URLhaus Database

You are currently viewing the URLhaus database entry for http://fanction.jp/Ne50wfrBn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:9967
URL: http://fanction.jp/Ne50wfrBn/
URL Status:Offline
Host: fanction.jp
Date added:2018-05-14 18:38:38 UTC
Last online:2019-01-10 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: cocaman
Abuse complaint sent (?): Yes (2018-07-24 06:17:22 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-05-16INV34619848520.docdoc 80c353c7f5cb47a02e80743d3b98772b5e195a50166a147dab1beea634bd2c5eVirustotal results 27.59% 
2018-05-16INV986860660607.docdoc d7d917f4586f4c453f61fe536c5dcbf808e8bfa56376625343aa2d6a08880817n/a 
2018-05-16INV38599604310.docdoc 30031fb352b8c753ca5aa8756a67435f19f94046fac589724d2a41fd162012b2Virustotal results 32.76% 
2018-05-15INV677219562.docdoc d84eee4e637944017ad294d50e66280cd335f2b9e44745877d585d133587ab3eVirustotal results 33.33% Heodo
2018-05-15INV29770319.docdoc 7d013c71ea22af7b40f6628262ba76f0d5bc152bbfe3c7086ecf8c5d810a0446Virustotal results 28.07% 
2018-05-15INV81946402705639939.docdoc 7f5604e8ca4dc2153f2d94aabbecdbc27e0fe66b78701e2d52192bebcaf426aaVirustotal results 24.14% 
2018-05-14Past Due Invoices.docdoc 1d151ad8ed9c850f4b2822598e9a4fca72b33c6f332a6140221d53d3ccbe4b40Virustotal results 27.59%