URLhaus Database

You are currently viewing the URLhaus database entry for http://egomall.net/files/En_us/ACH-form which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:49748
URL: http://egomall.net/files/En_us/ACH-form
URL Status:Offline
Host: egomall.net
Date added:2018-08-30 17:49:01 UTC
Last online:2018-11-19 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-10-11 11:03:49 UTC to ipas{at}cnnic[dot]cn)
Takedown time:1 month, 9 days, 4 hours, 7 minutes Bad (down since 2018-11-19 15:11:36 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-31Outstanding invoice.docdoc 7f8aec95699ba129406c6d469a139cfd54ac9c0397276e74ebbcc14d1768053eVirustotal results 29.51% Heodo
2018-08-31Billing Invoice - Job # 5652435.docdoc 5d2921cc47674a73edffb022957010dd71ad853d1b695ef904c61d1fbed43293n/a Heodo
2018-08-31Invoice # 63B41087.docdoc 1a4f5e46de4172c9ccb46fe003342817aaf10787252a98ec4178794f4483d449n/a Heodo
2018-08-31Month notice.docdoc 87d1341c26511e57d07e8df5c6d6cd64d4d6f95e7403e171c1fc38415d134177Virustotal results 33.33% Heodo
2018-08-31Month notice.docdoc 632ab451b8daa9da4ace36891d845319d055fb1eba65eeec3fd68ab0d2fd8ceeVirustotal results 37.70% Heodo
2018-08-31Statement as at 31.08.2018.docdoc 7174340687728c5230d046de38b89b02c469e096956eb0341fab4aeed9abb529Virustotal results 37.70% Heodo
2018-08-31Accounts - Invoice.docdoc e0953baca7f001d0813b2e86994c00d7110431adac7f2cbaa45efa1191f2ea3bVirustotal results 34.43% Heodo
2018-08-30Inv. no. 2LKE2350.docdoc 783b831fb2d080ecd97e5d4753632dc477556e9fb6d6059a00d1ae84b3b910ebVirustotal results 31.15% Heodo
2018-08-30Outstanding invoice.docdoc 176442914b0e63af7880d00c8a02febd3d9add954519c2f065f8bbaa5cdef838Virustotal results 32.79% Heodo
2018-08-30Latest invoice - 991192.docdoc 1947828121590b7185084d024c3ba75b597c912ee9e1b0e29fe4f55bd7f94236Virustotal results 35.00% Heodo