URLhaus Database

You are currently viewing the URLhaus database entry for http://whiskeycreekoutfitters.com/cgi-bin/invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:704139
URL: http://whiskeycreekoutfitters.com/cgi-bin/invoice/
URL Status:Offline
Host: whiskeycreekoutfitters.com
Date added:2020-10-16 21:42:08 UTC
Last online:2020-10-17 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 21:44:35 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:20 hours, 59 minutes Good (down since 2020-10-17 18:44:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-1746581255.docdoc 360a5cb7eed923017b4ef07460e7652362cdf1fc0a902516addbb8e244e30134Virustotal results 53.23%Heodo
2020-10-17GML_100120_MXH_101720.docdoc b0f945ed6afda303421f9501b2b2d1d2996a132eb27486911019cb9996538460Virustotal results 54.10%Heodo
2020-10-1763274145.docdoc ba34959e897c2ec63c8cba1a6da0e8711cd958153938466386cfe70cc8f2df52Virustotal results 50.82%Heodo
2020-10-17RSRG_LA9645440059KP.docdoc 169fa4037e8c45a38a3b2e862d860e955fc810c63682c78155bbbd45820b83bfVirustotal results 54.84%Heodo
2020-10-17PO_10172020EX.docdoc 08171ab9613c40f0cffda97d95d104eabd33aca151d19a4315b8e2ec2142fb63Virustotal results 53.33%Heodo
2020-10-1706597650761.docdoc 8eed16b7e0a64351cb06ea437eeae8f69b227cac04237187ed17cff470a3cb0dVirustotal results 52.46%Heodo
2020-10-17REP_PO_10172020EX.docdoc 9fddabb44e0d01bdc8e0886790e1e34059ac1aedbe3faf4cdfa66bf9dec923cbVirustotal results 53.23%Heodo
2020-10-17GKNK_WZ7278533975LA.docdoc d6b61570ca15f09c5e9707aaa5658abb2ff3c1916805b287b31ceb75a95f4130Virustotal results 53.23%Heodo
2020-10-17BAL_1OYHU5HIMPJP.docdoc a9c15187e473446421b0e900dcd094ee8be1c5ac010d6d2a19bcc988f60d7ddbn/aHeodo
2020-10-17PO_10172020EX.docdoc cab952f8c6436054516b7fb9b6dc980a0921858a4a312229099f2817b9846340Virustotal results 54.84%Heodo
2020-10-17DOC_T0H1C4LNVBJU46D.docdoc 7f7aaae8116f26c7d91c5c3d87ab7c7a752e628195c25563cc7c3074669e6c7aVirustotal results 54.84%Heodo
2020-10-17EH_XHS_100120_FOX_101720.docdoc 127e5f88e44a1886181820087f5a2d1bb09ecec7ca49c027c33c9cdead79c1acn/aHeodo
2020-10-17DOC_PO_10172020EX.docdoc ab8be8e21a7c5f0a158818bdf5fa9883acaffa78d8cfa5cae36ba7d756b8fed6n/aHeodo
2020-10-170434805544.docdoc 499b6b84f53cf364ec9102e8947398e3435340efcc0638338dc94d2ffe7f635dn/aHeodo
2020-10-17BAL_VH0909871539LY.docdoc 7563b098e425087d70e59bc0ad1d712d39ec6286fc63eaa9a9eea68f9a7ede26Virustotal results 51.61%Heodo
2020-10-17XZR_100120_XOH_101720.docdoc 8358ae3aef04560a786b84a17aa88a981d700993291a3b11aa001fab16829ad9Virustotal results 50.00%Heodo
2020-10-17AO5171610061JF.docdoc d1e952f7b8eac274a9eb54c0ce6e8c6542aaa16cbdf7345c10c79852c2d5bd0dVirustotal results 50.00%Heodo
2020-10-17DOC_DD9022582526WJ.docdoc 33e3f84944619fd92c3e53215fafb2b4b962f3e7b97ac0e358959d8ca710de70Virustotal results 50.00%Heodo
2020-10-17SU4367125195FJ.docdoc 02730b23749bb5e945d78771425520fe94a15b5647f34a7efeca54a72c9297c9n/aHeodo
2020-10-17FILE_PO_10172020EX.docdoc db234da6bba5f671c8a6fad07cfc6ad7ce1b078a32f920e2edb4b142167e18dcVirustotal results 51.61%Heodo
2020-10-17REP_OQQLHT0RUQA836.docdoc cad389f338446345616f9a4f005b47f186be55fdd914d1b88f42bc4f26220685Virustotal results 50.82%Heodo
2020-10-17ZI5792916620EZ.docdoc eb06448eea7b0d73132945671275ea572688e13de195a89974d8315900ff8cb7Virustotal results 52.46%Heodo
2020-10-1717764285.docdoc af4011781c0a2add45a6f72b8d52e5bd7d7381ff28c93e478dede0ff100ff237Virustotal results 50.82%Heodo
2020-10-17XXX_100120_DWI_101720.docdoc 99acccb026919eac0d3249c8a9207a71d032fbe59c7540c12aee398ae86e6780Virustotal results 50.00%Heodo
2020-10-17INV_LQO_100120_HGO_101720.docdoc 1f9fcb8ad3585c6cbf7250308fc58ebd7fd913baf350cbd3d7fd8934c9e33e43Virustotal results 50.00%Heodo
2020-10-16DOC_630340691855790.docdoc c25321d27755dd74dfcb51c16c96a607d16b09b59b1cbe7f025dc89763d9d630n/aHeodo
2020-10-16INV_5130620874.docdoc 53467ef76cb2d0f4cc9404439089220dd6d34680c167f2f062307713724ee9bbVirustotal results 50.00%Heodo
2020-10-1683389473.docdoc 6647111dcc98f3a01470eee7de5a3b93b579a08c585cd3553cbfbdf3d54db556Virustotal results 48.39%Heodo
2020-10-16Z_91928749.docdoc 6539d2ac4a847b3444866e22b642a335e3d8b92d40031a090fa315aef1af2930Virustotal results 51.61%Heodo
2020-10-16BAL_97255230.docdoc b22624074fb5efd4b4c7a4882f6a7bf06faa842197e9fc9199e85c8c1fe02b8bVirustotal results 52.46%Heodo
2020-10-1610963560.docdoc 59330f6abd11ccf8373697955746b598be71ca8c69774640b41ebd9650abb398Virustotal results 45.61%Heodo