URLhaus Database

You are currently viewing the URLhaus database entry for http://pngbreakingnews.com/cgi-bin/5CB08/X25/481yxinz-0090/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:730027
URL: http://pngbreakingnews.com/cgi-bin/5CB08/X25/481yxinz-0090/
URL Status:Offline
Host: pngbreakingnews.com
Date added:2020-10-21 15:52:10 UTC
Last online:2020-10-28 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 15:54:06 UTC to abuse{at}microsoft[dot]com)
Takedown time:7 days, 5 hours, 21 minutes Bad (down since 2020-10-28 21:15:51 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Inv. 30084116.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 39.66%Heodo
2020-10-22Form - Oct 23, 2020.docdoc 7104dd32f9de62701f5d5a01ac763237757d11e8fa2c10ec24749f5791467fcbVirustotal results 38.98% Heodo
2020-10-22Payment.docdoc 86ac3d592d28aef479ad69aabb33de92fa7dc8f50a31a4ccb8090cd1c6a3fa98Virustotal results 39.62% Heodo
2020-10-22004268663.docdoc f95869656ea95b50cdc0dcdc93991a0bff0a1c265541f45bf204766fb5870736Virustotal results 39.62% Heodo
2020-10-22Payment status.docdoc 188d183f83a1b99f55ae2810384c67e6f7be09014e6004bb5ddbf245abda02b3n/a Heodo
2020-10-22invoice #48679.docdoc 12e6288fa176b86b7658d14a6f17935f324b38b4b454088088c6aa7548b9e905Virustotal results 37.25% Heodo
2020-10-22Form.docdoc a92e9fd1aaea72831f29e20e4afe829f2fd63c7645e2ae3b8b4786a8ade2b0b6Virustotal results 37.70% Heodo
2020-10-22Form - Oct 22, 2020.docdoc 837053e508d4b63b491b2e13135ab62be34d6cafbc9a8cbd7d763816dc17f4afVirustotal results 39.34% Heodo
2020-10-22Form.docdoc 2a3debc28e12818dd54c53582337c7024a1cfb99138ea2baf06c6b45a36efc2bVirustotal results 38.71% Heodo
2020-10-22invoices 9116 & 9164.docdoc 709d844ebb9040838314e0bb22f53af41eff662d3b322cfac5858710def23245n/a Heodo
2020-10-22invoice.docdoc dfb6817c6e31d81f6a98945394150b500c04fb563d8fe9ae170733fc922f8421Virustotal results 40.38% Heodo
2020-10-22invoices 93564 & 21926.docdoc b297a103aaa08649721ae6d213d337f4edbe265f325db9d9dd077501e8074cf7Virustotal results 35.85% Heodo
2020-10-22Payment status.docdoc 79736f48bc5bedb3ed839a65879732bd7302955da6defa742dbc590f04c2d043Virustotal results 35.71% Heodo
2020-10-22invoice #578671.docdoc 01b228cd4f024acce23be7b762797915e8ece1d47c301e20f9596a98aed2acb5Virustotal results 49.06% Heodo
2020-10-22Copy invoice #417439.docdoc c997bba83eb4e15d19a871e5f4e7f506eb780772858f744dd12742b9c678e897Virustotal results 50.91% Heodo
2020-10-22HU0063 invoicing.docdoc 8849667217cbf5aaf17be7bc7eaef3b073f32d6d7d7a6f36a022c270228a0d8bVirustotal results 50.00% Heodo
2020-10-22PO# 10222020.docdoc 5faf67cb4b9dbfd86904abb00fed294cac743cafc127f9502b779ffc6aedb7c7Virustotal results 50.00% Heodo
2020-10-22Form - Oct 22, 2020.docdoc 65fab287607d55bb546b639bcce9b869bae1c1fda07a15c68e1b9ebe8a626a68Virustotal results 49.06% Heodo
2020-10-22Form.docdoc 64ee7027b8c1fc6f5a53589c1b063a42cf59f5a99924588ae219a9950fbe7130Virustotal results 46.67% Heodo
2020-10-22Inv. 0181218006.docdoc 48c4356a3629c972a22b83fe612ed12ed47467fd7085e18ac16786cbd9c2bc4aVirustotal results 53.70% Heodo
2020-10-22Payment.docdoc 098b7a1d812c209b85974e1f187e3a670e02821164c1dba212da04d78e86ff33Virustotal results 47.17% Heodo
2020-10-22272409.docdoc 973f68fa660b0ff4da0047bc9d942a6f2faf63713e745fe19eaf4cf5d29828ben/a Heodo
2020-10-22Electronic form.docdoc 4c0eefb631af43ca75f18562817c8ac29361fdf7b5a528341efa855a8d1c6a6an/a Heodo
2020-10-22Payment.docdoc 889113bf50a9e3543f97ca07e4e572f2328587944be4de82f441ba1b23e6ece1Virustotal results 38.89% Heodo
2020-10-22Payment.docdoc 077db39d1c6f7785aa6191761f4033eeaf24c81e2c0ed0f104e798e63a6a1c4an/a Heodo
2020-10-22INV_456803.docdoc caa64b3ac297b61892889a9f4a29cb2bd5719a809c2b610c07fdd30c5c9f7129Virustotal results 45.16% Heodo
2020-10-218687442596PP.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo