URLhaus Database

You are currently viewing the URLhaus database entry for http://mainlis.pt/newsletter/En/Invoices-Overdue which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:64651
URL: http://mainlis.pt/newsletter/En/Invoices-Overdue
URL Status:Offline
Host: mainlis.pt
Date added:2018-10-04 08:16:28 UTC
Last online:2018-12-07 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-10-04 08:18:03 UTC to abuse{at}ptisp[dot]pt)
Takedown time:2 months, 4 days, 8 hours, 30 minutes Bad (down since 2018-12-07 16:49:01 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-10-05Invoice as at 05/10/2018.docdoc 14ab848a21e4370cbecb5bce9b9233d37aa0d9a02dd7e3aa32fb1ccdf052b07cVirustotal results 27.87% Heodo
2018-10-05Final notice.docdoc 06af85ead8ace7175c7fce3135baad5f8d146bb079744e7b31a8e7761cbb2fc4n/a Heodo
2018-10-05Invoice as at 05/10/2018.docdoc c46aef0622e3a83a844ee833a1f125789498b29d679f28045ba612c9b6844a82n/a Heodo
2018-10-05Accounts - Invoice.docdoc 888c87a45a97a7619d5ed9aea96b86ebbfaf05a011fa6b8d11dfe422e51d8f2eVirustotal results 26.23% Heodo
2018-10-05Invoice.docdoc cfecec75cbc7ef7db1d9a6644bd8455707edab35916ff2abac9035c73e6fc0f6n/a Heodo
2018-10-05Customer No 1719605.docdoc 953d26498fe4e0521ee404590959d35bcfd1ab2b74be8cb335eb6fc0893474c0Virustotal results 24.59% Heodo
2018-10-05Billing Invoice - Job # 6762399.docdoc 7e295bd30b23730351b4896be3e2cb8ca1587462e3726857f7472129c72db3b5n/a Heodo
2018-10-05Latest invoice - 114391.docdoc ced4c51202f3f21602ef67968a7ff20643ffa1d28c66951adee0382dbcdd38e5n/a Heodo
2018-10-04Accounts - Invoice.docdoc 7361150891c805498328f2fa5b365f1310d11537aaed9fc416f09c070ed9ec33n/a 
2018-10-04Invoice.docdoc 7d85dfb66cf19a7291dffa7c90a661d08d101819ccb64cce1e82aed57dec4b0dn/a Heodo
2018-10-04Statement as at 04.10.2018.docdoc 1d14dbb75eafb7983e6e7f5c1b6fba7be29a6a3d0e912375318345e543f6c055Virustotal results 30.00% Heodo
2018-10-04Inv. no. 6HYO471516.docdoc 9aa454a68b248d70a09129bab15950648cf4bfd67a9416d32012b00d58de59ddn/a Heodo
2018-10-04Review invoice required.docdoc 9025062857e1ec18f4b032a04ba3a5c87a6bc8b524dd7668fc9b2020e8da3cd0n/a Heodo
2018-10-04Invoice.docdoc 66ded24f149f56561b0f84ffe1d0f1b7d69a82ea556bbc7d59331368f946cbean/a Heodo
2018-10-04Final notice.docdoc 5686505912cc5bbd1797644e1e4cfe5db63e626609c3823f9f267de4e0f16b1en/a Heodo
2018-10-04Accounts - Invoice.docdoc 1ac98c4a82486676ac5f806f1e956e4b70215187bd3a2cc12969c7680e7cee24Virustotal results 34.43% Heodo
2018-10-04Invoice.docdoc bd2bc3ba7751098cc00f464280bbf9c63055093105b3a18363a3b93eee0d0f85Virustotal results 32.20% Heodo