URLhaus Database

You are currently viewing the URLhaus database entry for http://www.windo360.com/cgi-bin/sites/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:271243
URL: http://www.windo360.com/cgi-bin/sites/
URL Status:Offline
Host: www.windo360.com
Date added:2019-12-18 03:28:03 UTC
Last online:2019-12-20 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002182229 created on 2019-12-18 03:30:05 UTC)
Takedown time:1 day, 21 hours, 32 minutes Poor (down since 2019-12-20 01:02:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-19REP_VPU_120119_UMQ_122019.docdoc 15a7b776059c720dd390206464d669980d4285a1b8619667d5961c8bfc6221e7Virustotal results 29.51% Heodo
2019-12-19BAL_IKV_120119_ZGW_122019.docdoc c47565767b41e8ee3afc13533f44790a8d5134d4401fbe561df065d7d34cf6bbVirustotal results 29.03% Heodo
2019-12-19FILE_RLJ_120119_LBX_121919.docdoc cf1e1c5fdce6dfaeb87c86090e186b06e0165f13e4e47b7136298473f02118bdVirustotal results 25.00% 
2019-12-19ST_75574937031164.docdoc 67df26e9976eb13b8fddbea2e9e1ddf08ef741bc6d9eabc42e3eab1c48fb6a97Virustotal results 25.81% Heodo
2019-12-19REP_WQ5617730414YG.docdoc 99f5916f3803009668c44ca41a2ca4b5a17f9647163738438946951f7d3930b3Virustotal results 27.87% Heodo
2019-12-19H5JD8OWE159.docdoc 680e2b8bdd4e9ff629943f71f9520e38d77b6357396863dc1912acf559f0f181Virustotal results 26.23% Heodo
2019-12-19PAY_VDW_120119_VLT_121919.docdoc 1735d3c1c0d1500169d6a078c16216336af67c126f9dc97046f18d8f3c5a7d86Virustotal results 25.81% Heodo
2019-12-19REP_6392417745978004.docdoc 829263c831f1b2b0cec4218df826504150f2b0c15acb1a72e09300d5cf23c115Virustotal results 25.81% Heodo
2019-12-19AXF_VRC0L0GQN1KWU.docdoc 2690f1d2738e0d05d6d233f4ad695ddb102a0d162cf8c90996b85bc404f7acf6Virustotal results 22.58% Heodo
2019-12-19IU5204672007DM.docdoc f8e09058c07066ec081facf80968b241051ed56f16ac468a976bf07e6e31770eVirustotal results 22.95% Heodo
2019-12-19ST_57419462497533353.docdoc 32b16c30ff6c2a8ffbe3afd1318566c3bda00191296af85b263639d894eb4600Virustotal results 22.95% Heodo
2019-12-19RP_23461998.docdoc 7e2f99d6163561921f3d31bb2a00bea019b1addcbf09dd89b597d57562b229f4Virustotal results 21.67% Heodo
2019-12-19RP_EU9649545542RH.docdoc b81e8f4e54f74553d961c0af4df80b3fca7caa825c000a88eafa760833b62a08Virustotal results 24.19% Heodo
2019-12-19INV_RTR_120119_JGJ_121919.docdoc 0533851ea1605039ad7a074e05a1020d131fc343cd65de41d04e273294956a68Virustotal results 24.59% Heodo
2019-12-18NP3058697172BU.docdoc d697c45ef339d7418ae7caf0bf640fc4055605c8892508d825c21c701364930cVirustotal results 25.81% 
2019-12-18ST_L9ALRXV95B2QF.docdoc 7af0436052fc188b4873f17046e2e073a7a82706179a796f82c27b32a8fcb95eVirustotal results 24.19% Heodo
2019-12-18INV_BZ4598385826YU.docdoc 8b974a004a4926372021ced18f1b480e32367d38fb9e5e8e29ef08f9b03232f4Virustotal results 24.59% Heodo
2019-12-18RP_050391472848152241.docdoc 9e1926052857a2e225958cd4be2f519fc158025c1917ef13ee55619055c882f9Virustotal results 22.58% Heodo
2019-12-18RP_OI0675514253YX.docdoc c1dde6d798a5db4804f7163344fcd116cc8488e715e232947c8ef092da0f41bbVirustotal results 21.31% Heodo
2019-12-18ST_BOM_120119_EHD_121819.docdoc d19458049a137e1bfcd3f580aeef39686b6e1ea204dbf4f4a3abf79bcde08016Virustotal results 42.62% 
2019-12-18PAY_LDG_120119_TIL_121819.docdoc 53f9a8929a317cef9ef0be07118146e7ca56149c35b7552645999b1c6ebae147n/a 
2019-12-18SW_PO_12182019EX.docdoc 862593f0ec4b40cc1593362375fb3751cc51fc9f73e14dd6e5681c81433d3472n/a Heodo
2019-12-18PO_12182019EX.docdoc 2d646eebb1e3ad68ce3cdd7d783aa4e08b1502f0b6d371373c11727061d9bab4Virustotal results 41.94% Heodo