URLhaus Database

You are currently viewing the URLhaus database entry for https://cruxlytics.com/wp-content/Document/3mkk-00041/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:754998
URL: https://cruxlytics.com/wp-content/Document/3mkk-00041/
URL Status:Offline
Host: cruxlytics.com
Date added:2020-10-27 06:36:05 UTC
Last online:2020-10-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 06:38:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 7 hours, 3 minutes Poor (down since 2020-10-29 13:41:13 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29invoice.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-27W1603380318LF.docdoc 99c6f01f310c8963530831c2c4cdaa4e6c87290436b0b299e6c066510afd3ae9n/a Heodo
2020-10-27invoice #19315.docdoc 01d93b8545e19757739b9cbe3a771d7d757ba8fc6f32dcefc1695a86e6957638n/a Heodo
2020-10-27Inv. 96788.docdoc 75e9bbd2466e53cb3d43940128a3518f795ede2cc682a3f1e132adb98ca4ab68n/a Heodo
2020-10-27Invoice 01205917.docdoc 311b325ab2da16b422b2e1d19d3b93af7e9b8dd2729e9f2b2f6aff7c96929f25n/a Heodo
2020-10-27Y003 invoicing.docdoc 20d07fffae8b7e13ed1a8730eabed4917b47513e5288336bd8373914088aaa56n/a Heodo
2020-10-27PO# 10272020.docdoc b171e32307062d678cf65b634b1c711ac00b69ce2762db5e486e17858686ed6cn/a Heodo
2020-10-27form.docdoc 1abc9cb4b42aa993827e65cc07634e361063327ecfff66f291760b54d91dcd80n/a Heodo
2020-10-27INV #04023 FOR PO #007482256.docdoc 28b8cc8a466d51d35baf39d43b1b8ee07cc39c6311c3160b416b9cd0db7ead64n/a Heodo
2020-10-27Electronic form.docdoc a1aea6e72d2cc9a2455978bc908ef6b25cde57d5add02b2d4a707fe66e65e9b7Virustotal results 31.48% Heodo
2020-10-27invoice.docdoc 7cdd10d2fa19ecdbca4fd4ce4ce2bdff3c32f911dfddb6dbdcfc42cdbf77c287n/a Heodo