URLhaus Database

You are currently viewing the URLhaus database entry for http://www.stepstoshops.com/cgi-bin/OCT/9079695/ntjzlqqzv-00020595/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762769
URL: http://www.stepstoshops.com/cgi-bin/OCT/9079695/ntjzlqqzv-00020595/
URL Status:Offline
Host: www.stepstoshops.com
Date added:2020-10-28 22:58:05 UTC
Last online:2020-10-30 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-10-28 23:22:30 UTC to abuse{at}a2hosting[dot]com)
Takedown time:1 day, 11 hours, 38 minutes Poor (down since 2020-10-30 11:00:54 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30ED-100120 BYYH-103020.docdoc 2efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfVirustotal results 40.00% Heodo
2020-10-29Form - Oct 29, 2020.docdoc fb4e266871e925f780d416984177d01ccf3dd5a3ffb76d031a5cc3738a76a3bfVirustotal results 24.59% Heodo
2020-10-29Invoice #598137.docdoc 477abef826205efd3cf971b2c425dff760789b1c15cfcbc182634ba92187e59bn/a Heodo
2020-10-29Form - Oct 29, 2020.docdoc 32ffb1dec406a36a9e2bce688ed2c8219c952a6b479506a24aefd9dd0d7f9566Virustotal results 26.56% Heodo
2020-10-29Payment.docdoc 9ee04def912bfe9d3a92492ff4f8aa8170dca54f97fb376a5c42bf5f3f2cda60n/a Heodo
2020-10-29Copy invoice #173913.docdoc 9eddbf9eaa4b753108631f0cdbef5ecc758378c188d216542bf2db06a4c4e7e5Virustotal results 22.22% Heodo
2020-10-29October invoice.docdoc 918aa2eb7333c6f0dfed50ccde760c827c26c5b2f3b2022f83c03a7d3c1f1464n/a Heodo
2020-10-29Form - Oct 29, 2020.docdoc 56fee4b612e880d994e5c2581806181f3d258b7b6a64094075e2612856d9de8dn/a Heodo
2020-10-29Electronic form.docdoc 26e0dedfbc389de133350f134455565f185e864b79466539b658dacc21fb1bb6Virustotal results 22.58% Heodo
2020-10-29form.docdoc 0f34d0527521d358b1ac6aad3fb49b422bb06378891bf93065188f0db702bfc6n/a Heodo
2020-10-29Invoice 3559178.docdoc f62b9d8351f6fd35ff31acf9d6f34ff25c528aafec056c9ea7ad7f7c6468cc09n/a Heodo
2020-10-29Invoice #466.docdoc df634084d9cb08a06d2e82f00cc3fef1f64efc21da9ebd08ba86b684ee237863Virustotal results 19.05% Heodo
2020-10-29Payment.docdoc 526517f6cb457615481a34a844da89648c01e54f25dadafc68c5594c9797cb17n/a Heodo
2020-10-29invoices 52874 & 68051.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 42.86% Heodo
2020-10-28form.docdoc 96357920882bf90a3ffe1e87ea63ef9f2dac43a1f01c5ac5d3c390103e9a8bb5Virustotal results 22.95% Heodo