URLhaus Database

You are currently viewing the URLhaus database entry for https://www.stepstoshops.com/cgi-bin/OCT/9079695/ntjzlqqzv-00020595/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762290
URL: https://www.stepstoshops.com/cgi-bin/OCT/9079695/ntjzlqqzv-00020595/
URL Status:Offline
Host: www.stepstoshops.com
Date added:2020-10-28 20:07:04 UTC
Last online:2020-11-02 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 20:08:14 UTC to abuse{at}a2hosting[dot]com)
Takedown time:4 days, 9 hours, 19 minutes Bad (down since 2020-11-02 05:28:04 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30invoice.docdoc 2efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfVirustotal results 40.00% Heodo
2020-10-29invoice.docdoc 3bbd2607e23ff082929cad28a957e8e1096e5419ecd6e56856d3504b946a12bfVirustotal results 26.98% Heodo
2020-10-29Invoice #46978928.docdoc 92ac003fb233443b86d9985f85bb50a56d64b8017e15191e8b5739c537f16802Virustotal results 26.98% Heodo
2020-10-29Form - Oct 29, 2020.docdoc 32ffb1dec406a36a9e2bce688ed2c8219c952a6b479506a24aefd9dd0d7f9566n/a Heodo
2020-10-29Invoice 0545426.docdoc d5d9e0e60d6db253aed185dd686c68b29fbec72a120812b62cba1e5bacbcd2d5Virustotal results 21.88% Heodo
2020-10-29invoice.docdoc 7d41847fb131218d629e6bb8132dc6b2b1ce714b4090c01c3f531fa66ad7274aVirustotal results 21.88% Heodo
2020-10-2900497851814.docdoc f55e4dc1405e6f36ed1bce409f373ae6aa7e6080e506ee0b8e7afb30193dedd8Virustotal results 22.58% Heodo
2020-10-29invoice #880069.docdoc 8200214bee8f21c170b9173814cac8166b9f605ebeee543870d9facdefa73d76Virustotal results 21.88% Heodo
2020-10-29771472.docdoc 26ecd84d3c7a3cb416d832a5695934324e8d2b2eb5d44a4d3103d0eff7a7dfd6Virustotal results 22.22%Heodo
2020-10-29form.docdoc 0f34d0527521d358b1ac6aad3fb49b422bb06378891bf93065188f0db702bfc6Virustotal results 22.22% Heodo
2020-10-29DO0079 invoicing.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 42.86% Heodo
2020-10-28form.docdoc 96357920882bf90a3ffe1e87ea63ef9f2dac43a1f01c5ac5d3c390103e9a8bb5Virustotal results 22.95% Heodo
2020-10-28Inv. 0013188470.docdoc 77373248ec2c394eb9cfd85b94e561cdd8ed66646be0298961d65b24a97305e5Virustotal results 22.22% Heodo
2020-10-28Form.docdoc 329f623c62c598576abebccee07ddfe04ba97b4c7ae3307e6a9601185941755bVirustotal results 21.67% Heodo