URLhaus Database

You are currently viewing the URLhaus database entry for http://apcngassociation.com/uxtQ-UFzDY_bb-Fm/INVOICE/US_us/Invoice-Number-07697/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:98343
URL: http://apcngassociation.com/uxtQ-UFzDY_bb-Fm/INVOICE/US_us/Invoice-Number-07697/
URL Status:Offline
Host: apcngassociation.com
Date added:2018-12-20 15:46:58 UTC
Last online:2019-01-25 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-20 17:26:11 UTC to noc{at}premianet[dot]com)
Takedown time:1 month, 5 days, 13 hours, 21 minutes Bad (down since 2019-01-25 06:47:37 UTC)
Tags:emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-21this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 0.00%
2018-12-21219595727938.docdoc e88c2b2a2df124144ac5204b46773cd3513da174ab4f2453fbf76649021a5360Virustotal results 16.95% 
2018-12-21PAY384202321735649097.docdoc 539304f5371e263c73240dafd270fc82baf06b3fa02d8bff6b7f46bc67daee69Virustotal results 20.00% Heodo
2018-12-21PAY022887356606.docdoc 94bc64c71cbade3ef7e0e54fb6315de33b0e69f80919c6e1b3bb2b5e6dd9a520n/a Heodo
2018-12-21ATT6512717662258723092.docdoc 5cad192a789f67750bc61c85746ffefacd9a1084e64e877b19761d8af3e01417n/a Heodo
2018-12-21US440426694887838435.docdoc e75eabba5ecd2843cb70935d7d6ad7045e031f57b52f4bdf5fe04f136d91ea8dn/a Heodo
2018-12-21US55718085326.docdoc 4a848d3552f9e5c102a5beb770d727704969dc2049b7ffa2714c03106148a4f4n/a Heodo
2018-12-21ATT606088332.docdoc b3a07fe6e8deec0a4bb72cd33320cd3e22f13d46fe4d2928dd439adcdebea3c7n/a Heodo
2018-12-21US7302757283.docdoc 35d69c999becbfbaf3563c934a851c9e90e1850e07506dc011f851447aa3dce1n/a Heodo
2018-12-21PAY11267629256893.docdoc d9e32bb26bff81b53df36f9f48345895b2e2c06c30fd467f2c0c964243e5c3f9Virustotal results 20.00% Heodo
2018-12-21PAY3747385473579040508.docdoc bccddf643a7199aa666fae5d914cba3c86f31be9ed7828966d5d855b9e0ef104n/a Heodo
2018-12-20811318353.docdoc 0e2a18b41184c5fe2f6d9e5205303252c7ae9dad15b1e50774f2e384eb527682n/a Heodo
2018-12-20678479445120.docdoc 8f568a553084056ba2d6c4458f6f81cca2ce02de0d02cbb36a82056b6d895d5bVirustotal results 20.00% Heodo
2018-12-20US6258835644299.docdoc 2d7b47002f9f7efc12d19365812e0f6d24cf855e63e1a08112126048711706e2Virustotal results 22.03% Heodo
2018-12-20ATT72478540416465282.docdoc 2bc19f1a55b61ebc203dbda2b2aab16e0b47508db2f868532c9b44e1555a9019Virustotal results 22.03% Heodo
2018-12-205845385821657685.docdoc 39223a9cee974527c8538ff76f9df28d50218c4b080cde7249d2b3fee7e6710bVirustotal results 22.03% Heodo
2018-12-20US8451307359957775.docdoc 2ac3a26272f2af4119c21f5ea362f26d3fd59d64e822b05a8ab816c352287da8Virustotal results 21.67% Heodo
2018-12-20ATT929788189959817683.docdoc 38dcc5d86e63914b92409e6d8600220df667fedfdc7edac19dd9ef0bcd3648faVirustotal results 22.03% Heodo
2018-12-20US693250157857763565.docdoc 9ed11279e4650bc7f72b554339510c611fe59003caf9ca90071bb82afa12341dVirustotal results 20.00% Heodo
2018-12-20US88904348839796535751.docdoc ce2ff6082923aebde2294e0a3996d0048a61a637720f573af55bc192b0b28702Virustotal results 21.67% Heodo
2018-12-20ATT81284252802532.docdoc ef8cd8c96f4ce08a00b941b4fe9406f82e3f8cd086095b8dfb422ec882e14262n/a Heodo
2018-12-20ATT48724392165017.docdoc 2c41c11939836650f6a6d52e16c40d5b29094e59f34e4f81ff06c6f193335f59Virustotal results 27.12% Heodo
2018-12-20PAY02723051903.docdoc 67e7724ea81c96f3ff14f62231507c7ac3da8b7f54485a3cf6c43e0d02d0db6eVirustotal results 26.67% Heodo
2018-12-20US30704356451039.docdoc 82c8667d9a8fc1e0b2e6544334f8783861edae4444125797edb1ca7c9d9b239cVirustotal results 27.12% Heodo
2018-12-20US47140273738302828.docdoc ff0bd259761812d0f4df0e2454e5cb6bd076fbf6d52a7896fc7d9224b12a610an/a Heodo
2018-12-20ATT8785589246.docdoc 4234effa686b742473b6d7eb5b9c733be481e0645ed96a44106726a7dac794ffVirustotal results 25.42% Heodo
2018-12-20PAY837356930.docdoc b98143e9cddef8410389d6e051f04290e049af16e616ad87b5174b9ad61ce7c4Virustotal results 26.67% Heodo
2018-12-20ATT025144830903774642.docdoc cb6cf978c042342d394d8e705ba911d35650262696b327c0c883d5727cd6b6efVirustotal results 33.90% Heodo
2018-12-205075044187238400351.docdoc f403b2e655b34c03cd33f3302d98c38f2a755aca008c4c14c29211920829d26bn/a Heodo
2018-12-20PAY8855496320108962.docdoc 200e9f0ffaa1c07ee596212059e01280bbaccfa6c22d54414068c28d30a81160Virustotal results 26.67% Heodo
2018-12-20ATT10175435565894904.docdoc 92e39ac764a910ffc06acf41e43187003fcdc10d4076faa2640a4ac79e924cceVirustotal results 27.12% Heodo
2018-12-20ATT8323649579958987572.docdoc 03a85e11c44190d01ca2a7123195e82cfd67353d0763218abb349bd7024b6509n/a Heodo
2018-12-20PAY59618201272569423834.docdoc 56a37928d0549592fe5cb4b33066c442ef2b37ec15612d5777cde3f44ab7fa2eVirustotal results 26.67% Heodo
2018-12-209698713006613741813.docdoc d64cae7e0840e557ce0d4bd8f0b043ac1831d4c963dbffb4dbb494874296b91aVirustotal results 26.67% Heodo
2018-12-2011005577178038980940.docdoc 85386588dc3f29e5f3bbde3ab9fc6cba826c293bbfce11b6c3f1a4403f9e2ae8n/a Heodo