URLhaus Database

You are currently viewing the URLhaus database entry for http://shagua.name/fonts/Mizu-nM4Xl_WhW-1D/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:167071
URL: http://shagua.name/fonts/Mizu-nM4Xl_WhW-1D/
URL Status:Offline
Host: shagua.name
Date added:2019-03-27 12:01:13 UTC
Last online:2019-04-21 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-27 12:02:02 UTC to ipas{at}cnnic[dot]cn)
Takedown time:25 days, 4 hours, 54 minutes Bad (down since 2019-04-21 16:56:22 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-292019_03___US___INSTR3488350568626401146___96637549029366628.zipzip 8288c0bb949f8c898339ad9d02176fd7f1c76f2c068c5bd1418a1f25580e4daen/a 
2019-03-292019_03___US___0617327397892___3837810936156395588.zipzip 1d88f82ca71ab4781ffe4af666686a36f072c78507995b436af941e78d685ea6n/a 
2019-03-292019_03___US___INSTR7551700408684913___89580507380370408725.zipzip ebf06ad8d66018257f53074650497c65c33c02f02b6d3d2e6d2747fc1e433231n/a 
2019-03-282019_03___US___2600684664091835738___103346002563027.zipzip 50b6c003e21ed336ec185d2d3ba0ab6d358de34da697918c51b509bce9f6af9an/a 
2019-03-282019_03___US___ACC26513618552301___510039698256442.zipzip 18d95719035b9ef1b3faab16a1758e22c38dced3c68586d97dda21b90ecdbdcan/a 
2019-03-282019_03___US___KDKEM36923333684___82407242666990140.zipzip 1ed827b2468bd168c48c1d8ad8b077ab3831a7015c1b0a67aa34d6e13fa138d7n/a 
2019-03-282019_03___US___SADHW90576648490910056670___9009368610.docdoc 87698079ef2b9a3ce0ff2c16e9039e847a81bae4e0793b005c72a443683d28f4Virustotal results 21.43% Heodo
2019-03-282019_03___US___FXL3482257613603___687723946580992653.docdoc f3adf91c3cd1e972bff7f230f24729c6e69737862b88b491720f05a6fda282f4Virustotal results 19.30% Heodo
2019-03-282019_03___US___US51713076449115707594___885580960733.docdoc 3e871b698dc5613e3d7c241a32e8eb07f2a0ea98204e151cfb119255c6f28c65Virustotal results 17.54% Heodo
2019-03-282019_03___US___VEZHX4586703556029693141___027537163763922.docdoc c6483d11cbc8b37ebdb393c4c01b38ca9354a09e9214a713e2354cfbc7728672Virustotal results 20.00% Heodo
2019-03-282019_03___US___8226535297364528___71122292328.docdoc 17139a0b1e99a41443a231820173404850d3ee4093bcb4011cc71f790d1f9f09Virustotal results 18.97% Heodo
2019-03-282019_03___US___ACC18833897099677___58102266396821705385.docdoc 24ecfe71f85e9c8d734e8438171c62e5982fa9962e28600f2dea828b91d510b8Virustotal results 19.64% Heodo
2019-03-282019_03___US___620628395982___61127284555261.docdoc cd2d3b2f7eec90c2195bdbee984d67ce99230a76066a6a619a5895c06ab89db4Virustotal results 19.67% Heodo
2019-03-282019_03___US___65171687788406959373___564125046034627586.docdoc e9b57e2b29288ee0c219029141219b9064d8021aecf255cc9ea41198486daa55Virustotal results 19.67% Heodo
2019-03-282019_03___US___ACC607500706789447___916009596918110.docdoc ad5faaa82a6caef20722faf6fd1efd2d441b0e8362210d6e57af6ed666b62769Virustotal results 21.43% Heodo
2019-03-282019_03___US___US0127690586209___93500659412.docdoc 7d805fd6032eb14134efe16f128638bb6ea296911ad55fac6340ace72707f251Virustotal results 20.00% Heodo
2019-03-282019_03___US___INSTR694853399625655___679215394579623.docdoc 084d0997def7560fa87cb31751f21177cc3d0efc904a4901472b2cdb5225ee5cVirustotal results 20.34% Heodo
2019-03-282019_03___US___WBGAZ777340685221795___8328635681310751273.zipzip 041be537512efa2d6854664f4584edd3f1611f4145dcdad11bb7c4ba93bb6cf9n/a 
2019-03-282019_03___US___22797267311438312___8946296037251.zipzip e1b20a4be97cf62674fd9b14db9a418fb0747d8c2c1765411f4fafbdab834e25n/a 
2019-03-282019_03___US___PAY271931754902146___427034795.zipzip 7d3f141bf6d3c3a2b407f1884c727721af7eea6b4532808acde0a3a46efeede8n/a 
2019-03-282019_03___US___US84418749474___1487759423659750.docdoc 0b2865d4fa1698a720768ce6ca2d9042bb81d71b0518a063a94b302924ef5903Virustotal results 20.69% Heodo
2019-03-282019_03___US___US733204604___126147789.docdoc 317a746f7feff930bd6946c5d741d513303a03d4ab17d5bff017339a23a8014bVirustotal results 19.30% Heodo
2019-03-282019_03___US___ASWWR5291350873138238___4880345447690441745.docdoc 649a24597f3c8200c7d5eec932d168ec360aab882b9d9fb5f2f512ebaa433f38n/a Heodo
2019-03-282019_03___US___ILZQR93283788828___36029980679834375.docdoc c0e334e36a81f68f1c858422edeb2452483b808e2f72e2de289b14f90b6d4269Virustotal results 19.67% Heodo
2019-03-282019_03___US___VJ74003883299798864___0534541752.docdoc 35f786ff20a4822786b18f0012308fd5e2dbaba89a1928a6dfaf8d4b4a8f8e5fn/a Heodo
2019-03-282019_03___US___10462347620___270034558.docdoc 2b9604bae3248d8a134c549e86ca36649cb5e558a08e9e2a60d476a31b0294e2n/a Heodo
2019-03-282019_03___US___PAY102311383407362___49795312266166784022.docdoc 939fd6d752669eeeb3bf135cf1a64fc38fb3ae650b85f1fe3fa471100bb28981n/a Heodo
2019-03-282019_03___US___LO98397697298___871956058524316010.docdoc d73ab573a6281e5c1cd6b4ecb2e7ee89e29686ceac30906c480d948a7ad1109cn/a Heodo
2019-03-282019_03___US___US438525985897522___961755306210203234.docdoc 6d8d966985206b4f06bad79e5bc13d92f0253ebaf7ec9bd60df7c0cf06589737Virustotal results 18.64% Heodo
2019-03-282019_03___US___US10060667553___3633450352.docdoc 7bed206561fb6dbbf6dc4240564ab7f9b222836b67b1fea0ac06f5a6dba3f324n/a Heodo
2019-03-282019_03___US___PAY062651078809863___50899890431.docdoc 734d527ffa979b6019c9ac4a16bf3834739816d2ed3efd8154fbedd66be450a4Virustotal results 18.33% Heodo
2019-03-282019_03___US___INSTR013418546081345___1228035311.docdoc 5aa86074410aa1b1c35bf87c5546c883a4da6b2bec413e06e42dc56a133cf298Virustotal results 18.64% Heodo
2019-03-282019_03___US___US762777660___37675780310932283317.zipzip e6cbc834df0c20c80166ffb0187966dce89e40e0a5c6d2a0299f201c6981a691n/a 
2019-03-282019_03___US___06040022152522___457314175641660.zipzip 2735bb74390c4ac49b204bf74d06b5b589ad0dbb91bc0b86359efd5855d47b5dn/a 
2019-03-282019_03___US___US7645092603___8705587328.zipzip d1da0eeeb1c5ae91324408de8d76fd75452bade7601b7f0904731863c778b73an/a 
2019-03-282019_03___US___BU3013310401380___2895310618.zipzip ad90538fc4279bed06db1933a26d52ccf631349e02be605325652a06fefddbfdn/a 
2019-03-282019_03___US___ACC7286781171121___12107118215740777933.zipzip 5a25a6209103c6699de4d119e9716d500109035deede3c4042225bfcb7599529n/a 
2019-03-282019_03___US___INSTR7682393530550635547___78237361898351832499.zipzip 195447bee3877766b57f3d6cc6101f5cd533e0cc9ad448e056ea2ecfd3d6fd45n/a 
2019-03-282019_03___US___272700236528871339___763207897372072635.zipzip b060f6a343e376d853e5bd4a906860249b2080477f02df953d3f447141042748n/a 
2019-03-282019_03___US___1643619371805338___4446035127286.zipzip 0f983cec91ea722a0355322fd370b69884537e2d1769df6b9fb361beae6224a8n/a 
2019-03-282019_03___US___ACC69896540417064744131___053425933.zipzip 3fde286e14809bccb449cf4483a58f8cf333e48f4525b46f01c02f51325a73aen/a 
2019-03-282019_03___US___484911439222484236___746028591858180714.zipzip 1a83216a6de8c6b494890c8cc8fd6820b9cff4b54b96600afcea90af2ca355f6n/a 
2019-03-282019_03___US___CJ983338472221195053___5559733800362.zipzip eed55f7349e1d73d93d848febd54be5d98f3f26d18364e9902c5d92fa6078f56n/a 
2019-03-282019_03___US___ACC4706277807___472296711489984.zipzip 1af4c62f79d69fd9e8b4927f0e296c01a2f5ced8533cdd1ca9a41f4773c3acb5n/a 
2019-03-282019_03___US___ONAA889553377___100613912020594958.zipzip 6a1d5a2976abdad957758491ceb5413e07f99a676399e5abb9e58bbb64f84e65n/a 
2019-03-282019_03___US___INSTR1350221629716003171___198467435235.zipzip 254563a7f817e34906c45f6b48dd66a4fbb8ce3460dc41261f21c83a8cdafbfcn/a 
2019-03-272019_03___US___7507733950229276___9161554663668530.zipzip 49ea5cfa171ca7fb57e4ec435230309586e1db0785c2cbdd2728e19c76519127n/a 
2019-03-272019_03___US___ACC9288078755550___988913535830459755.zipzip 373133374ec7b4bbfea9ab9625d14d64e0f445f513fb0864903fbac7ec191c5cn/a 
2019-03-272019_03___US___PAY381646530900559___911117130.zipzip cc491da54277d30b4a4fe65a65906b4e94591dc54b33c4e6517520c82405fa81n/a 
2019-03-272019_03___US___ACC249779631827890___79292597916.zipzip b9f35d8bbb4bb758f05fe7566c7d8068de5e7743d7fa43d3dbbdbd4dfe37c086n/a 
2019-03-272019_03___US___PAY6408028664___1368125117603736672.zipzip f060927b1f207dcfc1266764648dce51703f4443d4164e5de5f7051dc7a49798n/a 
2019-03-272019_03___US___US57001161883___72670660256259893545.zipzip e5dd9893f013e0a47ea58da83ed7b874855a48f061669d8538c316ade97e22e1n/a 
2019-03-272019_03___US___327724019917148601___08201348792.zipzip f655512cb6e7aa4422d876021a2d79bd5a05b1e5af212e4ecb49229041b95aabn/a 
2019-03-272019_03___US___ZEEE3249822747384___3816174287.zipzip f4e5e0d664d18258a460b78e3021db403da01f1cc01fc7304564009f0981a696n/a 
2019-03-272019_03___US___56134299306___83531305760.zipzip 5107443484f1ba33ff1bf5480921bd2d4496e8466639fa579657796edabfa31dn/a 
2019-03-272019_03___US___US62721699621155___96438688147590080618.zipzip 6d958d71eb0a39bcbfbeae71210f2567d735cc0585d03ad0b50845b4f1d1afefn/a 
2019-03-272019_03___US___INSTR400907948___3628608698317721.zipzip e70e00923b57ce2dccc1940dd776afd1b21977ded10f5feabdba4f304be5ca3en/a 
2019-03-272019_03___US___ACC39372918940764813594___73245165980.zipzip 2f1d173e6b974ac80117fd4a8ce802446258fdff35e0069a9eea79ae3a92698en/a 
2019-03-272019_03___US___INSTR01906146914___0410373528579514891.zipzip fc13536eecb3d52edc568cb2339159626e4d735d176cc7404d3a1c2f4e4edc2an/a 
2019-03-272019_03___US___US720502212638___086671851.zipzip 10223233bbabba1e45ac43c54f31ea09edd3b76b9be28fc3e76f6c1ad3d46266n/a 
2019-03-272019_03___US___16490077182882830333___81138578924267648983.docdoc d9b81bbd973d6bacb77322a201ed36c43962247602b10073c0eef77de9843025Virustotal results 23.33% Heodo
2019-03-272019_03___US___0782906821926569___651960647326.docdoc 8622ad306bdb71845e69086858cb7bee044585ccf0a478d0610b1b04a192459dVirustotal results 22.81% Heodo
2019-03-272019_03___US___INSTR2950978969888___217347858515185116.docdoc 32a002db37bf228240a73f917438ce30995536a1b6b5cd3321df35fb1ca29dd4Virustotal results 20.00% Heodo
2019-03-272019_03___US___ACC70213382345089416___856400773100708584.zipzip 5a9cbc67147eb700e09297f8eb3a604817c5c8fa9d45c316891608a706384cbcn/a 
2019-03-272019_03___US___PAY3087597550___9272621212.zipzip 4d099bf5227d306164581232100dbe34f8dedccda2d51206388e2a437c840cd3n/a 
2019-03-272019_03___US___ACC144360672064301936___8115695114833.zipzip 6c6d18e8cf5aba972cef524ab1d4e59807857d89653723bea5755df9fcd6ef88n/a 
2019-03-272019_03___US___58561310158873696053___0998205553705.zipzip fa1821472f99281cc9db507115c57ab4253d7a705a6c099339f4d25e07ea0d47n/a 
2019-03-272019_03___US___PAY6449600272789849___3109514244188322.zipzip 80df25febfeee0905d644e1792c1d700f918b6a1859c1a9601ba777c879a945en/a 
2019-03-272019_03___US___412009114___84608898637.docdoc 015924d5bf2fd94b806aad406ff4dec89ecc17da5d0247231e2ae1ded25aff5en/a Heodo