URLhaus Database

You are currently viewing the URLhaus database entry for http://montegrappa.com.pa/DOC/EN_en/New-order/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:51827
URL: http://montegrappa.com.pa/DOC/EN_en/New-order/
URL Status:Offline
Host: montegrappa.com.pa
Date added:2018-09-05 04:59:44 UTC
Last online:2018-09-14 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-09-07 11:24:11 UTC to abuse{at}godaddy[dot]com)
Takedown time:7 days, 6 hours, 27 minutes Bad (down since 2018-09-14 17:51:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-05Invoice as at 05/09/2018.docdoc 6c6dfcab49a55f450552f210124f1f75cfe878f6f8ef2cdff9baacd80e177938Virustotal results 33.90% Heodo
2018-09-05Final notice.docdoc d0f71c391c1b1fb724c288ae368de757e5c6f0301d4efeeb51397054480e9d99Virustotal results 34.48% Heodo
2018-09-05New invoice 57XFQ7778.docdoc 73b18c6fa287641c65666af250521add854d957e7527a3690eb70dd6b116ac2dVirustotal results 31.15% Heodo
2018-09-05New invoice 1537P972742.docdoc 91339375f4e75eb6d1e2cd05f67b13b4eab1312309aa35bca56f3e1f0960c37bVirustotal results 29.51% Heodo
2018-09-05Review invoice required.docdoc e466888c8e21f43a235e0ca2ded46371e5c9120d2a8cc5f334149074e3150eb5Virustotal results 44.26% Heodo