URLhaus Database

You are currently viewing the URLhaus database entry for http://waleedintagency.com/cgi-bin/private-array/corporate-area/ogp63gj64-w7u4s2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:289404
URL: http://waleedintagency.com/cgi-bin/private-array/corporate-area/ogp63gj64-w7u4s2/
URL Status:Offline
Host: waleedintagency.com
Date added:2020-01-15 21:28:06 UTC
Last online:2020-01-30 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002248845 created on 2020-01-15 21:30:05 UTC)
Takedown time:14 days, 20 hours, 17 minutes Bad (down since 2020-01-30 17:47:39 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-175791693.docdoc 90444f88240663eb19aab9f4a45a1c0591f00bef7bf514c8e1763e669e3330f0Virustotal results 21.67% Heodo
2020-01-170204142118_4188.docdoc 14971442b709dd9aee9aa75a97a1809a10309d3836d4d9925e935de41a8c65a1Virustotal results 19.35% Heodo
2020-01-17Attachments 927370_816.docdoc 0e72c865b959ff343bcaed54902d52456bbc305790fcb1b268babb4d7a0b1086Virustotal results 22.95% 
2020-01-1724384-779120198.docdoc 3144b26dce719b333cd136d544491e8e1de4315924216c943722b32c19d22ac5Virustotal results 22.58% Heodo
2020-01-1754011-94520493.docdoc 3694a9cee7e9feda396ff033c02d4ee6fb7c5200734c2c4ca9d18dc6ad864f1eVirustotal results 21.31% Heodo
2020-01-170742692.docdoc 1db18e4f1e717111a6ebe3401e9583a77ce8bea0b4057b1f9681aa6fd3f1f0cfVirustotal results 19.35% Heodo
2020-01-17Attachments 814791716.docdoc 4eba8a541c94497f979b7230b0f6366159ccb650c462e66bb82a8d66edde2349Virustotal results 24.59% Heodo
2020-01-175279663_523.docdoc 864bcee1306de68b08f3c62b7d089cbab146fd47295aeefc4184bd1663c21a51Virustotal results 24.19% Heodo
2020-01-1782695177_16146.docdoc 86d440f588fbc52744ee8fd2c30e73f615d1f27b75b8351ba1b5cf8689033ffaVirustotal results 19.67% Heodo
2020-01-17389640-000692.docdoc 98bb1f6bfa92328a9d358c7dcc5a9bd5c1698ee03743cd39f803d6c519ab746dVirustotal results 18.64% Heodo
2020-01-17Attachment 3613-94539051.docdoc 2ad0521294bec243c52276586c33c9a742a4cc03f85eba377f60a18df2479f59Virustotal results 19.35% Heodo
2020-01-173068538963_62276.docdoc d58e3a873bc2d79ddd0d9449af813fecebe2fe92098d3e4c8b0197b09159aee0Virustotal results 19.35% Heodo
2020-01-173260142791.docdoc 17e6fbbc141f6b7e27df7ddeb423b4aee5adfecd80db00b9990b85ca7d75fa88Virustotal results 18.64% Heodo
2020-01-177897796248.docdoc 5efdc5e5f2c1146690945bd0705fefc903b099284c3f8166db23f872215c677fVirustotal results 43.33% Heodo
2020-01-17Attachment 93598-9991762.docdoc 142c2efda50596eb5d5e050338142a7c86a5030a0c4bd1095bb30cbe0f722e1eVirustotal results 40.98% 
2020-01-1728130114.docdoc baff02e524a1dc5e3aa3c7d79cd378bc8c858c899d1e25e75b0c13bfcbeb48feVirustotal results 40.98% Heodo
2020-01-17Attachments 1985412-40934695.docdoc 2ac0bb40219e750c921624eb8a594fd1e3da82daef680f193111378f46cd2d73Virustotal results 37.70% Heodo
2020-01-17Attachments 6111256194_477.docdoc de8bd947fc8203ef4899153c36ae350b2e4b4e69db34daee230ad89442f13951Virustotal results 36.67% Heodo
2020-01-165242-143064.docdoc f942462b771aaec7fb9e1bb8fc3eeeed0fa6c2b229eb6950b8135afa16403305Virustotal results 37.10% Heodo
2020-01-16UNTITLED 2270.docdoc 5b5fc12126eed77880537114373507d05bd137495a2a431d504b63de952c5851Virustotal results 36.07% Heodo
2020-01-16Attachments 674141211.docdoc 50c9656e9d815d21581aacde4941e794527b6764c8f0cbc5db0cffc94366b340Virustotal results 34.43% Heodo
2020-01-16Attachment 17558-539440584.docdoc 5c7d1bb4615145100fa04561534873729b8e59bc84d8fa7850575d16e4c003f6Virustotal results 32.26% Heodo
2020-01-161355381970.docdoc 56503e659d69adad5ac525757b9150c95dd7a7f9a7eb202cc0adf485cb72646aVirustotal results 29.51% Heodo
2020-01-168867-7748866.docdoc 96ad0ee66685dee743dc21aeecd11c01153ce2c4184c54e2a112f872f0166372Virustotal results 27.87% Heodo
2020-01-16306-33258921.docdoc 9c5d3fc74963aaa5ad9aaf17c7bd3e892195ba6bd66658f26f35f6e47f95953fVirustotal results 28.33% Heodo
2020-01-1627174010_99318.docdoc 6a848bc97aa9f95062a4698653bb69d5e4aa8258b01bb12717483b37aa6d0f33Virustotal results 26.23% 
2020-01-16Attachments 461545_441.docdoc 0971cc8674e5f9b1f2a3dc2647c42381380dae6cd097b96625012c379cf400b5Virustotal results 27.87% Heodo
2020-01-16Untitled 8136910.docdoc 41a33df5428a9b69eb9ca7bbed3dd8d8776d2243cf92c3ca20d20ff0745831c2Virustotal results 24.59% Heodo
2020-01-167997074_868.docdoc 058abfe0e47582efbe8082a02acb54eec587373096ba71b4f00150553e29a7faVirustotal results 24.59% Heodo
2020-01-1628562.docdoc 5c7211462187dbb4e5abf21ee9e5a05a3c25e6f516a271fa6cce643b806a5d4eVirustotal results 24.19% 
2020-01-16Untitled 1125420.docdoc 8a74acae6e18e058cb6298684509848286c3dc19189bb9f64e01f582cc31b919Virustotal results 20.97% Heodo
2020-01-16Untitled 7036258.docdoc 08258403e9f6dedf233554f21865bd22b4aa6941973c9268e933bb39a335d1f3Virustotal results 45.16% Heodo
2020-01-16UNTITLED 095000_319.docdoc 72d879cf6a283602966f151dec323a7b02e19627aca02a4e3550863c1e54c76cVirustotal results 44.26% Heodo
2020-01-16Untitled 5119922_0309.docdoc 881b837b4f8b743627ade4703cf5e6fb97eeb788212f253c65db3ed2d097375fVirustotal results 47.46% Heodo
2020-01-16Untitled 7658591194.docdoc df5ac7938838d52c0cae9fba928e85535e98dad36ef70be26a592926c7291c50Virustotal results 44.26% Heodo
2020-01-16095381.docdoc e2a9d9016c8575cc113654642aa970a6f3e13381a5d2f57aa4974f5009d51ba0Virustotal results 44.07% Heodo
2020-01-15Untitled 38223.docdoc c5ede9120a7219c5db64d4bd1d28da88ecde710c606892fce486b6771b8f7e41Virustotal results 42.62% Heodo
2020-01-15Untitled_291.docdoc 78616833085cfea2eb679516f1d7f7a22c930463f5d32622b2b5f3af4474021bVirustotal results 35.00% Heodo
2020-01-15Untitled.docdoc 12c45dc8fd27bc4a7113607a8d1eddfdb6edbea36683fa947b77e952d28d2108Virustotal results 36.21% Heodo