URLhaus Database

You are currently viewing the URLhaus database entry for http://365shopdirect.com/Attachments/122018/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:98566
URL: http://365shopdirect.com/Attachments/122018/
URL Status:Offline
Host: 365shopdirect.com
Date added:2018-12-21 02:56:11 UTC
Last online:2018-12-23 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-21 12:58:03 UTC to abuse{at}dacentec[dot]com)
Takedown time:2 days, 5 hours, 34 minutes Poor (down since 2018-12-23 18:32:38 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-21this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 0.00%
2018-12-21INV785.docdoc 248e6a6cc7935a0934b4eda0ad30ae9cb8f79ab4e850f450365f28ade9833990Virustotal results 20.34% Heodo
2018-12-21INV6152.docdoc e07774741415ba9cc3f1df731a625adf48b25f474d4104f074d36903f41d6846Virustotal results 20.34% Heodo
2018-12-21INV6151.docdoc 24b740495d703a4540794f07b62fe1f8be858b38600192eb5f289c5f7055b119Virustotal results 20.00% Heodo
2018-12-21INV962.docdoc 2f4013fa43986e9f4d9348bb143a97f472d0f36d595afa8f4bb33a3922e5420fn/a Heodo
2018-12-21Inv69872.docdoc b577e06275b467b6737bacb00414fef6cd9214f1ff15392f56b36543f0cadba1n/a Heodo
2018-12-21INV6538.docdoc c989dbe1375f01fbb9a0f388687c845a004904035c9d34e5cc120b1c6056bfc1Virustotal results 19.64% Heodo
2018-12-21INV8576.docdoc 57b0a093137784584e7c1a998d552876df74af0ec8a00a0b8526891f8c470cecVirustotal results 16.13% Heodo
2018-12-21INV532.docdoc 48b3075b281cafa8d1cc3d8f09baaf26f567e6734fcea9309dab93460623e760Virustotal results 20.00% Heodo
2018-12-21INV5360.docdoc 2d5f1cbe450545edabd3016706513ef0ad9dbf2753eddfdc3a3ba52107105f86Virustotal results 18.33% Heodo
2018-12-21INV66439.docdoc 732ebc46374af14d19cd3d60cc39f7e361f604ea76950fb46f6fae15cb0b438an/a Heodo
2018-12-21INV83374.docdoc 58920b10b34928db438824695fdbd9cc4e2f18091da412fe8ebd7828b5fd07b9Virustotal results 18.33% Heodo
2018-12-21Inv866.docdoc a198e729fa0ea5f5e9a18b7f783628d4b35471d4ed03538f5ab1a35aa527e2f8Virustotal results 18.97% Heodo
2018-12-21Inv66058.docdoc d05269541be58bf8eebf8c606c31e7e6540b3850356bab25d0001555e9a2bde5Virustotal results 18.33% Heodo