URLhaus Database

You are currently viewing the URLhaus database entry for http://1eight1.com/FILE/US_us/Overdue-payment which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:55606
URL: http://1eight1.com/FILE/US_us/Overdue-payment
URL Status:Offline
Host: 1eight1.com
Date added:2018-09-12 14:40:23 UTC
Last online:2018-09-13 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-12 14:42:07 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:14 hours, 14 minutes Good (down since 2018-09-13 04:56:43 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-12Invoice Confirmation D991870.docdoc a20a75e15847da4cc1b2dc4833b21146beaa9dbf52507205c1e89195370ecc20Virustotal results 31.67% Heodo
2018-09-12Invoice.docdoc 907aeb750eb680cb57c7e93fdb76af114de2bcd12fb4ea47af5e76e755f832c9n/a Heodo
2018-09-12Invoice as at 12/09/2018.docdoc 27b1c48e85c13f3657f2e2a9cc66f88c19da1d0897f6fa70ef973a29d927c3c9Virustotal results 22.41% Heodo