URLhaus Database

You are currently viewing the URLhaus database entry for http://www.windo360.com/cgi-bin/report/z-7287039072-183-8n21i3p-le539526c/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:271242
URL: http://www.windo360.com/cgi-bin/report/z-7287039072-183-8n21i3p-le539526c/
URL Status:Offline
Host: www.windo360.com
Date added:2019-12-18 03:23:03 UTC
Last online:2019-12-20 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002182200 created on 2019-12-18 03:24:05 UTC)
Takedown time:1 day, 21 hours, 38 minutes Poor (down since 2019-12-20 01:02:17 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-19INV_HN2146580458SG.docdoc 15a7b776059c720dd390206464d669980d4285a1b8619667d5961c8bfc6221e7Virustotal results 29.51% Heodo
2019-12-19PAY_J8FI477DZX.docdoc c47565767b41e8ee3afc13533f44790a8d5134d4401fbe561df065d7d34cf6bbVirustotal results 29.03% Heodo
2019-12-19RP_NX6069151582QL.docdoc 4fc9d25ed1c96663ba58d9dcb4950e5aba65c9a004115e9e78d93a057db8ffc6Virustotal results 28.81% Heodo
2019-12-19YRMF_5745348199215028.docdoc 5b6cc554583e44d7e69864ade8d2a79cb71683349e79b407f05ccec1dcac8eeeVirustotal results 30.00% 
2019-12-19PAY_PO_12192019EX.docdoc 67df26e9976eb13b8fddbea2e9e1ddf08ef741bc6d9eabc42e3eab1c48fb6a97Virustotal results 25.81% Heodo
2019-12-19INV_MJ6486900298JS.docdoc 99f5916f3803009668c44ca41a2ca4b5a17f9647163738438946951f7d3930b3Virustotal results 27.87% Heodo
2019-12-19PO_12192019EX.docdoc 680e2b8bdd4e9ff629943f71f9520e38d77b6357396863dc1912acf559f0f181Virustotal results 26.23% Heodo
2019-12-19NQZ_120119_KMF_121919.docdoc 1735d3c1c0d1500169d6a078c16216336af67c126f9dc97046f18d8f3c5a7d86Virustotal results 25.81% Heodo
2019-12-1940943322.docdoc 829263c831f1b2b0cec4218df826504150f2b0c15acb1a72e09300d5cf23c115Virustotal results 25.81% Heodo
2019-12-19DOC_CKWHQN8FM.docdoc b0ac17faf517301d9a4b18edc0f4a7879335f2f225e2dcdbe4a6377f598a3f99Virustotal results 22.95% 
2019-12-19INV_1766278874057537286130.docdoc b705c6b11ce5c95ab6e45a9063da6bd67b5418f1be7a7168bffca09db9e958d3Virustotal results 22.58% Heodo
2019-12-19BAL_XU8797525706KS.docdoc 32b16c30ff6c2a8ffbe3afd1318566c3bda00191296af85b263639d894eb4600Virustotal results 22.95% Heodo
2019-12-19RP_AW3797077960PR.docdoc 7e2f99d6163561921f3d31bb2a00bea019b1addcbf09dd89b597d57562b229f4Virustotal results 21.67% Heodo
2019-12-19INV_FUO_120119_QOF_121919.docdoc b81e8f4e54f74553d961c0af4df80b3fca7caa825c000a88eafa760833b62a08Virustotal results 24.19% Heodo
2019-12-19V_01871272.docdoc 0533851ea1605039ad7a074e05a1020d131fc343cd65de41d04e273294956a68Virustotal results 24.59% Heodo
2019-12-18PAY_LZZWFWMOT1.docdoc d697c45ef339d7418ae7caf0bf640fc4055605c8892508d825c21c701364930cVirustotal results 25.81% 
2019-12-18NK_YVJ_120119_ZQL_121819.docdoc 7af0436052fc188b4873f17046e2e073a7a82706179a796f82c27b32a8fcb95eVirustotal results 24.19% Heodo
2019-12-18n/aunknown c002022f27ca7fc85a4b6c2fb46ba2af167c7a9332322b196f767d406f3823fen/a 
2019-12-18INV_681769085504290.docdoc 9e1926052857a2e225958cd4be2f519fc158025c1917ef13ee55619055c882f9Virustotal results 22.58% Heodo
2019-12-18RP_XIB_120119_EZU_121819.docdoc aec3c0bab3c0b2749e0b8db8a7d375f8821f098e0497735472b73aaba8360b9bn/a 
2019-12-18FILE_AYN_120119_YLY_121819.docdoc d19458049a137e1bfcd3f580aeef39686b6e1ea204dbf4f4a3abf79bcde08016Virustotal results 42.62% 
2019-12-18INV_AV6FUWTC0.docdoc 53f9a8929a317cef9ef0be07118146e7ca56149c35b7552645999b1c6ebae147n/a 
2019-12-18REP_BF7131460806NF.docdoc 862593f0ec4b40cc1593362375fb3751cc51fc9f73e14dd6e5681c81433d3472Virustotal results 41.94% Heodo
2019-12-18130713219249.docdoc d93540d00b3e0df9c0d44218338d46c79dbbe156480a89c7f298ae1ededbc1d1Virustotal results 42.62%