URLhaus Database

You are currently viewing the URLhaus database entry for http://jebs.net.au/cgi-bin/invoice/823775879/yCr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:732810
URL: http://jebs.net.au/cgi-bin/invoice/823775879/yCr/
URL Status:Offline
Host: jebs.net.au
Date added:2020-10-22 05:03:07 UTC
Last online:2022-02-02 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 05:04:03 UTC to abuse{at}dreamscapenetworks[dot]com)
Takedown time:1 year, 3 month, 18 days, 2 hours, 12 minutes Bad (down since 2022-02-02 07:16:22 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-06invoice.docdoc 35f6d8f24630a6bf02cc4c21c3677a57648e5cff5e1422c9c03eb73813493eban/a Heodo
2020-10-23invoice.docdoc 3f9db285b73fd517a1c511a147a4cae314a29a33332f7e8012700c086132b6c2Virustotal results 43.14% Heodo
2020-10-22Electronic form.docdoc 7104dd32f9de62701f5d5a01ac763237757d11e8fa2c10ec24749f5791467fcbVirustotal results 38.98% Heodo
2020-10-22Form.docdoc 73afab923f309960ba6ef1f00b4d373abce5e6605b10a2b214ca42b7736f1f6bn/a Heodo
2020-10-22Invoice 01138104.docdoc 8f46672fc4bd13f926555000c39b3ff624d7b96f41429e568aa2bad30431bbe8n/a Heodo
2020-10-22Inv. 08256095216.docdoc 8a84251f63aa90465d3b8b145a9e710d1aedfc23d03511b87681f18ec3542298Virustotal results 38.71% Heodo
2020-10-22Inv. 00545251.docdoc a92e9fd1aaea72831f29e20e4afe829f2fd63c7645e2ae3b8b4786a8ade2b0b6n/a Heodo
2020-10-228720118219.docdoc 40ad317b6909d6800860af835411d7aedd3ff816bd1e02c7aa0553dadb8735b1n/a Heodo
2020-10-22B-100120 IUML-102220.docdoc 8ce84cc08c61ef8da560dab9863109bab6dac208bdb030c9d513aa71dc7b3492Virustotal results 40.68% Heodo
2020-10-22Copy invoice #3052.docdoc 171b68003d3217f50e0238721e0957d775d8eb225067a0191f56f2a31b998629Virustotal results 37.50% Heodo
2020-10-22INV #00501 FOR PO #00802577414708.docdoc d078837cdc9042641925b36475f87954994b19f05d89c10b4ab4a1ea28a806efn/a Heodo
2020-10-22Invoice 002436757.docdoc 9b918b3a0a118f50d3c8d4be4526b1fd8ec10563810c7dbb5088495e471f6b26Virustotal results 32.26% Heodo
2020-10-22Inv. 0619654.docdoc 2acac0803d5b5de2f17bb7d2c43af5ad438be8af04faec7bdb33b4cddda2a4d8n/a Heodo
2020-10-22VY053 invoicing.docdoc 01b228cd4f024acce23be7b762797915e8ece1d47c301e20f9596a98aed2acb5Virustotal results 49.06% Heodo
2020-10-22PO# 10222020.docdoc 74e16bd58ef88cfbc4267cf32b54a6444f5a01675811af2f8da025c1dd9e7272n/a Heodo
2020-10-22AZ-100120 FWTY-102220.docdoc 3d931f3056e01ac585facd9cd6b2295bd63dbc6e340ccc4d94549533f42558e4Virustotal results 46.30% Heodo
2020-10-22invoices 623 & 12083.docdoc 8c15a10ed4c619cdc9eefbb7d32596330ccb2dbc41b5e21841dd141fee55a85bVirustotal results 47.17% Heodo
2020-10-22Invoice #3834354.docdoc b25f82dbf33bc9cc154be6c8bef79aa2b570c84eba334f3fc27ae55681f6c154n/a Heodo
2020-10-22Copy invoice #160307.docdoc a3a1b4f0a15ce75c9c492676dd9fa1570d6fc7b3296538bbae39f678d2b28bf7Virustotal results 49.06% Heodo
2020-10-22Invoice #85538.docdoc f22e043076e2cafc9155e8e740e5ab74406ed9e83d3f875772e3f82b69d8d93cn/a Heodo
2020-10-22Payment status.docdoc a89a346ba95533594891a15e53625209199e68bad7519485b3bfaf1954b2a8b8Virustotal results 45.16% Heodo
2020-10-22Inv. 00886620168.docdoc 05902a6c459b5ee113e0160231e64f0c1e0a6023654d545ea93abeaf435b71beVirustotal results 43.33% Heodo
2020-10-22INV_6784.docdoc 2bc5c1591569f6e8a480a530bf343df21867da564b7503824cb0e5193d3f8937n/a Heodo
2020-10-22October Invoice.docdoc 889113bf50a9e3543f97ca07e4e572f2328587944be4de82f441ba1b23e6ece1n/a Heodo
2020-10-22Inv_44621.docdoc 2964a315de69bb8d274293c5de39c877468fa8f5395e04639fb3029533bc4c45n/a Heodo
2020-10-22Payment status.docdoc 4d7e619f0381816bed7d0ffb6ea0a43ebd6050cbfb10f691c1bf8d8466c11345Virustotal results 45.16% Heodo
2020-10-22Form - Oct 22, 2020.docdoc 72da9c13652853256f7cab8762f533e63f52328ba4b06d4bf44d3dc0cd5fe2c5Virustotal results 46.30% Heodo
2020-10-22Copy invoice #872136.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 60.78%Heodo