URLhaus Database

You are currently viewing the URLhaus database entry for http://ultimatebonus.net/cgi-bin/form/nsxqkoojg-0020140/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725459
URL: http://ultimatebonus.net/cgi-bin/form/nsxqkoojg-0020140/
URL Status:Offline
Host: ultimatebonus.net
Date added:2020-10-20 20:49:03 UTC
Last online:2020-10-21 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003024531 created on 2020-10-20 20:50:06 UTC)
Takedown time:1 day, 2 hours, 0 minutes Poor (down since 2020-10-21 22:50:13 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21Invoice.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 33.96%Heodo
2020-10-21Invoice 07382916.docdoc 95cc36236ff79a346718e90e5015315ec3f419d22f5ce7ed1d2abbc04eab70b9Virustotal results 32.26%Heodo
2020-10-21Inv. 087120352.docdoc 41355a097538a80c8204c61e7eb31f408568aa25e3593d587b0dc41e95838f6cn/a Heodo
2020-10-21PF-100120 ZCDR-102120.docdoc 958a56b45155799f98c055be1da4870f014dfc78b57a8c92a1c62c8b9a947248n/a Heodo
2020-10-21002842014.docdoc e45c71c909dafaee0830088e9068e0cb0f2f99e5ab1ff7da592240e46ba6fa58Virustotal results 29.03% Heodo
2020-10-21T-100120 FRQD-102120.docdoc d6722700e4deec26acf704986fa3460027afa685e40acd627dd4d9b85c0f199bn/a Heodo
2020-10-21Electronic form.docdoc ef59fe140a6b63b4aae9e7e31953441b4560e00bb76a3b2eef15fc04f5e1abb8Virustotal results 27.42%Heodo
2020-10-21PO# 10212020.docdoc f492868f49d7ac388ea92c1bf5895ce59c3b1de49e2d3b397a6987eb4c32abacVirustotal results 26.23% Heodo
2020-10-21invoice #6666.docdoc cf275b27c9d9ff1afbbf89c46cd4546584c4a173ddc75405c48b7ead240f7b0bn/a Heodo
2020-10-21Inv. 072561562883.docdoc f41d3c54b63ec1671bd601f1800ff185f8c325398a4ae3e1747d7d2421a2bfe1Virustotal results 26.67%Heodo
2020-10-21Payment.docdoc 1c615910d79aa7763683cab844eb3542e60cdc0b9052bf2649a0fe8034ccaa51n/aHeodo
2020-10-21PX-100120 UIVD-102120.docdoc d00125dd0f069c23c0ae5f95db081c57dfd23bc67fd5308053a4204ace382b4cVirustotal results 24.59%Heodo
2020-10-21invoice.docdoc cda828dede96620b0eed85c89ba9eebb9aae7aa5f6b54141207e8f0f9e44e0ebVirustotal results 28.57% Heodo
2020-10-21Inv. 0033949.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21Invoice.docdoc 7301eb52916c5b004b3f81ebf360c397e25aba900652108420b868313afce2aeVirustotal results 48.33%Heodo
2020-10-21S95 invoicing.docdoc 31658c6055bda692c4a944b0dd23ef5f0ef7d312df172a1eafb6317a110f286bVirustotal results 48.39%Heodo
2020-10-21SW-100120 GXMG-102120.docdoc a9b5951976e5aebe82b1a18ef33e379ec5f3a36a04b89103649e54d7dc746aecVirustotal results 49.06%Heodo
2020-10-21invoice #5922.docdoc cbc98038cc0dab8d10dbfa4950f8228777c05eee346ce80ab1f2002c51939ac1Virustotal results 46.15%Heodo
2020-10-21October Invoice.docdoc e3812e0aa164c68399e61ce76904450c3e6bc028111a3c4df2155e37ad5d01b1Virustotal results 44.44%Heodo
2020-10-21Invoice.docdoc a83dce48be132b625d87853a68a56238720b2fad3e3bfb67c50bdf1d677a98ddVirustotal results 43.33%Heodo
2020-10-21Inv_9827.docdoc a3bd9261b5a8844a6a6a77e06f0eabf6a21d998001e99718a42f8bfc8147762dVirustotal results 42.62%Heodo
2020-10-21invoice #9307.docdoc 29cdc20b4b547e832ab1e9c0eeff5b71201efe4262d8d542a8b359131f26ed1aVirustotal results 41.67%Heodo
2020-10-21Form - Oct 21, 2020.docdoc 916c5fa5d800ce852e4e0e1c215daf1e813c868e5b1d9b0c7956b16ec6649adfVirustotal results 41.51%Heodo
2020-10-21Inv. 09008897.docdoc 663930eb12ff6afb8cd3d0410fcef8fa32edf4964504e10f0cd56af546b0ecb2Virustotal results 41.51%Heodo
2020-10-21BY7753182694FN.docdoc f75dfd9100b7fb7c93a95812e11a04f911e4ed1f61fafa8b73c747df9898a212Virustotal results 40.98%Heodo
2020-10-20BI987 invoicing.docdoc f98b21e5ba36d3d933fdd95c54037c9a3412c52fd05700222580a7e4267608bdVirustotal results 41.51%Heodo
2020-10-20form.docdoc b07a48ca7d09a730829f65f399a5f0496e4c14989705d83a73630dc2a67f80f0Virustotal results 40.98%Heodo
2020-10-20Form.docdoc 9be377b592614918b5f4aa295f73afeb586e3e386f7bec12cf04637f31433d7bn/aHeodo
2020-10-20October Invoice.docdoc a85c57fa12d0087eb6da3bbeff4a027b351978d8b8073086c43d522366e5fe9en/aHeodo
2020-10-20Form - Oct 21, 2020.docdoc a8e92bb15ad9bcd8e93e71644a570c2aeb6d030e2b496412500deb4ee2a23889Virustotal results 37.10%Heodo
2020-10-20PA004 invoicing.docdoc c1a2f053ac0b9cafe6d08072e6971d0dfad8f938cc167753df413b1a5ee4065bVirustotal results 32.79%Heodo
2020-10-20PO# 10202020.docdoc 80112c9d5f76aa1687aa0df70c0d7f1d96f1b7524da942b87480ff37231091e8Virustotal results 32.79%Heodo