URLhaus Database

You are currently viewing the URLhaus database entry for http://fourtion.com/Sep2018/En/Past-Due-Invoices which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:52358
URL: http://fourtion.com/Sep2018/En/Past-Due-Invoices
URL Status:Offline
Host: fourtion.com
Date added:2018-09-05 22:20:10 UTC
Last online:2018-09-13 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 11:32:36 UTC to abuse{at}godaddy[dot]com)
Takedown time:5 days, 17 hours, 13 minutes Bad (down since 2018-09-13 04:46:16 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-06Review invoice required.docdoc f29c45eb73de27b19fb10b54f3241e0337e85dbcb022c66e14c9f9938083c810Virustotal results 28.33% Heodo
2018-09-06Outstanding invoice.docdoc 2a3de196bcf5a1a6c0388a0549a23abbf9ce1861e4089ef0d352883c8c3e56f1n/a Heodo
2018-09-06Invoice Confirmation 90901993.docdoc 1f81fcf435096b8cc41a3b0ee3e2059b768dad8a91f5edd7d3750ef7ed13a3a5Virustotal results 26.23% Heodo
2018-09-06Invoice # 3K857094.docdoc 3674df1d3b0a673b80a50f176d5fb241d5ed82675be0dbd6acf7a5fdaec4edabVirustotal results 27.87% Heodo
2018-09-06Invoice.docdoc 4203da09b117b21f0c758378fb9839260b17872351de0a90a270027d0c15d76bVirustotal results 27.12% Heodo
2018-09-06Final notice.docdoc 10b15f27ea2171d08ce96fa1ca590fe3087b5af324582fefa333240051580f7eVirustotal results 50.82% Heodo
2018-09-06Customer No 9058970.docdoc 686be242063662dc748033f885a226b9a5a43c1d2997ba833f1b0a9c6e474d92n/a Heodo
2018-09-06Outstanding invoice.docdoc 96b60ded9ee0e8bd55ec5d1b4c34f3e0eea61e0bbaa8fcf193fa6a511d6616b4Virustotal results 46.67% Heodo
2018-09-06Invoice Query.docdoc e5189a5ae04977c103a33e27522c37ea3401c8a00f8f2c561bc8109444b0cd9aVirustotal results 47.46% Heodo
2018-09-06Accounts - Invoice.docdoc 3b481406e54ebcb7fce8636eccb681945384a9112cb90cf7f53dc73fee904821Virustotal results 47.54% Heodo
2018-09-05Invoice.docdoc dd37edcd061cec244bc6abdc3d9618fddc5c875659daee1b6fd81c201e81b492n/a Heodo