URLhaus Database

You are currently viewing the URLhaus database entry for https://ommurticreations.com/cgi-bin/form/947145/eqyoo39-00338434/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:731407
URL: https://ommurticreations.com/cgi-bin/form/947145/eqyoo39-00338434/
URL Status:Offline
Host: ommurticreations.com
Date added:2020-10-21 22:31:05 UTC
Last online:2020-10-22 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003026720 created on 2020-10-21 22:32:06 UTC)
Takedown time:16 hours, 24 minutes Good (down since 2020-10-22 14:56:11 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Inv_4603.docdoc 4a44eb422716acd382deed2b165d37ce8de2d799d1c466a1aa2e1952f4b943eeVirustotal results 45.16% Heodo
2020-10-22Electronic form.docdoc 2c746449ae089b436ecab1058c035e9ea8e01fd8f45508ed2ed720ff30ee2c01Virustotal results 45.16% Heodo
2020-10-22invoice #74177.docdoc 2bc5c1591569f6e8a480a530bf343df21867da564b7503824cb0e5193d3f8937Virustotal results 41.38% Heodo
2020-10-22INV_80412.docdoc 889113bf50a9e3543f97ca07e4e572f2328587944be4de82f441ba1b23e6ece1Virustotal results 38.89% Heodo
2020-10-22R2046154767XX.docdoc 14a0d5ba65a4585300b4daafa06c20898b303bcea1302012ef2f19559124edbaVirustotal results 41.67% Heodo
2020-10-22INV #00235 FOR PO #9646681.docdoc 948302725f3208d721629436cfe1abbf592c813da68627c3c158cc6547e1cadbVirustotal results 43.33% Heodo
2020-10-22form.docdoc 72da9c13652853256f7cab8762f533e63f52328ba4b06d4bf44d3dc0cd5fe2c5Virustotal results 46.30% Heodo
2020-10-21form.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 51.85%Heodo