b199n/aHeodo
2020-08-28D_PO_08282020EX.docdoc 3ddf3600b1feb4c4e8a3ae126b798a2e61ff41794ff84e9f28d87080811c4899Virustotal results 31.03%Heodo
2020-08-28D_PO_08282020EX.docdoc 3ddf3600b1feb4c4e8a3ae126b798a2e61ff41794ff84e9f28d87080811c4899Virustotal results 31.03%Heodo
2020-08-28FILE_526238053516408969.docdoc 0103af1495d7b8b6b61d54d38b51fe7befbc70f0de62a08c00752c9ecfabc370Virustotal results 29.31%Heodo
2020-08-28BAL_459682779048978.docdoc f35f09ee31dc9ba4c3d871882fadeeb10ed716f5a87be56e6129b111b6e5e34aVirustotal results 48.33%Heodo
2020-08-28C_SI4401069642JU.docdoc 8658e7ea7f3c4c680d6ddeecf93b59b9bfd3298d79d6f0e7a5c3d9aa1623d961n/aHeodo
2020-08-28BAL_98561678.docdoc d9af175ba25dcae35440967cff2b9dbe0257596855b311d10e6fae3369558883Virustotal results 37.29%Heodo
2020-08-2862331933.docdoc 5a39b64f351708e72ad56acbd1067970f2a17194dabd5eecdf3dfa44b7e2deceVirustotal results 33.33%Heodo