URLhaus Database

You are currently viewing the URLhaus database entry for http://kyatama.com/default/US_us/Invoice which is or has been used to serve malware. Please consider that URLhaus does not differentiate between websites thats have been compromised by hackers and such that has been setup by hackers for serving malware.

Database Entry


ID:90524
URL:http://kyatama.com/default/US_us/Invoice
URL Status:Offline
Host:kyatama.com
Date added:2018-12-06 21:41:07 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-06 21:42:05 UTC to abuse{at}unifiedlayer[dot]com,ipadmin{at}websitewelcome[dot]com,abuse{at}hostgator[dot]com)
Takedown time:1 hour, 34 minutes Good
Tags:emotet epoch2 heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-12-06Review invoice required.docdocd52cf121765a06e662ab0fd1a97bfdc3b2b3c527b1bb8c3bd612dcac9a47ddefVirustotal results 18 / 59 (30.51)Heodo
2018-12-06Month notice.docdoc2ad637beed379f852e3a9cf85d3b0b5499c090effeb2adf6fcde17114d92cfacVirustotal results 18 / 60 (30.00)Heodo
2018-12-06Accounts - Invoice.docdocd52c96d5aeab96a6a01a7673ec78508ccfea5c3b7fd7acca3cb19847b5b832fdVirustotal results 18 / 59 (30.51)Heodo
2018-12-06Billing Invoice - Job # 844411.docdoc336b4d81f53fc104a2099539b1502b195c7181164d4e0168767994997ad2a638Virustotal results 18 / 59 (30.51)
2018-12-06Outstanding invoice.docdocc3eac3077eb9b1e6c5dd40b9c67cd20f8724ff1da9db2f74dd051c741a281de4Virustotal results 16 / 59 (27.12)Heodo