URLhaus Database

You are currently viewing the URLhaus database entry for http://egomall.net/files/En_us/ACH-form/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:49974
URL: http://egomall.net/files/En_us/ACH-form/
URL Status:Offline
Host: egomall.net
Date added:2018-08-31 05:12:04 UTC
Last online:2018-11-19 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-10-11 11:03:49 UTC to ipas{at}cnnic[dot]cn)
Takedown time:1 month, 9 days, 4 hours, 7 minutes Bad (down since 2018-11-19 15:11:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-31Outstanding invoice.docdoc 7f8aec95699ba129406c6d469a139cfd54ac9c0397276e74ebbcc14d1768053eVirustotal results 29.51% Heodo
2018-08-31Billing Invoice - Job # 5652435.docdoc 5d2921cc47674a73edffb022957010dd71ad853d1b695ef904c61d1fbed43293Virustotal results 31.15% Heodo
2018-08-31Invoice Query.docdoc ef704fa55454b296ff196b27dcf30e3e0974ab106ad6d927c5f258757e01f351n/a Heodo
2018-08-31Invoice Confirmation Q5412020.docdoc 79765635b755992b9035560d4e00b550c3690c4a75d4e022b5998f11db4db738Virustotal results 42.62% Heodo
2018-08-31Customer No 029925.docdoc 3a2ce04a9398657962a31a6e53e5762b754fd7bfd675a34ed40bf5817c15964cVirustotal results 40.68% Heodo
2018-08-31Statement as at 31.08.2018.docdoc 7174340687728c5230d046de38b89b02c469e096956eb0341fab4aeed9abb529Virustotal results 37.70% Heodo
2018-08-31Latest invoice - 511102.docdoc 3336fa4f379486a0b463988363975a52a3f3d6fd37d5ab029aba4ccd8b43b4ddVirustotal results 36.07% Heodo