URLhaus Database

You are currently viewing the URLhaus database entry for http://www.steelbarsshop.com/198598LC/ACH/US which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:76868
URL: http://www.steelbarsshop.com/198598LC/ACH/US
URL Status:Offline
Host: www.steelbarsshop.com
Date added:2018-11-08 14:36:07 UTC
Last online:2020-05-03 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-11-08 14:38:23 UTC to noc{at}psychz[dot]net)
Takedown time:1 year, 6 month, 2 days, 0 hours, 54 minutes Bad (down since 2020-05-03 15:32:35 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-24n/ajs 13ac71dbd94a99855cd65ff32c05e1cf0887c660e42bb53de59b2a47cdb1ada6Virustotal results 1.72% 
2019-06-23n/aunknown 8a1ebb340f6380ae285e0aa94f64e3fa85b5833a65bac672074a2104e8ebd291Virustotal results 0.00% 
2018-11-10PAYROLL #5728450AKDL.docdoc 65e4c3c3407f22722aeb6b0e477027e01aa381d83209f713b48f8b4f738528f9n/a Heodo
2018-11-10PAY #50357H.docdoc d749daf6d0ed6d955787d059ae1d580a0e8975d8dea0bd666635cb3b4b859d49Virustotal results 22.03% Heodo
2018-11-09PAY #197PP.docdoc eded1980695bbcbbfb137a944752dfd7f3c89311e8b2b748abde96b4c28c240fVirustotal results 18.64% 
2018-11-09PAY #51564OQK.docdoc bafe1dd3161a8ef8c0a25ded70336cc6108c26030590a01b38e61c2f7abdd95bn/a Heodo
2018-11-09PAY #73548OFYPW.docdoc 184d154b7350b9bb470d8b1119d2f92720d6b9f735f3f7aaeb601661927cd956Virustotal results 20.00% Heodo
2018-11-09PAYMENT #64472LHCX.docdoc 5c5d2e17e36020eb14b1c952c31f71186fbd8372ed32765e20d2f7c0df36faf1Virustotal results 15.25% Heodo
2018-11-09SEP #2542G.docdoc b2132ab94f9caa8d2a9a78d8bd70ecda3d2918d60f275f0c6008e2bf5273e372Virustotal results 55.93% 
2018-11-09SWIFT #2M.docdoc 0fe82daf5749199f74f3f6085a6749fa2e91d0ba1323d33c59fa4ab0bc82c23aVirustotal results 44.07% 
2018-11-09PAYROLL #16GVM.docdoc 3329277ebc13bc45cd40c28b51e83c382eb36598a931f9861d7b1ecf402a8a2dVirustotal results 44.07% Heodo
2018-11-09BIZ #826Y.docdoc a5ebce2fa96c3fe9c6a34697dbbe25ed83a21550478d77660994d759e2c77c98n/a Heodo
2018-11-08SEP #457624DY.docdoc 97b006e48fc5f35ec402eccd38df13fff9f9ed20818f94659534066ed793a272Virustotal results 40.35% Heodo
2018-11-08SEP #7BF.docdoc c34f4ec745ba8d3db5f00f7b08df0406c50e69d7aaf3fa61f197e54207ba4ea9Virustotal results 38.98% Heodo
2018-11-08SEP #627964AEHOJS.docdoc 7077e1c519ff5c35d604ebf6dd52b921e566db20ab57a669518527c36cc5bc9fVirustotal results 35.09% Heodo
2018-11-08PAYROLL #821493FR.docdoc 488a6807480eae8b91320fd43a3df9516068be7ea871b8dd478ec7d3662997bcVirustotal results 27.59% Heodo