URLhaus Database

You are currently viewing the URLhaus database entry for http://egomall.net/newsletter/EN_en/Paid-Invoice-Credit-Card-Receipt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:52182
URL: http://egomall.net/newsletter/EN_en/Paid-Invoice-Credit-Card-Receipt/
URL Status:Offline
Host: egomall.net
Date added:2018-09-05 14:15:07 UTC
Last online:2018-11-19 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-10-11 11:03:49 UTC to ipas{at}cnnic[dot]cn)
Takedown time:1 month, 9 days, 4 hours, 1 minutes Bad (down since 2018-11-19 15:05:22 UTC)
Tags:doc heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-06Invoice Confirmation GW24103.docdoc b17d0d77d9c437efc7cc67b71be0bd8c30eb64c4161698b8145d45560d06881cVirustotal results 29.51% Heodo
2018-09-06Review invoice required.docdoc 2a255834d890d8c82125c3701f929fbedabe2093c81e604d53621b83de0c509cVirustotal results 26.23% Heodo
2018-09-06New invoice 54MZ4407862.docdoc 1f81fcf435096b8cc41a3b0ee3e2059b768dad8a91f5edd7d3750ef7ed13a3a5Virustotal results 26.23% Heodo
2018-09-06Outstanding invoice.docdoc 3674df1d3b0a673b80a50f176d5fb241d5ed82675be0dbd6acf7a5fdaec4edabVirustotal results 27.87% Heodo
2018-09-06Invoice as at 06/09/2018.docdoc 4203da09b117b21f0c758378fb9839260b17872351de0a90a270027d0c15d76bVirustotal results 27.12% Heodo
2018-09-06Billing Invoice - Job # 950286.docdoc 10b15f27ea2171d08ce96fa1ca590fe3087b5af324582fefa333240051580f7eVirustotal results 50.82% Heodo
2018-09-06Statement as at 06.09.2018.docdoc 749f28c3773f38eb46266ef2a612253ac868255883e99a7117ba93790fed7831n/a Heodo
2018-09-06Final notice.docdoc 08bd5b72b01a1034086c779b4353fbef9e0f135e532556515b4737c45a7d0ea6Virustotal results 46.67% Heodo
2018-09-06Statement as at 06.09.2018.docdoc c0b8bd18ebe466754287750a2c21807e2f1438c32902df92490a84d71d5b772bn/a Heodo
2018-09-06Statement as at 06.09.2018.docdoc 1c7ac3f0f213a6628455433131b5673c84746fb55b37036642d381d3333708ben/a Heodo
2018-09-05Review invoice required.docdoc 20b9108674f61c9c77765f5c63ae759185eb5af223570f84e4394e7d7e74b620Virustotal results 45.76% Heodo
2018-09-05Invoice.docdoc 6a7368001187db20be0d83e0e450f06ee3968ab147db4be40241bafbd5f25a93Virustotal results 36.07% Heodo
2018-09-05Billing Invoice - Job # 8569020.docdoc 76c4ef2bba3eca811278e1f79b953777c61a1ce476cd371cf4192e22bcdacf6cVirustotal results 33.90% Heodo
2018-09-05Accounts - Invoice.docdoc 2e60c3855248440009d16ce09824a760fe4840b98c94d4a36040c0d6dc870b5en/a Heodo
2018-09-05Statement as at 05.09.2018.docdoc ab7e4d73909a8cac1107c2872c41b1f5453a311ee3270d558b42b13b558d3fc7Virustotal results 31.67% Heodo