URLhaus Database

You are currently viewing the URLhaus database entry for http://www.steelbarsshop.com/198598LC/ACH/US/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:77658
URL: http://www.steelbarsshop.com/198598LC/ACH/US/
URL Status:Offline
Host: www.steelbarsshop.com
Date added:2018-11-09 05:19:21 UTC
Last online:2020-05-03 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-09 05:20:19 UTC to noc{at}psychz[dot]net)
Takedown time:1 year, 6 month, 1 days, 10 hours, 12 minutes Bad (down since 2020-05-03 15:32:37 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-03n/ajs 13ac71dbd94a99855cd65ff32c05e1cf0887c660e42bb53de59b2a47cdb1ada6Virustotal results 1.72% 
2020-01-27n/aunknown 8a1ebb340f6380ae285e0aa94f64e3fa85b5833a65bac672074a2104e8ebd291Virustotal results 0.00% 
2019-11-12n/aunknown de9319225f64bc1d2c402f8fb592395b8197e4324c0f4cc7e2bd3cef89bba05cVirustotal results 0.00% 
2018-11-10PAYROLL #5728450AKDL.docdoc 65e4c3c3407f22722aeb6b0e477027e01aa381d83209f713b48f8b4f738528f9n/a Heodo
2018-11-10PAY #50357H.docdoc d749daf6d0ed6d955787d059ae1d580a0e8975d8dea0bd666635cb3b4b859d49Virustotal results 22.03% Heodo
2018-11-09PAY #197PP.docdoc eded1980695bbcbbfb137a944752dfd7f3c89311e8b2b748abde96b4c28c240fVirustotal results 18.64% 
2018-11-09PAY #73548OFYPW.docdoc 184d154b7350b9bb470d8b1119d2f92720d6b9f735f3f7aaeb601661927cd956Virustotal results 20.00% Heodo
2018-11-09PAYMENT #64472LHCX.docdoc 5c5d2e17e36020eb14b1c952c31f71186fbd8372ed32765e20d2f7c0df36faf1Virustotal results 15.25% Heodo
2018-11-09SEP #2542G.docdoc b2132ab94f9caa8d2a9a78d8bd70ecda3d2918d60f275f0c6008e2bf5273e372Virustotal results 55.93% 
2018-11-09SWIFT #12TWJYSVYG.docdoc 3677d37591f1a59159148433597d62de74c57d7705efd49dc0d6b6eb479f0e79Virustotal results 54.24% Heodo
2018-11-09SWIFT #12TWJYSVYG.docdoc 3677d37591f1a59159148433597d62de74c57d7705efd49dc0d6b6eb479f0e79Virustotal results 54.24% Heodo
2018-11-09BIZ #0RXJRWQZC.docdoc f71ebc079a8b553913d56f7e1ae0dfa6e3ce93527a8a5da6ba5f347349273888Virustotal results 53.45% Heodo