URLhaus Database

You are currently viewing the URLhaus database entry for http://mysitetrip.com/PHPMailer/788691485335836/xwjs-006714/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:717740
URL: http://mysitetrip.com/PHPMailer/788691485335836/xwjs-006714/
URL Status:Offline
Host: mysitetrip.com
Date added:2020-10-19 12:39:04 UTC
Last online:2020-10-21 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 12:40:29 UTC to abuse{at}servercentral[dot]com)
Takedown time:2 days, 2 hours, 23 minutes Poor (down since 2020-10-21 15:04:15 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19October Invoice.docdoc b52f4d01a0ab4d1cc721d51d83479234dda82213536075936f096f0d1203552eVirustotal results 45.16%Heodo
2020-10-19HPS-100120 KMTJ-101920.docdoc 96d88d8f9d91defeac3ba252e0b4fd5d37a9d58d3eb583ab00c38e7d3900edd5Virustotal results 37.10% Heodo
2020-10-19Electronic form.docdoc c2d708d7a95248e357a4b1ffbfade73c30676261a296acaddb1126e6cca85c7eVirustotal results 37.93% Heodo
2020-10-19L82 invoicing.docdoc 159b1dcd50701b604d7b54ca877818cf865ea30b51d029f649077d68265d7dbdVirustotal results 37.10% Heodo
2020-10-19invoices 65113 & 7044.docdoc 1342d806b2b4c5f985373fd1e8c09df85566108333cc0d1b83d89b157e1e663aVirustotal results 37.70% Heodo
2020-10-19C-100120 KHUJ-101920.docdoc 4aa74b49409e94ab976c378a624a8433b8b366a4ae90469b3b21d5f79c4accbcVirustotal results 29.03% Heodo
2020-10-19Invoice.docdoc f6331a9117aed819880d4d64c61c95084cd2f79b04b26bd7cf31028135367961Virustotal results 33.93% Heodo
2020-10-19INV_8381.docdoc d0ce767ff487db2650ddbe88d8ea48a14fefa5a7f0414104471bb87aaf2d8d31Virustotal results 35.71% Heodo
2020-10-19Invoice #8405.docdoc a5e0b39bfb2940276129d16f3fc3ff000386b32d37f86e87c7851d8f5b9047dfVirustotal results 32.26% Heodo
2020-10-19Form - Oct 19, 2020.docdoc 9cf56ebc5e58b34ab1632a4c30a334d9832c086258739c067ed83a334510992fVirustotal results 29.03% Heodo
2020-10-19Electronic form.docdoc 58b40a92a4676cecf2525d02ce4d55bfa8d035962252374007609b18c644d76eVirustotal results 30.00% Heodo
2020-10-19Copy invoice #8625.docdoc 087fd4cd1a8f90ea9b00236885e326c54f3478939949bccea90115fa52ac4dfbVirustotal results 30.65% Heodo
2020-10-19Electronic form.docdoc 15dd904a0c19479d474256cfda9e44f5d8b63d3e08bed5604da40c6c4ab14707Virustotal results 30.65% Heodo
2020-10-19O-100120 JUJW-101920.docdoc 1f7c5a9b21be39518f174f546e3df5997e617fb082d043d43540a774c6159f41n/a Heodo
2020-10-19Invoice #1350850.docdoc 8b556f9746db0fc7f51d52bf05efbadb0d23c4a926e03fc453ebe4130e94e18eVirustotal results 27.42% Heodo
2020-10-19INV_615213.docdoc 48e47f4f38a8a75d27f390be7aba2a82303b7a0ce23b462331814a6c61235012Virustotal results 28.81% Heodo
2020-10-19Electronic form.docdoc 6510557442baf6b31805cf410d325ba2fdba9b3c28800b0184cdc8b494f42870Virustotal results 29.51% Heodo
2020-10-19Form - Oct 19, 2020.docdoc 0dc24e6403ef1cb7caa0c5ac6279db62b96aff3ce815de2b1e2c29ddadba47c4n/a Heodo