URLhaus Database

You are currently viewing the URLhaus database entry for https://jimsautomotiveshop.com/F0xAutoConfig/report/ci494yy-000437/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:760441
URL: https://jimsautomotiveshop.com/F0xAutoConfig/report/ci494yy-000437/
URL Status:Offline
Host: jimsautomotiveshop.com
Date added:2020-10-28 10:41:04 UTC
Last online:2020-11-04 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 10:42:03 UTC to abuse{at}godaddy[dot]com)
Takedown time:7 days, 0 hours, 28 minutes Bad (down since 2020-11-04 11:10:25 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Payment.docdoc 2efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfVirustotal results 34.38% Heodo
2020-10-29Invoice 082175.docdoc b646a2f2855c1348d2d8cbdf2d3f54747bcd727069000f64e1bd824991732442Virustotal results 34.38% Heodo
2020-10-29Invoice.docdoc 824b555ab78a9670b9a6f46138f71620ac8a363dd7e6d8009bad404dcffca81fVirustotal results 34.38% Heodo
2020-10-29INV #0909456 FOR PO #0012541215.docdoc cbce0e0313a3db6fb0061fd2b0872e0735248ffc5e80ca6982ac2400e479e72eVirustotal results 34.38% Heodo
2020-10-29Electronic form.docdoc 490447ab0221c1d099b57c81080eeddf31c23a6b90f4e753aaa82be8e80aefacVirustotal results 34.38% Heodo
2020-10-29invoice.docdoc 4058286796ed1036d0c66b67dd83752f09a253f4b597095ffd3f2412645e3e3aVirustotal results 33.33% Heodo
2020-10-29Payment status.docdoc e82d122d0f3a727259860d1596b6a7a81984dddc13f13d4c77f719808c996915Virustotal results 34.92% Heodo
2020-10-29Invoice.docdoc 95ec936d873cb5dfc933cdcec29598333a215dcef39621afc666e44e98aa18c5Virustotal results 36.07% Heodo
2020-10-29Form.docdoc 93edcc5c13cef6e563c7c530cf9462e92dd1c80495800814540c045a9fc2cabfVirustotal results 34.38% Heodo
2020-10-29Payment.docdoc b5924a9723c7486c77771b4e6f971a2740eee79c6a1aa0bc21c05317c63560c1Virustotal results 33.33% Heodo
2020-10-29Inv_026407.docdoc ce26d68de2263ab355558dd9f0b201883404c91ecf3f164c8ef0bf17c9e98f20Virustotal results 33.33% Heodo
2020-10-29Invoice.docdoc e48485a5f02afb4fa932b38c41f278e6a4571911311828ff8fc0cae186be9be2n/a Heodo
2020-10-29Inv. 2550430.docdoc e30eceea75b291ff394ffb670b46a3b07e8725dc0a146c1df069952d9ed885a9Virustotal results 33.33% Heodo
2020-10-29Invoice #026.docdoc 07b12baabc51749df13d78cc093496d641f03a1aed14ee0ecb867e2a4a2d70d5Virustotal results 30.16% Heodo
2020-10-29Invoice.docdoc e8eaf6545e2cb1bb8d2294dd179c60990c18eb6fd9f4fa804effa77b6a28ae50Virustotal results 26.98% Heodo
2020-10-29invoices 80531 & 81661.docdoc 9143453f9dd04d35a094a0332fdc37a1d517cc582db210673a79310a26505e65Virustotal results 28.12% Heodo
2020-10-29Electronic form.docdoc f96f687fe6450306d4a9a26020bd2ff7e563d75f4eafb3732b34b816eae39fb0Virustotal results 26.67% Heodo
2020-10-29October Invoice.docdoc 34f4b941f7159e6c2f95f5e599b65b7cffea4b7e46a47c6bb16ea6c38027deb8Virustotal results 27.12% Heodo
2020-10-29INV #1788649 FOR PO #0091702888.docdoc 1c8f2dfb55495914bb8f8167e616d296fd5e0b1d9e0904b65020ce536eb8562dVirustotal results 23.68% Heodo
2020-10-29GM00755 invoicing.docdoc 9c69f6cf8966a5e6349506b4664919c990dcf411ccd38d0748ea6c60dbf3fd8cVirustotal results 26.98% Heodo
2020-10-29invoices 49156 & 9604.docdoc 0ff96480062e84aa44e93eb008a5937b1f317e5a0e222198658fb2a71dc4b952Virustotal results 28.12% Heodo
2020-10-29007827001.docdoc 92ac003fb233443b86d9985f85bb50a56d64b8017e15191e8b5739c537f16802Virustotal results 26.98% Heodo
2020-10-29Payment.docdoc 02fafe24fe1eab419305d450f7fe2753711cf6b5b8c5013c75c814cfdddb8348Virustotal results 25.00% Heodo
2020-10-29V0245461331HZ.docdoc d5d9e0e60d6db253aed185dd686c68b29fbec72a120812b62cba1e5bacbcd2d5Virustotal results 21.88% Heodo
2020-10-29PO# 10292020.docdoc 7d41847fb131218d629e6bb8132dc6b2b1ce714b4090c01c3f531fa66ad7274aVirustotal results 21.88% Heodo
2020-10-29K06 invoicing.docdoc 9da8a687183313d2dec4f41ff6c4b5b6fda388b7d8d295b3071df72518fb318eVirustotal results 21.88% Heodo
2020-10-29invoices 97272 & 7870.docdoc 56fee4b612e880d994e5c2581806181f3d258b7b6a64094075e2612856d9de8dn/a Heodo
2020-10-29Inv_223347.docdoc 95b4f0a791e9ffefe35972f8c4e1a90c115fe1c8976f779e44b5190d859b3eb0Virustotal results 22.58% Heodo
2020-10-29Invoice #983096485.docdoc da66ec2d3fdd0436fbda751119e9830b6600767a6c377cef8a85bebc4059bdc6Virustotal results 19.67% Heodo
2020-10-29invoice #2674.docdoc 3e84e096f2f889c271504b8dcfb1e9fb78a347087b984a219d7749a8a0839c31Virustotal results 19.35% Heodo
2020-10-29PO# 10292020.docdoc 65a1c1b8cbaeaa9098df96d462c765ec20c8d6acad74e0a0ac60e895d9468c06Virustotal results 19.05% Heodo
2020-10-292663087267RS.docdoc 586002b2b5259558f6fdf99f8bfcf2e4292dbdf458258eb918efb751c35cef01Virustotal results 19.67% Heodo
2020-10-29Electronic form.docdoc e06078c4dbd95ae50e1851d57970a1f2a98d874ba5726452404dbc9cd64ea8faVirustotal results 19.05% Heodo
2020-10-29H-100120 URVB-102920.docdoc 86784b37bc0a4c5ad8f488356ec333dbeda709272a5aa412aeff54fee3f9db46n/a Heodo
2020-10-29KE-100120 BDSY-102920.docdoc 8744e383bf013444ed1f687f385d558ee1c4e2a153cdfe224250a02fd1eada2eVirustotal results 19.05% Heodo
2020-10-2900448607047.docdoc 92d834cc4eeb0c988360abd919fed33b6ff21d18e7fc4fbf17a443d56374ac19n/aHeodo
2020-10-29INV #0627300 FOR PO #598453661176.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 42.86% Heodo
2020-10-28PO# 10282020.docdoc f973018352488fe6ba623919161c5b4387f67d9aca131af19480684ae2740544Virustotal results 17.46% Heodo
2020-10-28G0079 invoicing.docdoc 22501e141b52a24309578121d2ba63249fc21c36c6b4dbfd0f22635c0a0aae35Virustotal results 17.46% Heodo
2020-10-28J-100120 LKPE-102820.docdoc 5a559e7ae73b3dfc7c7dc4894ad3be202468c4531516315cdd9b18c1ffca464fn/a Heodo
2020-10-2850585.docdoc c941232a830436abd4969caa877cb7fdf70ceb9bfc8844e7dc75fd1f400cc897Virustotal results 17.74% Heodo
2020-10-28INV #8394314 FOR PO #793178809806.docdoc 52cffa7b6a722c32c17560a5d71ac09a91bdcd9cd36ab8b9913c92063aa109c5Virustotal results 17.74% Heodo
2020-10-28DQ-100120 WPLM-102820.docdoc 8a5d45742906d99f6a25870884036c29e1df4a190ada0ad3af81feae44092f1cn/a Heodo
2020-10-28invoice #3110.docdoc d052b404f414509ffe272015a3e233be84d889c982b538166102194f1c985172Virustotal results 16.67% Heodo
2020-10-28Electronic form.docdoc 380ff0d5d662477222c7f131f8ff90dea7c38d006d49c386f50cb738706e212bn/a Heodo
2020-10-28Invoice #84448.docdoc 484ae53bf0192a40df9a49b1a34ba687a1551905b56ec1ffbcf77930b1a5d1c9n/a Heodo
2020-10-28PO# 10282020.docdoc 74f1a1497472b687af8f8b50c10f4c44f817c9d2cc1252cb12e7729a2eb83f77n/a Heodo