URLhaus Database

You are currently viewing the URLhaus database entry for http://nz.dilmah.com/INFO/US_us/Paid-Invoice which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:49672
URL: http://nz.dilmah.com/INFO/US_us/Paid-Invoice
URL Status:Offline
Host: nz.dilmah.com
Date added:2018-08-30 17:44:21 UTC
Last online:2018-09-13 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 11:41:14 UTC to abuse{at}rackspace[dot]com)
Takedown time:6 days, 1 hours, 7 minutes Bad (down since 2018-09-13 12:48:44 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-01Final notice.docdoc 8e04c42475bc3540925710dd1c71fad658b7cb19b6b2206fb59d0fea9b37cd2aVirustotal results 45.00% Heodo
2018-09-01Accounts - Invoice.docdoc 491c3d24b3b6153de9fdbc5c2c32f27f9677f441ec251559a9191b5a10d344d9Virustotal results 40.98% Heodo
2018-09-01Review invoice required.docdoc df4782979ddc3dc1a7e76d26eac7ee6db976d85bfd9f785fad67113d229c9213Virustotal results 33.33% Heodo
2018-08-31Outstanding invoice.docdoc 51b33b16f7ad8a624048ef27a6270f21fed3d12d66a3874f735ec7582fb58f26n/a Heodo
2018-08-31Customer No 4882176.docdoc b134ac283063896b64c18aabb90961561dca0480e9c7fccdbbdb7316f231d369n/a Heodo
2018-08-31Accounts - Invoice.docdoc 4986ba3fb0b7756341ebeddf0af16792fb61dad7cc47f6c1e44e5e2fb629d171Virustotal results 33.33% Heodo
2018-08-31Month notice.docdoc 1a4f5e46de4172c9ccb46fe003342817aaf10787252a98ec4178794f4483d449Virustotal results 32.79% Heodo
2018-08-31Invoice Confirmation Q3329912.docdoc 87d1341c26511e57d07e8df5c6d6cd64d4d6f95e7403e171c1fc38415d134177Virustotal results 33.33% Heodo
2018-08-31Invoice Query.docdoc 632ab451b8daa9da4ace36891d845319d055fb1eba65eeec3fd68ab0d2fd8ceen/a Heodo
2018-08-31Month notice.docdoc de0e3be51c4083fe7e6ab6d9808500d1b38555238a1b610d68788f030cbd3e32Virustotal results 36.07% Heodo
2018-08-31Invoice.docdoc e0953baca7f001d0813b2e86994c00d7110431adac7f2cbaa45efa1191f2ea3bVirustotal results 34.43% Heodo
2018-08-30Customer No 801323.docdoc 80e44902672ecab3b31405757629b002ff1ae15b15498bbc19a9ecb923b0cd92Virustotal results 32.79% Heodo
2018-08-30New invoice 86U084938.docdoc 92e27f0f1bdefda08f890d324e4a631f53f33096379d9bba32efb554a4834dbdn/a Heodo
2018-08-30Review invoice required.docdoc 91a463c2f58f868cc635e5109240c1d165e44180208e0b61cba1f76e797ea24aVirustotal results 34.43% Heodo