URLhaus Database

You are currently viewing the URLhaus database entry for http://xn--glrrj640lp9kt0l.com/huusui/0689557/ysi1-5220/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:725912
URL: http://xn--glrrj640lp9kt0l.com/huusui/0689557/ysi1-5220/
URL Status:Offline
Host: 双龍門占術.com
Date added:2020-10-20 22:45:08 UTC
Last online:2020-10-21 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 22:46:07 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:7 hours, 11 minutes Good (down since 2020-10-21 05:57:35 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21PO# 10212020.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21Inv. 084022185.docdoc a32b8fc89045749411368894b5eb70012518a8d9d1703b940bcbc966c0e40bdfVirustotal results 50.94%Heodo
2020-10-21form.docdoc a190cc4bd4d39b253f7e560cdf793dd829f74b0f816bbddc666525007a02412fVirustotal results 47.54%Heodo
2020-10-21Electronic form.docdoc cbc98038cc0dab8d10dbfa4950f8228777c05eee346ce80ab1f2002c51939ac1Virustotal results 46.15%Heodo
2020-10-21XS-100120 EIKN-102120.docdoc e3812e0aa164c68399e61ce76904450c3e6bc028111a3c4df2155e37ad5d01b1n/aHeodo
2020-10-21Form - Oct 21, 2020.docdoc a83dce48be132b625d87853a68a56238720b2fad3e3bfb67c50bdf1d677a98ddVirustotal results 43.33%Heodo
2020-10-21Payment.docdoc a3bd9261b5a8844a6a6a77e06f0eabf6a21d998001e99718a42f8bfc8147762dVirustotal results 42.62%Heodo
2020-10-21Inv_0074.docdoc 916c5fa5d800ce852e4e0e1c215daf1e813c868e5b1d9b0c7956b16ec6649adfVirustotal results 41.51%Heodo
2020-10-21invoice.docdoc 663930eb12ff6afb8cd3d0410fcef8fa32edf4964504e10f0cd56af546b0ecb2Virustotal results 41.51%Heodo
2020-10-21Electronic form.docdoc 470148839aa8007c61691a8cb506baef031b0bfc909e0a664bf3a94356e06208n/aHeodo
2020-10-20invoice #100147.docdoc 46771e0edd6c8d5e7018f34426fd4813d4b5293bc1b20def01e9c6e5e2cd632an/aHeodo
2020-10-20Payment.docdoc 368608fc48be7d6239425f9a9e23b2aa19d22aaa001796c8c0e391858bd2932eVirustotal results 39.62%Heodo
2020-10-20Electronic form.docdoc cf4ee7df0ffd61e8ffcd0559aad63ff1c60cfbe2b0f7bf5e3cb4d771218f8657Virustotal results 39.62%Heodo