URLhaus Database

You are currently viewing the URLhaus database entry for https://www.ommurticreations.com/cgi-bin/form/947145/eqyoo39-00338434/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729659
URL: https://www.ommurticreations.com/cgi-bin/form/947145/eqyoo39-00338434/
URL Status:Offline
Host: www.ommurticreations.com
Date added:2020-10-21 14:21:06 UTC
Last online:2020-10-22 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003025950 created on 2020-10-21 14:22:11 UTC)
Takedown time:1 day, 0 hours, 29 minutes Poor (down since 2020-10-22 14:51:49 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Inv_4603.docdoc 4a44eb422716acd382deed2b165d37ce8de2d799d1c466a1aa2e1952f4b943eeVirustotal results 45.16% Heodo
2020-10-22Payment.docdoc 5fb5309b154278b57d6a94d784dd5de602c441608e00557aa6c53c200ccbb3b1n/a Heodo
2020-10-22invoice #74177.docdoc 2bc5c1591569f6e8a480a530bf343df21867da564b7503824cb0e5193d3f8937Virustotal results 46.15% Heodo
2020-10-22INV_80412.docdoc 889113bf50a9e3543f97ca07e4e572f2328587944be4de82f441ba1b23e6ece1Virustotal results 38.89% Heodo
2020-10-22Payment status.docdoc fcc90ffa2119faa6417ad4df76ac4e324afd8f543b1e3896337c6ce2ba635a21Virustotal results 42.37% Heodo
2020-10-22Q0265 invoicing.docdoc 410f511f7ba84ffbd69fbabc0226828f52eec22c5b5db6759f60fb65ea20270an/a Heodo
2020-10-22INV_93589.docdoc 72da9c13652853256f7cab8762f533e63f52328ba4b06d4bf44d3dc0cd5fe2c5Virustotal results 46.30% Heodo
2020-10-21Payment.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo