URLhaus Database

You are currently viewing the URLhaus database entry for http://testsite.muchscu.org/cgi-bin/parts_service/40677/f6pkh-0676427/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:723796
URL: http://testsite.muchscu.org/cgi-bin/parts_service/40677/f6pkh-0676427/
URL Status:Offline
Host: testsite.muchscu.org
Date added:2020-10-20 13:44:03 UTC
Last online:2020-10-20 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 13:46:07 UTC to abuse{at}reliablesite[dot]net)
Takedown time:4 hours, 59 minutes Good (down since 2020-10-20 18:45:27 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20Inv_184385.docdoc 306d01912045e266a9fe2015a5ef474be9768263f196550ab49052a0c676cef5Virustotal results 33.96% Heodo
2020-10-20Inv. 613965.docdoc f58cbfc9a8abe26d8ee344b97d04bac6ed709bdc6e3920b6b4cc4f6fe22bdabfVirustotal results 30.51% Heodo
2020-10-20Payment status.docdoc 7e136d3bc68a6578cdb157624c2783f78b48a13944133de3d0f5b0d34ce6ffa2Virustotal results 30.00% Heodo
2020-10-20Invoice.docdoc f64d1d64e95cb52e8ac1e43c619b165f65e0a882fb8d0e8314f2e82271425089Virustotal results 32.79% Heodo
2020-10-20INV #59861 FOR PO #0000708848602.docdoc c7bae32f76eebe4cb2fdbd687d6d09d30ea38d1c6751a1ae5cbee6c9bfb5b96dVirustotal results 30.00% Heodo
2020-10-20K03 invoicing.docdoc f86eebc5209b2e92bd174a3c00c80a3b021c7ab0ba5c60b46e91b9d92d8f23d6Virustotal results 30.51% Heodo
2020-10-20E-100120 ZFMJ-102020.docdoc 6664d59aec5871d443503652ecf25bac9b57963b8022e44f0d00711ec4aca495Virustotal results 30.00% Heodo
2020-10-20invoice.docdoc fcf66fd33f42c75abf852452c661e3ccc4f85c48a721dbc4471bd28332760145Virustotal results 51.61% Heodo
2020-10-20invoice #99365.docdoc 354fea5033e720e774f141b26f7606a4d844f9e990565c0c9ef51558c3581836Virustotal results 51.61% Heodo
2020-10-20October Invoice.docdoc 2f0abbe89ce350352b4029575dffb4895f42d2296aadc1745287763704b7093dVirustotal results 51.67% Heodo
2020-10-20ZZ1666625408FH.docdoc c31795e9d2a3b7bf6e19d054a2574f0ea3eef997e49bd9318316efd609cada94Virustotal results 50.00% Heodo
2020-10-20PO# 10202020.docdoc ba0c80b63d4eeb717fc84124358ac5f00d1ccd8e02b842dc16f47920a33363b7Virustotal results 50.91% Heodo