URLhaus Database

You are currently viewing the URLhaus database entry for http://rejasan.com/icon/622442031/EHty/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:446284
URL: http://rejasan.com/icon/622442031/EHty/
URL Status:Offline
Host: rejasan.com
Date added:2020-08-28 21:40:10 UTC
Last online:2020-09-04 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-08-28 21:42:03 UTC to support{at}servermania[dot]com)
Takedown time:7 days, 1 hours, 27 minutes Bad (down since 2020-09-04 23:09:38 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-29PO# 08292020.docdoc 5df4f10d255d1733e9450ecf67d166c73f6f29bb36efe88d6093a31d31ce0ad4n/aHeodo
2020-08-29INV #722 FOR PO #380284038686.docdoc 3b5c4fffd6b0548d5d66842086b1b3762032be24a72ceb3154d72cc55cbb8d83n/aHeodo
2020-08-29form.docdoc bafeb0485f36e4e1ba176fcbc1b43cec6639282dbeeb7244c56f9b98fe8df5bdVirustotal results 44.83%Heodo
2020-08-29Copy invoice #21145.docdoc 139e6af741bc7d94ee44f8a69dbc8e694a72bb780b0b984a2c57cc99966d3e5dVirustotal results 44.07%Heodo
2020-08-29PO# 08292020.docdoc 784032625b6d1b88dd76d550cb768c579598aea088f9fcb111d041fff5f57019n/aHeodo
2020-08-29Inv_21109.docdoc 20d5c90c46b7747659e92efa4aa78da9e7404b82187e9e8605337918faad432fn/aHeodo
2020-08-29Form.docdoc b7a2a470b35a3cbf4a6501f45709fa7cc29d2a33c5cac4f00ac64b426b90929en/aHeodo
2020-08-29invoices 32812 & 64814.docdoc b8029c0d90d1b4ff550cf1f13603ccb9b462e64c8b81afc2ac33252b86839931Virustotal results 35.59%Heodo
2020-08-29invoices 3640 & 18105.docdoc c98ebc2ba9a8e8f27e921e635f8742cdbb64688b48b57e7300575ccee61930a5Virustotal results 35.59%Heodo
2020-08-292219621684IC.docdoc d8c49275c5f1f5f0737181da7071f1755efac730269b0741539b1430a34096ebn/aHeodo
2020-08-29invoice.docdoc 0c962f3623896801e405c611fdc2b6cbbff5a1757ab32e43feaaa32ac76fd56an/aHeodo
2020-08-29form.docdoc 8024aa6cee62d71b90733458c64c779647087eb613aba76cd872a01b46cfdea6n/aHeodo
2020-08-29Invoice #56376727.docdoc a936fa77ef0be55ddc1bba6a24c65da623b7207d45356219d55b2475a4234b9cVirustotal results 36.21%Heodo
2020-08-29invoice #3015.docdoc e2e03f4ee18e589f52459cd372bef3e8a8935fc5e5638f41044f00fe0f151e52n/aHeodo
2020-08-29August Invoice.docdoc 8c3d2e0fd7d2cc86088185bf1acaf32d2d7e43124beba918f38856179ade8097Virustotal results 31.03%Heodo
2020-08-28Electronic form.docdoc 5db10c40e7788456c57bf2481d95f86b762e85ec74c1ba5a232014afc0b7071en/a Heodo
2020-08-28August Invoice.docdoc 418cd12b251bce9b75ac793c3d626440b35e8e6ef2002751114a27eb3a627d26Virustotal results 29.31%Heodo
2020-08-28Inv_984859.docdoc a457afd23063f580f5431f2118cc0936362067a7440f76d90eeb270da41508ecVirustotal results 28.81%Heodo
2020-08-28Inv. 00268266746.docdoc c6a98abe2ef2b0e445d4145a16d2728b53d55c55b9303eb550696db4b531bdc1Virustotal results 28.81%Heodo
2020-08-28Inv_520921.docdoc 1af25f1feab8bab24a7f9f4531268d94b21a132eb001a1474213e7f92378cef5n/aHeodo
2020-08-28Invoice 008325754.docdoc 83a4d7860de46ad541e0399824ba56d53f755c233914096fa08cdf1d966960b0n/aHeodo
2020-08-28Inv. 048054.docdoc b89e478d217b03e8c0042bab248bd9431243f6fbe54c13d26d77b63b93c0c99cVirustotal results 28.81%Heodo
2020-08-28August invoice.docdoc c7042f61131d4a483d3b7433af94d39743944f2fd4e00abf795450a603c883fcVirustotal results 27.12%Heodo
2020-08-28form.docdoc 96955576446f803417498ea62363fb51274e644a275afcd1086cfa9a60df1d92Virustotal results 27.12%Heodo
2020-08-28Form.docdoc 5247f3a28b50babf22fb454ffac4172d77fe1e13cda0fa05e0e7d8ea1b15af52Virustotal results 28.81%Heodo