URLhaus Database

You are currently viewing the URLhaus database entry for http://flexitravel.com/files/En_us/Past-Due-Invoices/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:57299
URL: http://flexitravel.com/files/En_us/Past-Due-Invoices/
URL Status:Offline
Host: flexitravel.com
Date added:2018-09-18 07:31:07 UTC
Last online:2018-09-19 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2018-09-18 07:32:07 UTC to abuse{at}unifiedlayer[dot]com,ipadmin{at}websitewelcome[dot]com,abuse{at}hostgator[dot]com)
Takedown time:23 hours, 36 minutes Good (down since 2018-09-19 07:08:20 UTC)
Tags:doc heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-19Invoice as at 19/09/2018.docdoc 92db91577a4b1926cf181729ddbfbb61f16aef8520aeaf56a4a4a6d5c7ba3c1dVirustotal results 44.26% Heodo
2018-09-19Inv. no. 3T4V8492.docdoc 82b649d074063f4e07887337e94459474d0cbee28627802c8f2022c58fa8414dVirustotal results 46.67% Heodo
2018-09-19Accounts - Invoice.docdoc e8025adabc32213ac3b761dbfc6d13eb0e0a66cf9f7ed26d32fd97063c09c968n/a Heodo
2018-09-19Outstanding invoice.docdoc b12c2a253804425152d82fcba170e3654f4eee72368245554a5073136c45195fVirustotal results 40.98% Heodo
2018-09-18Review invoice required.docdoc 87ec5f127d0eb913dcc9228930fca402403b5911d7e7329af9ffc4e6f0494173Virustotal results 44.26% Heodo
2018-09-18Statement as at 19.09.2018.docdoc bcd5e00300fe88f6716e7cb852f95c27950e2bf0c80ff55d27172db369cc059eVirustotal results 42.62% Heodo
2018-09-18Billing Invoice - Job # 0203562.docdoc 11c4c9955d77e8c297320755568bfeffd73e77b2f8f6d516aec73bfdcb4ae5c5Virustotal results 42.62% Heodo
2018-09-18Customer No 712223.docdoc fdd5b1d003aa632d667c4169616603e87eeeadf004e5385ad8ec31735a3af47fVirustotal results 40.98% Heodo
2018-09-18Customer No 833091.docdoc 3863a43d951e8365e96d5d982a3cb178b260c608a904c378d048b8715406802fn/a Heodo
2018-09-18Statement as at 18.09.2018.docdoc dcd0d2367cf1140e7802c9b55f813767a698b39f94ec5fb4c1b4cc603856f155n/a Heodo
2018-09-18Invoice # 48VI9154.docdoc 32672ba948b154df420ba14abb99948d5b1337f0782e1701e08e52c4457beebcVirustotal results 29.51% Heodo
2018-09-18Billing Invoice - Job # 3014927.docdoc ea7be9a5b95aa367a2f5b182a189da831c19b70d54bbea74c43f801be69b1c1fn/a Heodo