URLhaus Database

You are currently viewing the URLhaus database entry for http://avto-baki.ru/INVOICES which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:51996
URL: http://avto-baki.ru/INVOICES
URL Status:Offline
Host: avto-baki.ru
Date added:2018-09-05 08:39:07 UTC
Last online:2018-09-07 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-09-07 11:48:44 UTC to abuse{at}best-hoster[dot]ru)
Takedown time:27 minutes Wow (down since 2018-09-07 12:16:14 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-07Doc1885.docdoc ca71170483f94cc9d5cf385aed5119287d3e5cc4fa19d9c8746dff5938e324b4Virustotal results 39.34% Heodo
2018-09-07Doc3920.docdoc 1beb180a4800b400249628e20421a092ed47491194721c97e5616f8daa5b2aa0n/a Heodo
2018-09-07Doc29064.docdoc 04032c6d53dda3aaf0dc44431c2b435fdcd1804a8b4286fd7925635f54740f91n/a Heodo
2018-09-06Doc89047.docdoc 32be4a232301016942083ff39478ac5d28617f38b09c50f087b1cfffde3e87cbVirustotal results 36.07% Heodo
2018-09-06Doc59644.docdoc 02f247feaff773b8190a6bf2440a5ff158fad61ee05372284952471d65ca8b19Virustotal results 36.07% Heodo
2018-09-06Doc3996.docdoc 8392cbca4a188b038a4ee855e738edc4c782725a2e8efc9ba0529eb8a7c965b9n/a Heodo
2018-09-06Doc614151.docdoc 51d3d70235769a5fd43d542aa1c60a0f88ca82b4ccf51a40225a8a29675e77c5Virustotal results 26.23% Heodo
2018-09-06Doc196240.docdoc b5cf1eb2dfa9a64cfdbc05a292407200c105142e0f60845a2e90ef28f0883e46Virustotal results 26.23% Heodo
2018-09-06Doc0043.docdoc 9ac3e1dea648ef282333855dbbe7e3746614a2eedfc2dee3678125a6423fc063Virustotal results 27.87% Heodo
2018-09-06Doc18731.docdoc 44d3f49429e2ab93d575243f67bf919f5100826c26d90ddd80c6c1462ec20a63Virustotal results 28.81% Heodo
2018-09-06Doc219312.docdoc 7d6dd6f31fe153a4a9bdea4409458f293cb219f29c102f42ed37466b08f6383dn/a Heodo
2018-09-06Doc710319.docdoc 7308d4a14897affcb826fca3d54187bd4d23a355f55312fba8285aa8a7a4e238Virustotal results 49.18% Heodo
2018-09-06Doc94173.docdoc 2c03a9624b09fec521467583a59a50d37703b4a17ffa257760b9c07fbfb3a51fVirustotal results 45.90% Heodo
2018-09-06Doc3234.docdoc d7a867dda03c53284cf58654bacd77ed3177a663194f2ebf730970617e85a72dn/a Heodo
2018-09-06Doc1859.docdoc 1ce1209b507ae76b3f83ff6d382024f08b38ff7c4572baee00575c8fbed5cebcn/a Heodo
2018-09-06Doc63620.docdoc 3907d1a0e32137c281103d769f2466cc14e59361f110b312f9e930a9c743b05fVirustotal results 48.33% Heodo
2018-09-05Doc8645.docdoc 57d477727da145d35c4a2157b7b5f296bc1ea315aa9c0854e46bcfe85650b491Virustotal results 44.26% Heodo
2018-09-05Doc86880.docdoc f102672d1eac888af58585e5ae3dc4b120f3fc2d75617ad153f6b4307a67ee22n/a Heodo
2018-09-05Doc5573.docdoc 44417054cd298a5cf98c3888506449bac3c96c0fdfe9512e9ad6608d051fa0e3Virustotal results 32.79% Heodo
2018-09-05Doc1702.docdoc 41f2624ee50f76b952ab4f253d97b83ce934119a5d432f6cab31af1557245bf7n/a Heodo
2018-09-05Doc39177.docdoc 110b0451c464f21e14b7f2effc1cf83b9abc6df641342dc4c0e67f5e1613826cVirustotal results 31.03% Heodo
2018-09-05Doc810933.docdoc 685e15aba86645cba2e85df47a2e868d3114738d67ebee2bb6f7fe24825cfa6en/a Heodo
2018-09-05Doc4382.docdoc fa0119b36302cd7d16eed6c7d2b5898bcd8edcd8cb24668b56fbca129bf07b03n/a Heodo
2018-09-05Doc2571.docdoc 19aa82f78708233ba6d10ea05cef120c50010d2c61201f7a7087469287fd12dbVirustotal results 45.76% Heodo