URLhaus Database

You are currently viewing the URLhaus database entry for http://fourtion.com/scan/EN_en/Paid-Invoice which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:44814
URL: http://fourtion.com/scan/EN_en/Paid-Invoice
URL Status:Offline
Host: fourtion.com
Date added:2018-08-21 04:40:34 UTC
Last online:2018-09-09 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-09-07 11:32:36 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 days, 4 hours, 29 minutes Poor (down since 2018-09-09 16:01:38 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-22Month notice.docdoc dcd7feb1774d994996fb3822536bf6a65b183aec087c735cac707c666afb8b54Virustotal results 23.33% Heodo
2018-08-22Invoice # 91Y8353.docdoc e18b1c0d39833232a9e66756d91984394b567762d33bc6141e6b7a899692ed25n/a Heodo
2018-08-22Statement as at 22.08.2018.docdoc e98e5d17dc7aa4586e1f26a03a718f8a4901b2f3366926177c382ea5509333c4Virustotal results 22.03% Heodo
2018-08-22New invoice 31MO8704.docdoc c98875d055850d409690a0e06eb782346d78e577e5971d1df66b1c3ff3412282n/a Heodo
2018-08-22Statement as at 22.08.2018.docdoc 9c0dff4dd890ef8601826bd9b8cb1d351f75e298e5e23e7a9abc40dc3fa99011Virustotal results 20.00% Heodo
2018-08-22Invoice.docdoc 6cb31227b512fc6d988c41e3b6e1c8b49ee7dd1595a0513cd39707efe1ad0553Virustotal results 35.00% Heodo
2018-08-22Month notice.docdoc d5ec03108350723a975792693405a3755af119e7639a505a59a2e4856eda32e5Virustotal results 29.51% Heodo
2018-08-22Statement as at 22.08.2018.docdoc ce0f0e0d8bbad2167369ba230b45a02bb02ca5fc65ea8a8a18f0f6529c283bd1Virustotal results 27.12% Heodo
2018-08-22Outstanding invoice.docdoc 93f71add31ed5a4f14981f656c1b8709fb327996fd571fe996dad19449062010Virustotal results 44.83% Heodo
2018-08-22Invoice Query.docdoc 52168096b9963f97883d921ad6af207b2a4cb9a41c45ede5ab22c4349e22033fVirustotal results 38.33% Heodo
2018-08-22Accounts - Invoice.docdoc a65ed438212c652de3b0a414fbc81ecadfc10bf3aa96cf8607a1054ec2c596deVirustotal results 36.67% Heodo
2018-08-22Outstanding invoice.docdoc 298ae90599a1f68d6a8817533eeed4c21e21416922d0ed346df6bd8da7062776n/a Heodo
2018-08-22Review invoice required.docdoc b9e7c2096c33e8fb98ec7e5bb24861d61061342bcb4931feb63f24e5cf529e6dn/a Heodo
2018-08-21Inv. no. 183463550.docdoc 6d7e29aa12387777da230a4d4b9958c480f40011c686b79df18f6424e1b53ab1n/a Heodo
2018-08-21Invoice.docdoc 040383f170e9500a9bfbe6d3965c0aec1c7df837ea90d81c4a9ecfd9bb960d31n/a Heodo
2018-08-21Invoice.docdoc 0683e0ba3ae879510788c36e80ccd62f8e934391f57fb46f511b42c30cb60f8bn/a Heodo
2018-08-21Final notice.docdoc 183334930d4aefe32cc2b934254af4a98433b105ff7976bb97097b6b153fa878Virustotal results 25.00% Heodo
2018-08-21Invoice Query.docdoc e1694b78f79447de4333f0946a7f60e593a6ae32ba6d25dbb484f2aee48a7a31n/a Heodo
2018-08-21Inv. no. 0W5J627373.docdoc f071d16e2fe798a868d07e99261e6885d45778e2624da6180a7b500acc97187an/a Heodo
2018-08-21Billing Invoice - Job # 481773.docdoc c6b5113c1f0a3e7d384c9bd6965ca6031402370066ed6cda277c88ab6d2b8ad7Virustotal results 22.41% Heodo
2018-08-21Inv. no. 7P5U2553.docdoc 0f8bcd7cf3d04ab7582f04b8c66502debbd5ba92100e5546d938ac2f3c9cebd3Virustotal results 22.41% Heodo
2018-08-21Invoice as at 21/08/2018.docdoc 351b5d7f01f09d5726fa50d3164965cd95a3a651b0028939ba92588c8b7aae2dVirustotal results 31.67% Heodo
2018-08-21Final notice.docdoc 50abceb0847ffb5915421d68b4530c75caad14987ee88b9daa2b15ac87f01215Virustotal results 27.59% Heodo
2018-08-21Invoice Confirmation ZB73162.docdoc 6b38d7526296b8e32a1326af70b8241c2a5d7f844f95fb61a0e8320de1b946d6Virustotal results 26.67% Heodo
2018-08-21Invoice.docdoc b084388b731ff2950f86d4bf4a8dd606d04dfa04a88f2e21652138b8f80e9cceVirustotal results 27.59% Heodo