URLhaus Database

You are currently viewing the URLhaus database entry for http://dsspainting.com/gm-navigation/sites/5730833517423/82f6mk-0042370/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:726738
URL: http://dsspainting.com/gm-navigation/sites/5730833517423/82f6mk-0042370/
URL Status:Offline
Host: dsspainting.com
Date added:2020-10-21 05:52:24 UTC
Last online:2021-10-12 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003025199 created on 2020-10-21 05:54:05 UTC)
Takedown time:11 months, 26 days, 7 hours, 6 minutes Bad (down since 2021-10-12 13:00:40 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-12KI00688 invoicing.docdoc fe69570cfe43c056f36d0a40929d53d4532cd181924613bda7436913979c33cbVirustotal results 68.75% Heodo
2020-10-22Electronic form.docdoc df51e418e047ba848de075954ab841887fafe6e47c6b7b6d529222e3795ecb23Virustotal results 47.54% Heodo
2020-10-22GV008 invoicing.docdoc 73dbec89c21200a9e7dd1ec67b06b9efad9718584b71af252f4926418abf32f6Virustotal results 48.15% Heodo
2020-10-22invoices 155 & 0612.docdoc 2c746449ae089b436ecab1058c035e9ea8e01fd8f45508ed2ed720ff30ee2c01n/a Heodo
2020-10-22Inv_051244.docdoc cfca456cd0b2f420fe799623f9e2bbf831e6463a73b754f9efd9f2eac8f9714cVirustotal results 44.44% Heodo
2020-10-22Payment status.docdoc 3abe5cdbb82a1a48fb89ecf043e24351ffb466cb6112ea7316f6fb518244a289Virustotal results 47.06% Heodo
2020-10-22invoice.docdoc 14a0d5ba65a4585300b4daafa06c20898b303bcea1302012ef2f19559124edbaVirustotal results 41.67% Heodo
2020-10-22INV_07009.docdoc 4d7e619f0381816bed7d0ffb6ea0a43ebd6050cbfb10f691c1bf8d8466c11345Virustotal results 45.16% Heodo
2020-10-22Invoice.docdoc 49e99a2c9064c24011dc0c71ff29d661e2b447f8213bc858b7feaa28d5d22576Virustotal results 44.26%Heodo
2020-10-21INV_4756.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo
2020-10-21ZA5900089875IG.docdoc 2a603eb060abe8cf0ce5259b69da9cdd0e5c3015332a943828ef24212ae982e8Virustotal results 30.51%Heodo
2020-10-2169428.docdoc bce4a6fe31eb854ee0fc5fb9c17c81ee19922b93a2998de467fdd004aa3ddf37Virustotal results 34.04% Heodo
2020-10-21Form - Oct 21, 2020.docdoc 691362c45442117e45c24d72759ba526d7b8d384114a90840a562ebf74ff1346n/a Heodo
2020-10-21October invoice.docdoc 12abe2772542ac1ffc94f0b0e88db86ca97976a83a371d0ce054b72a8ed1053fVirustotal results 29.03% Heodo
2020-10-21Inv_3123.docdoc d6722700e4deec26acf704986fa3460027afa685e40acd627dd4d9b85c0f199bVirustotal results 31.48% Heodo
2020-10-21invoices 562 & 78990.docdoc bf82d80c6784207b3b2b71c4c33d4e0a0866908ebdb14a571e6f36eb7b616c60Virustotal results 26.98%Heodo
2020-10-21E826 invoicing.docdoc 136727da9e9bf447ed1e4d28162afc8ff4af1819c1ced08571ee835190d56704Virustotal results 26.23% Heodo
2020-10-21PO# 10212020.docdoc e9a60c57f83826d551499e5bf6d5e52d163e80c8348699eb508d92f926cacb91Virustotal results 25.86% Heodo
2020-10-21invoice #1725.docdoc 50adbbe45a5b62ff5f3d9a11748102950c470799fd9c4e01eaeb9b93641c5ec6n/aHeodo
2020-10-21invoice.docdoc eacff736f8b2dd566e31558748f6a61037203b68ec084fdb29476ece21c3c246n/aHeodo
2020-10-21Invoice 0004201.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo