URLhaus Database

You are currently viewing the URLhaus database entry for http://insurecars.co.za/wp-content/77328854635657/0ewfc3le-0082560/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:724280
URL: http://insurecars.co.za/wp-content/77328854635657/0ewfc3le-0082560/
URL Status:Offline
Host: insurecars.co.za
Date added:2020-10-20 15:44:04 UTC
Last online:2020-12-23 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 15:44:19 UTC to abuse{at}godaddy[dot]com)
Takedown time:2 months, 4 days, 6 hours, 5 minutes Bad (down since 2020-12-23 21:50:13 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23Payment.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 75.41%Heodo
2020-10-21Payment.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 49.18%Heodo
2020-10-21Copy invoice #52305.docdoc 7301eb52916c5b004b3f81ebf360c397e25aba900652108420b868313afce2aen/aHeodo
2020-10-21invoice #5532.docdoc 31658c6055bda692c4a944b0dd23ef5f0ef7d312df172a1eafb6317a110f286bVirustotal results 48.39%Heodo
2020-10-21Payment status.docdoc a190cc4bd4d39b253f7e560cdf793dd829f74b0f816bbddc666525007a02412fVirustotal results 47.54%Heodo
2020-10-21Invoice 0945833.docdoc e321ead5188a4d2e7abd2c7f2ca1bc74c905e875d34703bea49fa84c50cf4ed0Virustotal results 42.37%Heodo
2020-10-21008889.docdoc df0901fe828ab8ff739461f32f011dd20e5cf34df476de9821c56d8bc6e9528dVirustotal results 44.26%Heodo
2020-10-21J003 invoicing.docdoc b5ffec3587a49bc07b737c4a095b6822dfe32ab6f54062ab3720d31490849eaen/aHeodo
2020-10-21Invoice.docdoc 15680f3d4397a2ea2191e960421dd8650642415c14be15b1495f859bc6b9d7cfVirustotal results 40.98%Heodo
2020-10-21Invoice 0005852.docdoc 916c5fa5d800ce852e4e0e1c215daf1e813c868e5b1d9b0c7956b16ec6649adfVirustotal results 41.94%Heodo
2020-10-21GBR-100120 FFZE-102120.docdoc 663930eb12ff6afb8cd3d0410fcef8fa32edf4964504e10f0cd56af546b0ecb2Virustotal results 41.51%Heodo
2020-10-21Payment status.docdoc f75dfd9100b7fb7c93a95812e11a04f911e4ed1f61fafa8b73c747df9898a212Virustotal results 40.98%Heodo
2020-10-20INV_317988.docdoc d590ed65aef80ecdc7f0a44755ee436937f30c0b05287ce6d177b654512940e8Virustotal results 40.98%Heodo
2020-10-20Payment status.docdoc d2b7e7d77c65f006e6878f64efc31bcc0fdcacf7293e2e19c30e3bf4e40b09fcn/aHeodo
2020-10-20Invoice 3636102.docdoc 306d01912045e266a9fe2015a5ef474be9768263f196550ab49052a0c676cef5Virustotal results 32.76% Heodo
2020-10-20DK2104250810ET.docdoc 4217ed123cc2bd063b8cc599340aec39fda437a4e62df3118a01251a915c226bn/a Heodo
2020-10-20Inv_09954.docdoc 18286f51c980997e07241a170822a950f101cfa264c232edbfcb4d67694d5b45Virustotal results 31.15% Heodo
2020-10-20Payment status.docdoc 6a003ad11e4785ca68e20e102246780b6e3d1ef660453fed530da4ba2ed14639Virustotal results 30.51% Heodo
2020-10-20invoice #20370.docdoc 2578a0f788096c10b3bcb14ac8c024f44b035e361ca8e1af809c81fb4cdc6ad6Virustotal results 32.79% Heodo
2020-10-20PO# 10202020.docdoc 0c826456d4bf7da7aaf36377a19de56cb2712b94c047a86518ff7745d252479cVirustotal results 32.26% Heodo
2020-10-20invoices 22346 & 6803.docdoc 47914da6e4ee4b6892b42cdb0076cc23a9887a862a7b366434d7c77c0a21123dVirustotal results 32.26% Heodo