URLhaus Database

You are currently viewing the URLhaus database entry for http://pravokd.ru/UAQmQ-AG2Da_yLIbNo-iYA/INV/8501169FORPO/3632845162/US/Past-Due-Invoices/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:98835
URL: http://pravokd.ru/UAQmQ-AG2Da_yLIbNo-iYA/INV/8501169FORPO/3632845162/US/Past-Due-Invoices/
URL Status:Offline
Host: pravokd.ru
Date added:2018-12-21 16:32:19 UTC
Last online:2019-01-04 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-21 16:34:11 UTC to abuse{at}beget[dot]ru)
Takedown time:14 days, 3 hours, 10 minutes Bad (down since 2019-01-04 19:44:56 UTC)
Tags:doc emotet link epoch2

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-01-04this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 0.00%
2018-12-21ATT6955416123.docdoc 523b8855fc3a19261a1fbb7ef36dbc039fff0943158a7a706d1c75c45ae8dd17n/a 
2018-12-2188288393773035606035.docdoc 8ac7e39bbf842d7efa2565edbc55cfb858f25a2c0554cdc7ea8a247c5340ef70n/a 
2018-12-21ATT1708685396001114180.docdoc f43aeb9334ea9ac3c5d96f953824d0e9e38ec46e0d9a7fbdf50b79e6830a3393Virustotal results 18.64% 
2018-12-21753035031547995906.docdoc 8cd52f27b42d99270ad570bb0c8ed8a45846e94f246f0027721caf6b35110d4dn/a 
2018-12-21ATT49402379035.docdoc 4b4014bd957fd90821e7dd2bb940cb0ae565b257cb58bfc473b256d30f5cc207n/a 
2018-12-21865820320144088.docdoc 167aa92b953e437c96c43db26fce8477d5e0c72f80dff97a77c722086f604304n/a 
2018-12-21303204644690.docdoc c487b27617f4c7d2da63e39277c2902e7d43720d4f19fd2877f84d5dfe4c60c0Virustotal results 18.64%