URLhaus Database

You are currently viewing the URLhaus database entry for http://store.damatag.com/wou5nv.bak/public/lg0ut4a7r-0443/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752705
URL: http://store.damatag.com/wou5nv.bak/public/lg0ut4a7r-0443/
URL Status:Offline
Host: store.damatag.com
Date added:2020-10-26 17:48:03 UTC
Last online:2020-10-31 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 17:48:10 UTC to abuse{at}godaddy[dot]com)
Takedown time:4 days, 17 hours, 32 minutes Bad (down since 2020-10-31 11:20:57 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28Form - Oct 28, 2020.docdoc afefa823336f768cfa29c0c274bc7043d6f1d89f6a068f93acb1b22844c42a71Virustotal results 16.98% Heodo
2020-10-28PO# 10282020.docdoc 9f132d350226a798ec1c896757c5b5e81ad9909f4c56f479121e733393ba3d8dVirustotal results 18.52% Heodo
2020-10-28Inv. 000739621.docdoc 9e583231a4092b32f4c900501fc90210418cfbc4fc6c7bdd3fc8c3610cff588bVirustotal results 15.87% Heodo
2020-10-28Y-100120 DRWT-102820.docdoc a0a14d3c83ee0266089dabde6d9b7f238920744382e92852153fdbf23c61f04eVirustotal results 17.86% Heodo
2020-10-28invoices 436 & 00181.docdoc 734df9186877b3d2ed74c1bb7cf211c1787bc3c94c4761b01c32fff69d89d77bVirustotal results 42.59% Heodo
2020-10-28Invoice #3053.docdoc dac1a4a8fdf126653a5e87cac70fe2d8fd38b92b962d4be9191f0446d6c650a2Virustotal results 42.31% Heodo
2020-10-28October invoice.docdoc 95d417c5e1d71c30625a95f40fb7d368da11fb8052ed9cf36b2e811f6200846fVirustotal results 38.71% Heodo
2020-10-28invoice.docdoc 639f3d1d1a494dcf20b64daa8f46a98affe8b7e708fac26f08a732bf4a03c06aVirustotal results 26.98% Heodo
2020-10-28Copy invoice #79591.docdoc 7cdf46cacb08878324d471fc7cec17b333e38c7d76479a164d1115811dccceb8Virustotal results 28.30% Heodo
2020-10-28Payment.docdoc aaf05aa6da7de09b0f276cb3b3116e61aa22d72769e52a1c85f492d3a1a9e002Virustotal results 30.19% Heodo
2020-10-28Payment status.docdoc dae0cc43be550a6d83464a1f5b2ba4ab8dafdaac48c3441bfc941279afd56de1Virustotal results 24.59% Heodo
2020-10-28INV_4968.docdoc f3e02448d1bd54a9fffbb229b8006033175e4098eec24dfca51f5a0229dfcff9Virustotal results 23.33% Heodo
2020-10-28invoice.docdoc 062ccdaf377390b0400188dd4b76f5479b5c5e4cb11cc321ad63e9223179feaeVirustotal results 29.63% Heodo
2020-10-28Invoice #9553.docdoc a1546bd45c31f3d8028e9ed32b37a0394e615efc5a71ea3f36e4696a6a913c56Virustotal results 23.81% Heodo
2020-10-283349959160.docdoc cefdece809bb4ea44a6ed18923e403e409190c61aebfadc97e7eddc70da59285Virustotal results 28.85% Heodo
2020-10-28October Invoice.docdoc 3f5f89c1ba2c99ea85266e572e4d7fcc689b614028747d726b0496698b6a93e5Virustotal results 23.81% Heodo
2020-10-28Payment status.docdoc bed792107addffb25cb050a7c86ccffdadbbfd55c8a06c01479b51975f34adc2Virustotal results 22.58% Heodo
2020-10-28form.docdoc bb035dfa04791584d81e71d154e443811c21deb1ae691425a9bfe05696187c9eVirustotal results 25.00% Heodo
2020-10-28PZ09 invoicing.docdoc f7c62df3d72569e02a22d018a54631d3041f23b308ed9da7af261561ac318a74Virustotal results 27.45% Heodo
2020-10-28invoice #943581.docdoc 0046dd430f33eec36daf84e72714fd8adae02e6cf32755fc2284462d9bce05daVirustotal results 27.87% Heodo
2020-10-27October Invoice.docdoc ccfb92a335944590af2f1b2c9a759e4c3e6c5d9842878821a451e78183e0c51bVirustotal results 27.78% Heodo
2020-10-27INV_4613.docdoc 0265d621d36ce8fa5ab27442f8af6b2ff09e4c00563947aba99868174be82a58Virustotal results 26.32% Heodo
2020-10-27Form - Oct 28, 2020.docdoc 14e540b9e6a505b670a6107a33915ebdf49ef9cdcbe819e7d14993c1f1d2619aVirustotal results 25.42% Heodo
2020-10-27PO# 10282020.docdoc 99c91035c6a269a23e022673bb84e4cb8e8b40909281707212bd9dc4a074c3cfVirustotal results 28.30% Heodo
2020-10-27KU2764673154WC.docdoc 4955a66e9711e8207f53c9204d68f89903e7aec37f30cbd298ff102bf68f937bVirustotal results 28.30% Heodo
2020-10-27083605.docdoc 269ebb02c0552abc38ea7b9e4e0a464ebabbc80035e259af2fa94f1544a3b351Virustotal results 24.59% Heodo
2020-10-27CM816 invoicing.docdoc 3c0b0961efde86a2b9c1a239fbefeaa8c6cf896bfd8e930f972af471efc540c3Virustotal results 23.81% Heodo
2020-10-272733609203BB.docdoc e33c5a896f20bee29de9a591962c4bd9643be1ca87866cf8b574822decfa2c6eVirustotal results 27.78% Heodo
2020-10-27Form.docdoc 18e31e5b8ad5d3194d4fad561b4c5bf1bece67a65dc3454ef30e5019479afc42Virustotal results 23.81% Heodo
2020-10-27form.docdoc 29653b55f19e3e294854ce4b946c5d409d54825e9e713202a95aeec929d9de5cVirustotal results 23.81% Heodo
2020-10-27PO# 10272020.docdoc 26b6c08bbd6f91a2bed79c26264bdeecd3f1c92733a9870924e53eda84d5ccdfVirustotal results 23.81% Heodo
2020-10-27Form - Oct 27, 2020.docdoc 6c40a86cca19d777bd981ee02c7511d1e4d2cb3b958f17a34e06eda569c38be3n/a Heodo
2020-10-27Payment status.docdoc e39757188d82ee09fcb868b4d5ce2f37b8904f29335dfe60501e67a14fa09f51n/a Heodo
2020-10-27October invoice.docdoc b916e469287c8fa2ea7c9bc0a36e62e310ff1d6553b19639d30d09ede22f77e4Virustotal results 22.95% Heodo
2020-10-27Form - Oct 27, 2020.docdoc 5a07cc5df83be11d085d9a031f8c188b40fc8133ffa322777aed9a7c9a239c5cVirustotal results 28.85% Heodo
2020-10-27Copy invoice #353611.docdoc 799de3c0b3c57093a424c4e80e471b26b7f7d121e6e4b75a250304ed59ab9d6fVirustotal results 34.92%Heodo
2020-10-27Invoice #14700.docdoc 415b92121d9ef5bb027cfaab1e727cfd0a49c70a998e2ced96f0b21182c6182aVirustotal results 35.59% Heodo
2020-10-2793307.docdoc 3ef590314e0374ea0d69809bf451d0cd1296a7d1c2cbaee157a7dfd627389e3cVirustotal results 36.73% Heodo
2020-10-27Payment status.docdoc 82230abce3c93f75f392dfe544ebe93613a07953e4249a557ed37080f3b63eedn/a Heodo
2020-10-27Invoice 01486599.docdoc 618b42ed1f918805007ba2386a3456d92250a54d5091f096234f293b695a5715Virustotal results 35.19% Heodo
2020-10-27L029 invoicing.docdoc 083c20d80dfd7f17a95d7bbfd891cc3756255aac0c24d4515b8c3b2d8bf87d12Virustotal results 33.33% Heodo
2020-10-27Invoice.docdoc 0021bbe25ff5b692875ec9b22ecc7f278d7859484560e1b975c37770a227a1cbVirustotal results 34.92% Heodo
2020-10-27Payment.docdoc 3c770b3c0dc037c15c218f40b4b26f9b624902625345c4cb53b1f589eccf29b5Virustotal results 34.43% Heodo
2020-10-27form.docdoc bd1e2b593717d1115d12095e04ca4ef5fb5581e4a712e0ccd8ad504b5763792aVirustotal results 37.74% Heodo
2020-10-27H9924834213UB.docdoc fffd8f91ba3992b4e4ab37f5c691bda01848627747b4483dd6f6cca97716c2a2Virustotal results 33.96% Heodo
2020-10-27I3522024451FJ.docdoc 486b51ff559079eea8a0864b77511485391fb712af28ba9d47183e75f965174fn/a Heodo
2020-10-27invoices 70180 & 2071.docdoc 828a0a418d5b60af4adae55859160a2f505592c7f21d9d0c9a7e6735288a7383n/a Heodo
2020-10-27Payment.docdoc 2cf2dfa19f757a60bd861a5e683e9c01ef431ba0036084514114b246ee96e440n/a Heodo
2020-10-27Inv. 0207606586.docdoc 61b403da4c4eb7f846fd883a540a2ebf928b02655982fc44e08674c13c849d62n/a Heodo
2020-10-27Inv. 0799296042.docdoc a2c3818b3d6d1b11a76e7e707793435950683ee8ae2a7627baa84f3914b97ec0Virustotal results 32.08% Heodo
2020-10-27Electronic form.docdoc f4c63a57cf3097ee2f82854c11cb835c587eabddbb5cfe0b790f409165693200Virustotal results 33.33% Heodo
2020-10-27Form.docdoc bf919cafed94b4925e4ffac8782e0f11c045d10d802a806e21dc77e6ba92322dn/a Heodo
2020-10-27Payment.docdoc a87c03b72e4bfc12901f263c082a8116384d91ee5d14bbb51d2d5d513e3be595Virustotal results 28.57% Heodo
2020-10-27form.docdoc 6bec2d25f21cfd8e028b9be4f3b7dbddd62daa9d0d583a281dce8228e66a5216n/a Heodo
2020-10-27INV_8788.docdoc bd861f436da8dc7910c87daee1945e3a2e4d6366a7437c90f10722d06927e752Virustotal results 50.00% Heodo
2020-10-27PO# 10272020.docdoc 499be3405dec60f227add58dc1522ebd88cb919ce13fdc17c9a874886b8c6ba2n/a Heodo
2020-10-27Electronic form.docdoc 08a81f468de57ca996fab6bee82c920fd2b24445688964c679371f611ea8a24fVirustotal results 50.00% Heodo
2020-10-27Inv. 0928331.docdoc ca286e09b37ac73d3f0f4c732859bfb635073af2e14c81db7268955f8f2b796cn/a Heodo
2020-10-27Form - Oct 27, 2020.docdoc 87aff19e4da90231f8986afbfc0da7864ac4cb35626e8e520f7e299f5dcbee75Virustotal results 51.85% Heodo
2020-10-27055673.docdoc 7025a79caf1e0e05400aa946eea8f0cf6a58638edb662f95314ecf9ce329a37an/a Heodo
2020-10-27Electronic form.docdoc 0bc46a2e9d51cfd44e7b374d90154c5a0d5fa2b25650104c3c7c3e670fff9a97n/a Heodo
2020-10-27invoice.docdoc f13697232547b8dc42b239391658066e10e62a37e32b2555e9afff6641fca012Virustotal results 46.77% Heodo
2020-10-26invoices 343 & 4990.docdoc c6837f0ac871c07b7e1330f74ba054bffcf4b9d45e482669cfa35f7447229353Virustotal results 43.14% Heodo
2020-10-26form.docdoc 936cc33573cce7fe684d96d53ef673119c9c0fc4d307b6bf5f2939b96e031aa2Virustotal results 44.44% Heodo
2020-10-26invoice.docdoc 160cdfd946aa8c04ca0f2e1f621bf04d63403d69ca338b2d7c47dc4657d6bbfdVirustotal results 42.59% Heodo
2020-10-26Form - Oct 27, 2020.docdoc 9564fe1969dc77c3169f53cdc4410fd2d940c5052263abf684ff769509eceec3Virustotal results 43.64% Heodo
2020-10-26INV #0054509 FOR PO #00024657305.docdoc df79c5ac52cb9b66b05a9a1fa95575b895fe157d766fdee900dc948e749ad73aVirustotal results 42.59% Heodo
2020-10-26Copy invoice #2863.docdoc 8a72b79d9447ac65f8b615cb8f4cfa740e65ecbb2cb1babeab81558dbd168be4Virustotal results 44.07% Heodo
2020-10-26OS27 invoicing.docdoc 146073d62b50246e66c61329c7f2488453f73a0702c2fc45604fea9aeb6e3088n/a Heodo
2020-10-26October Invoice.docdoc 4578377fb6eb1be6d27ff9169961b26c2e185523809b311bc70b2ef6ef5d10ebn/a Heodo
2020-10-26B0011 invoicing.docdoc c7b32d97c409e0a129cc49c45ce69e94b6fc692f3f8bdfb82523f616d5d38968Virustotal results 42.59% Heodo
2020-10-26Invoice 0086525.docdoc 97ff328e1e41db8e554d923847eef80d3c264707f08103c946c114c1e6d1fb9bn/a Heodo
2020-10-26Payment.docdoc 751e5ccbf0e70879d2e00ec2bca3c7b756e0b17a3d841faa1a6bf46e76ad65f4n/a Heodo
2020-10-26Invoice.docdoc 48dc30e76d484749d152e5dae556982822af7448889052940e5e1abd054228e2Virustotal results 37.10% Heodo
2020-10-26Form - Oct 26, 2020.docdoc 3e8c21b8cdc8d6ddf1fe7fe7b6c6cdb19e035c0a29dae4c4d6db7f879b98a135Virustotal results 40.74% Heodo
2020-10-26Invoice 008190611.docdoc 58ec8769cfec380fd7e7c7e06a8713052f79dabe9036b3e129d28adccffbac6bn/a Heodo
2020-10-260877608411.docdoc aea343c9847c5822b7515e19aeb290322989e4392dba85af30e898eaeb0963fcVirustotal results 36.67% Heodo
2020-10-26Inv. 00492468.docdoc 18d2ed4b0c2fb25b682a7a7907c0eb2d769b09669eec99934400067bf2feb5f7Virustotal results 39.62% Heodo
2020-10-265555579070XH.docdoc 93e5def0758b0d085c5bb28b8503186bc1c32ef02517016543c552b93f30c3daVirustotal results 37.10% Heodo
2020-10-26Copy invoice #11278.docdoc 715e60a24fd90a6e59aa6930219217d550926adf6e14321bbdc712b5cbaa4f94Virustotal results 39.62% Heodo
2020-10-26INV #1991 FOR PO #001625713130.docdoc d35d77fc097c281427aac8404aa3a3c3f4ede28d65b42455abd1c79d4e28ed3an/a Heodo