URLhaus Database

You are currently viewing the URLhaus database entry for http://4glory.net/DOC/En/Need-to-send-the-attachment which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:57639
URL: http://4glory.net/DOC/En/Need-to-send-the-attachment
URL Status:Offline
Host: 4glory.net
Date added:2018-09-18 20:04:16 UTC
Last online:2018-09-19 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-18 20:06:10 UTC to abuse{at}unifiedlayer[dot]com,ipadmin{at}websitewelcome[dot]com,abuse{at}hostgator[dot]com)
Takedown time:10 hours, 54 minutes Good (down since 2018-09-19 07:00:20 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-19Invoice.docdoc 92db91577a4b1926cf181729ddbfbb61f16aef8520aeaf56a4a4a6d5c7ba3c1dVirustotal results 44.26% Heodo
2018-09-19Invoice Query.docdoc db06680ebb82a6d11d5b1e282386153d61163ce88c28d56c053cf302c60f131fn/a Heodo
2018-09-19Customer No 7015427.docdoc b12c2a253804425152d82fcba170e3654f4eee72368245554a5073136c45195fVirustotal results 40.98% Heodo
2018-09-18Outstanding invoice.docdoc 87ec5f127d0eb913dcc9228930fca402403b5911d7e7329af9ffc4e6f0494173Virustotal results 44.26% Heodo
2018-09-18Invoice.docdoc 32c8ab0b2762bb7c2ed5510280c9d880aee17e46f46bf652a12b6568de97fe8eVirustotal results 45.00% Heodo
2018-09-18Customer No 760406.docdoc 1a53ce6e01844b9c939595ff13155ad968dfd6123d704f97413c528f910689b0Virustotal results 44.26% Heodo