URLhaus Database

You are currently viewing the URLhaus database entry for https://www.oakcns.com/wp-content/form/cblpf13-000360331/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:750858
URL: https://www.oakcns.com/wp-content/form/cblpf13-000360331/
URL Status:Offline
Host: www.oakcns.com
Date added:2020-10-26 09:10:09 UTC
Last online:2020-10-26 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 09:12:07 UTC to abuse{at}tierpoint[dot]com)
Takedown time:10 hours, 22 minutes Good (down since 2020-10-26 19:34:52 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26invoices 2570 & 41617.docdoc fdc13e0eb96fc86eab980a9dccda097b97596ae720cdce391434c48e89765286Virustotal results 38.18% Heodo
2020-10-26Inv. 38053.docdoc 749f1fef4ba13eb2fc52615fe37c25ea91408df922aa37d79937e6604f5bdf18Virustotal results 37.10% Heodo
2020-10-26NY-100120 CESI-102620.docdoc 715e60a24fd90a6e59aa6930219217d550926adf6e14321bbdc712b5cbaa4f94Virustotal results 39.62% Heodo
2020-10-26K5704593939PQ.docdoc 288ddec37f764ebf494aedcfc3b09f1f3046c12ab943866c60aa3af9f66c98d2Virustotal results 37.04% Heodo
2020-10-26009945867.docdoc 3ed353da2dc37fc292c206be69f75a4089984648171978dea332df73c610e31fVirustotal results 36.54% Heodo
2020-10-26invoice #57716.docdoc 7d45638dd69103b750d054648d54be73dda911e47b0f4f8b53111f26b00a14can/a Heodo
2020-10-26October invoice.docdoc b42f16bc79ca0272af298eec2553e8cbbabdfb5ba633bbc3b02e0c8453005ad5n/a Heodo
2020-10-26form.docdoc 05bdc226ce29c665f8738f79540000c0b2c0a834949f6d3f9e2bb0ee59e07b2fVirustotal results 37.04% Heodo
2020-10-26October Invoice.docdoc e4e2b59b96de572796b1b3d7aa8cdaf3527ec0435e4855c01e7a2442d6caccf3Virustotal results 35.48% Heodo
2020-10-26Payment status.docdoc 9a5144ffd2ab4399f7986090c9f1d50ac07b566c2c4df9a30f557dfb9f915fc0Virustotal results 34.48% Heodo
2020-10-26invoice.docdoc d12f1b4f9774e6c09f48c6e81a1739a2e07370e093e7fe33f6d65055598e8830Virustotal results 35.00%Heodo
2020-10-26invoice.docdoc 7c03ea101a78bc3c17f17ab1999f5d4debec4f5f90560e8828666f4f24597bf9n/aHeodo
2020-10-26October Invoice.docdoc a88691be2dee049c4df8247d08229a9ac1c327e3249e985aa4f1b513b1b52b0an/aHeodo
2020-10-26PO# 10262020.docdoc b61e055b46db6cd68dfea7e10e1038b9cd6986a1a42da4a7dc4baeeac26ade14n/a Heodo
2020-10-26Form - Oct 26, 2020.docdoc 05d23786837f4fda591dcd1fd6e3505c416947521ed1664a16f2da45f774dcf8n/a Heodo
2020-10-26Inv_7930.docdoc b976ce33e20c45272b7793ade400b1dbfae0f4a8911a9764feb6159d63393574Virustotal results 35.85% Heodo
2020-10-26Payment status.docdoc e50304baf418b794765ec3e14c25137e509a3670f0877da91666c85965993c23Virustotal results 33.33% Heodo
2020-10-26Inv_5230.docdoc 800b0814055620a28c02480afc02d9b61980c868f8ddb1a6474d83004689a6ddn/a Heodo
2020-10-26L0036 invoicing.docdoc 944defdcfec039dc542577bd4e4cb65f82589cb8a731403841764a77ddf0186bVirustotal results 33.33% Heodo
2020-10-26Payment status.docdoc bf8597201d22d0ac4f4f1bfcbfee0c6e114c2795f6db98b47c9e81154a85c871Virustotal results 31.75% Heodo
2020-10-26Electronic form.docdoc 2e90362549f361c65f023ecb6decce30e24d49f337b7127fdf8a2981b0e48f50Virustotal results 33.96% Heodo
2020-10-26invoice.docdoc 628fed623605c3ea52b5697e305dbc0c2e0ddd53dae6711ed1d89873c5e2f831Virustotal results 31.48% Heodo
2020-10-26invoice.docdoc 33bc493e35171898f15cc529330ffef62bef083d637effcac019e6afbb5fae73Virustotal results 30.00% Heodo
2020-10-26Invoice.docdoc de8f1d660d3503e393ef82fd2f7989f03ec3671dca272bd17f06d68cd057f1acVirustotal results 29.51% Heodo
2020-10-26October invoice.docdoc a8c090b4510037b54d598b47112216fadccebd9e52e5654d6db13fa79b35adc6n/a Heodo
2020-10-26Payment status.docdoc 0db761318752265daead2f33be7b9724ce5f262d370b8ccc175d3b7f0706e0e9Virustotal results 30.36%Heodo
2020-10-26INV #03029403 FOR PO #02909926838.docdoc 770b6bfe521bfa754d589daa61416ad23ecca3bfae03b351ebd5f23ed36983bbVirustotal results 30.16% Heodo
2020-10-26Copy invoice #050856.docdoc a7f7d754063eb1862745db0a7121b83d55e73254f0712ed6ff8bc737185a5f58Virustotal results 31.48% Heodo
2020-10-26Inv_830626.docdoc 5cf82eff7894873f2bdc66245bbca42258453fe895fc4cc4d5d21d603af39f40n/a Heodo
2020-10-26R07 invoicing.docdoc d0cb51c5b5f8cc9000ac6b719e451ea647df9f4a8f1972e3604df78d9fa67915Virustotal results 28.33% Heodo
2020-10-26Form.docdoc dfe092f148ca1a45cdec6d566d8b4dc65b32f44914213cca431def8719680bd7n/a Heodo
2020-10-26Copy invoice #59339.docdoc 019933d9876806ea49d706390619bd210647aa65c83ae1beab66d7ad5e80ba0aVirustotal results 32.69% Heodo