URLhaus Database

You are currently viewing the URLhaus database entry for http://mainlis.pt/doc/En/Inv-375448-PO-5K520813 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:63559
URL: http://mainlis.pt/doc/En/Inv-375448-PO-5K520813
URL Status:Offline
Host: mainlis.pt
Date added:2018-10-02 11:01:16 UTC
Last online:2018-12-07 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-10-02 11:02:06 UTC to abuse{at}ptisp[dot]pt)
Takedown time:2 months, 6 days, 5 hours, 47 minutes Bad (down since 2018-12-07 16:49:13 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-10-03Accounts - Invoice.docdoc 724613c782464a8292e0aedaa3af7d4f2a30146c3d68a59cbd53a0a670f7f440Virustotal results 29.51% Heodo
2018-10-03Invoice # 2NQ528465.docdoc 1cedd14a129c1784a6216e72c1f98168de9ffa0d0df2f5367548bd396b03b890Virustotal results 29.51% Heodo
2018-10-03Billing Invoice - Job # 370920.docdoc 8903fb1a6080570556c4217c3f329c66c3000b71163a5449047edfe701018456Virustotal results 23.33% Heodo
2018-10-03Outstanding invoice.docdoc f307a8dba269262ffd35549938a7c950e83ea534734a752dc385c3cd00594a1eVirustotal results 31.15% Heodo
2018-10-03Invoice # 36DC021664.docdoc 1c8382645c92a3727199a84dfc792638b2fc26d5d4c67c95565fc32d25f60aecVirustotal results 31.67% Heodo
2018-10-03Final notice.docdoc ba063a282be3c86d05ba721ab2635cd920c88038ce5804a2732b4f716637b286Virustotal results 31.15% 
2018-10-03Month notice.docdoc 87e95573aa86825445616e4333b8878c6829ca9b125fc5947ddb80da3f900eeaVirustotal results 27.87% Heodo
2018-10-03Latest invoice - 744047.docdoc a1537896ddc2ee52cc1d06b82276ddb12a79c3477d49def47fe8585c12f38437Virustotal results 27.87% Heodo
2018-10-03Invoice # 8D901815.docdoc 1a5171472f15d1a715dbd9d8b108cbbed096404db6067b34e86936a5c603b50an/a Heodo
2018-10-03Invoice.docdoc cabf953f0c7b1ade83647ced760070d2d72e9f57dd9a2c7ec7e4177141849d7aVirustotal results 25.00% 
2018-10-03Invoice Confirmation MH314269.docdoc 35c3c740de000235df89a4eff4cd6e4e3b1bfedce77336850b75af2da7a9c51aVirustotal results 25.00% Heodo
2018-10-02Outstanding invoice.docdoc 615552f123608583a949a390c8fbae2842bd52926b3b143a6c47d8667e3ba3afn/a Heodo
2018-10-02New invoice 4XQ19641.docdoc 50c1bdfa56a73c43368705071d2e19b58d2fe77f537feb32919b2b77a1323288n/a Heodo
2018-10-02Statement as at 03.10.2018.docdoc f4adec35401a9340582e3dc9ccd784be3e296ca4ed88f04fa4fc387f56420f6fn/a Heodo
2018-10-02Invoice # 4JE7654.docdoc 6453be335f33d287158e7886518d28d888ab375e24abf7448f3231bc9c849635n/a Heodo
2018-10-02Billing Invoice - Job # 1736015.docdoc 5ae507e8d93f6a451324da2c9a5f73dbf0d0d847bb56e29ca58e0d9f6047e91dn/a Heodo
2018-10-02Invoice Query.docdoc fb02e8091d17c95a14792002d1bc5b4811422c15929ea55177b5d24f3b4cbb1fn/a Heodo
2018-10-02Invoice.docdoc 55c9e5e566fe3aa14796e7d667bbbb3000e1bb49c1add4b15d07cb7a1ec16317n/a Heodo
2018-10-02Invoice Query.docdoc 1066d6e26ab51099ecfe1a778c2ba217b511bd169facd51cfd9eb83d781c7882Virustotal results 30.00% Heodo